Knowledge base

Exposed files and folders

Vigavo requests a list of well-known paths that should never be public and reports the ones your server returns:

  • env_exposed: a .env file with configuration and often passwords or keys.
  • git_exposed: the .git folder, from which the whole source code can be rebuilt.
  • backup_archive_exposed: backup or archive files (for example backup.zip, archive.zip, site.tar.gz, .sql dumps).
  • sensitive_file_exposed: other configuration or credential files.
  • phpinfo_exposed: a phpinfo() page describing the server.
  • dir_listing: a folder that lists its files.
  • sourcemap_exposed: source maps that publish your original front-end code.
  • security_txt_missing (hygiene): no /.well-known/security.txt for people who want to report a problem.

Fixing

Delete the file from the web root or block it in the web server, then treat anything it contained as leaked: rotate passwords and keys that were in it. Critical findings have a fix prompt with the exact steps.

Last reviewed Oct 7, 2026, 12:00:00 AM

Still stuck? Send a ticket

Feedback
Type