Check · Exposed secrets · default severity critical
Exposed .env file
What Kavach checks
Whether your environment file (secrets, DB passwords, API keys) is downloadable from the web.
Why it matters
A public .env hands an attacker your production credentials directly -- database logins, payment keys, signing secrets. It is game over, with no exploit required.
How an attacker uses it
- Attacker requests https://yoursite.com/.env
- The server hands back your real DB password and API keys.
- They log straight into your database and payment provider.
How to fix it
Remove .env from the web root, block dotfiles at the server, and ROTATE every secret that was exposed -- assume it is compromised.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.