Skip to content

What it checks

Exposed files

Files that were never meant to be public but can be downloaded by anyone.

How it is checked

Sentinel asks for a fixed list of file names that are often left behind. It reports one only when what comes back is really that kind of file, and only when your site does not answer every made-up address the same way.

  • Left-behind files. A fixed list of file names: version-control folders, settings files, backups, database dumps and keys.
  • Folder listings. Whether folders on the site show a list of their files.

What it can find

Your site's source code can be downloaded by anyone

Fix now

Someone could take data or control of the site today.

What it is
The hidden folder that a developer's version-control tool keeps is on the public site. From it, the whole history of the site's code can be rebuilt.
Why it matters
Source code usually contains passwords and keys, and shows an attacker exactly where the weak points are.
How to fix it
Block access to /.git in the web server settings, or deploy the site without that folder. Then change every password and key that appears anywhere in the code's history.

A file of passwords and keys can be read by anyone

Fix now

Someone could take data or control of the site today.

What it is
A settings file that normally holds database passwords and secret keys is being served to anyone who asks for it.
Why it matters
Whoever reads it can sign in to your database and the services your site uses.
How to fix it
Move the file outside the public folder, or block it in the web server settings. Then change every password and key it contains, because it must be assumed they were copied.

A backup copy of your site's settings can be read by anyone

Fix now

Someone could take data or control of the site today.

What it is
A spare copy of the site's settings file was left on the server under a name the server shows as plain text, database password included.
Why it matters
Whoever reads it can sign in to your database.
How to fix it
Delete the backup file from the server. Then change the database password and any keys in it.WordPress: this is usually an editor's leftover copy of wp-config.php. Delete it, change the database password at the host, and replace the security keys.

A copy of your database can be downloaded by anyone

Fix now

Someone could take data or control of the site today.

What it is
A database export was left in the public folder of the site.
Why it matters
It can contain every customer record, order and password the site holds. Depending on where you are, a leak like this may have to be reported.
How to fix it
Delete the file from the server. Check the access logs for downloads. If customer data was in it, get advice on your duty to tell the people affected.

A backup archive of your site can be downloaded by anyone

Fix soon

A real weakness that an attacker would look for.

What it is
A compressed backup file sits in the public folder of the site under a name that is easy to guess.
Why it matters
Site backups usually contain the code, the settings with their passwords, and often the database.
How to fix it
Delete the file from the server and store backups somewhere that is not public. Change the passwords the backup contains.

A private key can be downloaded from your site

Fix now

Someone could take data or control of the site today.

What it is
A private key file is being served to anyone who asks for it.
Why it matters
A private key is a password for a server or a certificate. With it, someone can sign in as you or impersonate the site.
How to fix it
Delete the file from the server. Create a new key and remove the old one from every server and service that trusted it.

A file of user names and scrambled passwords can be read by anyone

Fix soon

A real weakness that an attacker would look for.

What it is
The file a web server uses to check passwords for a protected area is itself publicly readable.
Why it matters
The passwords are scrambled, but weak ones can be recovered, and the user names are in the clear.
How to fix it
Move the file outside the public folder or block it in the web server settings, then change those passwords.

A hidden file lists the contents of a folder on your site

Worth tidying

Good practice that is missing.

What it is
A hidden file that Mac computers create was uploaded with the site. It lists the names of the files in that folder.
Why it matters
It can reveal files that are not linked from anywhere and were not meant to be found.
How to fix it
Delete the file from the server and stop uploading it with the site.

A folder on your site shows a list of everything in it

Should fix

Makes an attack easier or more damaging.

What it is
Opening a folder's address shows a list of its files instead of a page.
Why it matters
Anyone can browse the folder and find files that were never linked: old backups, uploads, private documents.
How to fix it
Turn off directory listing in the web server settings. On Apache that is Options -Indexes; on nginx, autoindex off.

See which of these your own website has.

Start free trial