Exposed .env and .git on a website: how to check and close them
A public .env file, .git folder or database dump hands out passwords and code. Check your site in a minute, close access and rotate leaked keys.
Checked against sources: 11 October 2026

- 20typical paths Awe Check probes
- 1 requestper path, no password guessing
- Allkeys in an exposed file count as leaked
What is most often left open
- .git: a repository with the source and its full history, including old passwords.
- .env and copies: the database password and payment and email keys.
- backup.sql, dump.sql, backup.zip: database and site copies forgotten after a migration.
- wp-config.php.bak, config.php.bak: a configuration copy the server serves as text.
- phpinfo.php, server-status, phpMyAdmin: hints for password guessing.
Check in a minute
Open your-site/.env and your-site/.git/HEAD in a browser. If you see settings text or a line like ref: refs/heads/…, the file is exposed. Awe Check tests 20 typical paths and recognises a file by its content, not the response code, so a pretty 404 page does not cause false alarms.
What to do if you find one
- Remove the file from the public path or block access in the server config.
- Treat every password and key in it as leaked: rotate the database password and payment and email keys.
- Check the logs for outside downloads. If customer data was in the file it may count as a breach under the law.
# nginx: block dotfiles and backup copies
location ~ /\.(?!well-known) { deny all; }
location ~* \.(sql|bak|zip|old|env)$ { deny all; }Frequently asked
Why do so many sites expose .git?
The site is deployed with git clone straight into the web root and the .git folder stays beside the pages. Anyone can download it and rebuild all the code.
Is it a legal violation?
If personal data leaked through an exposed file, it breaches data protection duties: GDPR Art. 32 in the EU, Art. 79 of the Administrative Code in Kazakhstan. An exposed file without data is not itself a violation but raises the risk of a break-in sharply.
Is the Awe Check probe safe for my site?
Yes. Each path gets one ordinary read request, with no password guessing and no attempt to change anything.
