Skip to content

What it checks

Exposed doors

Admin, setup and debugging pages that anyone on the internet can open.

How it is checked

Sentinel asks for a fixed list of addresses where these pages usually live and looks at what comes back. It never fills in or submits a form.

  • Admin, setup and debug pages. A fixed list of addresses where installers, database tools, status pages and login pages usually live.

What it can find

A setup page is open to anyone

Fix soon

A real weakness that an attacker would look for.

What it is
An installer or setup page for the site's software can be opened by anyone and appears ready to run.
Why it matters
Whoever runs it can set the site up again as their own, with themselves as administrator.
How to fix it
Finish the installation, or delete the installer file from the server.

A diagnostics page shows your server's full configuration

Fix soon

A real weakness that an attacker would look for.

What it is
A page that prints every detail of the server's setup is public: software versions, file paths, and sometimes passwords held in settings.
Why it matters
It is a map of the server for anyone planning an attack.
How to fix it
Delete the file from the server.

Your database's control panel is open to the internet

Should fix

Makes an attack easier or more damaging.

What it is
The sign-in page of a database administration tool can be reached by anyone.
Why it matters
It invites password guessing against the place all your data lives, and these tools have a history of security holes of their own.
How to fix it
Remove the tool if it is not needed. Otherwise limit who can reach it, by network address or an extra password in front.

A live status page for your server is public

Should fix

Makes an attack easier or more damaging.

What it is
A page showing what the server is doing right now, including the addresses visitors are requesting, can be opened by anyone.
Why it matters
It reveals visitors' activity and addresses on your site that were meant to be private.
How to fix it
Limit the status page to the server itself in the web server settings, or turn it off.

A developer's debugging tool is switched on for everyone

Fix soon

A real weakness that an attacker would look for.

What it is
A debugging screen meant for development is reachable on the live site.
Why it matters
These tools show the inner workings of the site: database queries, settings, and often passwords and customers' data from recent requests.
How to fix it
Switch the site out of debug mode and remove development tools from the live server.

Your admin sign-in page is open to the internet

Worth tidying

Good practice that is missing.

What it is
The page where administrators sign in can be reached by anyone. This is how most sites are set up, and it is not a hole by itself.
Why it matters
It is the first place automated password guessing is aimed.
How to fix it
Use long unique passwords, turn on two-step sign-in for every administrator, and limit sign-in attempts.WordPress: a security plugin can limit sign-in attempts and add two-step sign-in.

See which of these your own website has.

Start free trial