Kavach

Check · Exposed secrets · default severity critical

Exposed .env file

What Kavach checks

Whether your environment file (secrets, DB passwords, API keys) is downloadable from the web.

Why it matters

A public .env hands an attacker your production credentials directly -- database logins, payment keys, signing secrets. It is game over, with no exploit required.

How an attacker uses it

  1. Attacker requests https://yoursite.com/.env
  2. The server hands back your real DB password and API keys.
  3. They log straight into your database and payment provider.

How to fix it

Remove .env from the web root, block dotfiles at the server, and ROTATE every secret that was exposed -- assume it is compromised.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.

Scan your site free → Monitor it continuously