Free check Nothing stored Scan only sites you own

Is your .env file exposed to the internet?

A misconfigured server can hand your .env file — database passwords, API keys, app secrets — to anyone who asks for it. Enter your site and DotenvScan checks from the outside, the same way an attacker would.

Checks over HTTPS. Only scan a site you own or have permission to test.
What it checks

The files that leak secrets.

Backup and editor copies (.env.bak, .env.save, .env.old) are the usual culprits: the app ignores them, but the web server sends them as plain text to anyone who requests them.

How it works

An outside-in check, in seconds.

  1. You enter your address

    Just the domain, like example.com. We scan it over HTTPS.

  2. We request each path

    A plain GET for /.env and the others — exactly what a browser or a bot would do. Nothing is changed on your server.

  3. You get a verdict

    For each file: exposed, protected, or not found. We read only enough to tell a real file from an error page, and never store it.

Prefer the command line? The manual check is curl -sI https://example.com/.env — look for 403 or 404, not 200. DotenvScan runs that check for every path at once and reads the result for you.

$ curl -sI https://example.com/.env
Why it matters

One exposed file is a full breach.

An exposed .env typically contains everything an attacker needs at once: database credentials, cloud and payment API keys, mail passwords and app secret keys. Automated bots request /.env on millions of sites a day, so exposure is usually found in hours, not years.

  • Database username and password
  • Cloud, payment and email API keys
  • App secret / signing keys (session, JWT)
  • Everything needed to impersonate your app
On the server itself

Found one? There are usually more.

DotenvScan checks a site from the outside. To find every secret file across a whole server — all hosting accounts, backup copies, WordPress, Laravel, Magento and more — run ServerSecretVault on the server itself. It's read-only, makes no network requests, and rates each file's risk.

$ curl -fsSL serversecretvault.com/install.sh | sudo sh
Explore ServerSecretVault
Guides

Found something? Fix it properly.

Step-by-step fixes for the files DotenvScan checks, with web-server rules tested on real nginx, Apache and Caddy servers. All guides

FAQ

Questions.

What does DotenvScan check?

It requests a short, fixed list of config-file paths on the address you enter — .env and its backup copies, WordPress’s wp-config.php and its .bak copy, leftover phpinfo() pages, Laravel’s log, and the .git, .svn, .aws and .DS_Store dotfiles — and reports whether each one is downloadable. It only makes GET requests, and only to the one site you enter.

Does it show or store my secrets?

No. For each path it reads only enough of the response to tell a real config file from an ordinary "not found" web page, then discards it. It never displays, logs or stores the contents, and it doesn't keep your scan results.

Is it safe to run against my own site?

Yes. Every request is a plain GET, the same as a browser loading a URL. It changes nothing on your server. It won't scan internal or private addresses, only public websites.

It says a file is exposed. What do I do?

Treat the secrets in that file as compromised: rotate the database password, API keys and any app secret keys. Then remove the file from the web root or block it in your web server, and check your access logs to see if it was already downloaded. The exposed .env guide walks through it, with copy-paste rules for nginx, Apache and Caddy.

Why only my homepage address — can it scan every page?

Exposed config files sit at known paths, so a fixed short list catches them without crawling your whole site. Keeping the list fixed is also what stops the tool being turned into a general-purpose scanner.

I run WordPress. What else should I do?

If wp-config.php or a copy of it was exposed, follow the wp-config backup guide: change the database password and replace the keys and salts — the WPSalt salts generator makes fresh ones in your browser. For a wider check of the site, WP Server Guard does WordPress security audits and malware cleanup.

I have lots of sites on one server.

Checking them one address at a time from outside is slow. ServerSecretVault runs on the server itself and finds every .env, wp-config.php and backup across all accounts in one pass, then rates the risk.