Skip to content

What it checks

Leaks in the page

Keys, internal addresses and error details visible in your pages to anyone who looks.

How it is checked

Sentinel searches the pages and scripts it has already read for the shapes of well-known keys, private network addresses and error messages.

  • Keys and errors in pages. Every page and script already read, searched for keys, private addresses and error traces.

What it can find

A secret key is visible in your site's pages

Fix now

Someone could take data or control of the site today.

What it is
A key that is meant to be kept on the server is written into a page or script that every visitor's browser downloads.
Why it matters
Whoever copies it can use the service it belongs to as you: take payments, read data, or run up charges.
How to fix it
Cancel the key with the service that issued it and create a new one. Then change the site so the key is only ever used on the server.

A service key is visible in your site's pages

Worth tidying

Good practice that is missing.

What it is
A key for an outside service is written into a page. Some keys of this kind are designed to be public, but only if they are restricted to your site.
Why it matters
An unrestricted key can be copied and used on someone else's site at your expense.
How to fix it
In the service's console, restrict the key to your website's address and to the features the site needs.

A page reveals an address inside your private network

Worth tidying

Good practice that is missing.

What it is
A page or script contains a network address that only exists inside a private network.
Why it matters
It tells an attacker how your internal systems are laid out, and may mean the page links to something visitors cannot reach.
How to fix it
Remove the address from the page, or replace it with the public one.

A page shows the details of an internal error

Should fix

Makes an attack easier or more damaging.

What it is
A page displays a raw error message from the site's software: file paths, database details or a trail of the code that failed.
Why it matters
It means part of the site is broken, and it hands an attacker details they would otherwise have to guess.
How to fix it
Fix the underlying error, and set the live site to log errors instead of showing them.WordPress: set WP_DEBUG_DISPLAY to false in wp-config.php.

See which of these your own website has.

Start free trial