What it checks
Leaks in the page
Keys, internal addresses and error details visible in your pages to anyone who looks.
How it is checked
Sentinel searches the pages and scripts it has already read for the shapes of well-known keys, private network addresses and error messages.
- Keys and errors in pages. Every page and script already read, searched for keys, private addresses and error traces.
What it can find
A secret key is visible in your site's pages
Fix nowSomeone could take data or control of the site today.
- What it is
- A key that is meant to be kept on the server is written into a page or script that every visitor's browser downloads.
- Why it matters
- Whoever copies it can use the service it belongs to as you: take payments, read data, or run up charges.
- How to fix it
- Cancel the key with the service that issued it and create a new one. Then change the site so the key is only ever used on the server.
A service key is visible in your site's pages
Worth tidyingGood practice that is missing.
- What it is
- A key for an outside service is written into a page. Some keys of this kind are designed to be public, but only if they are restricted to your site.
- Why it matters
- An unrestricted key can be copied and used on someone else's site at your expense.
- How to fix it
- In the service's console, restrict the key to your website's address and to the features the site needs.
A page reveals an address inside your private network
Worth tidyingGood practice that is missing.
- What it is
- A page or script contains a network address that only exists inside a private network.
- Why it matters
- It tells an attacker how your internal systems are laid out, and may mean the page links to something visitors cannot reach.
- How to fix it
- Remove the address from the page, or replace it with the public one.
A page shows the details of an internal error
Should fixMakes an attack easier or more damaging.
- What it is
- A page displays a raw error message from the site's software: file paths, database details or a trail of the code that failed.
- Why it matters
- It means part of the site is broken, and it hands an attacker details they would otherwise have to guess.
- How to fix it
- Fix the underlying error, and set the live site to log errors instead of showing them.WordPress: set WP_DEBUG_DISPLAY to false in wp-config.php.