Kavach

Check · Exposed secrets · default severity critical

Exposed .git directory

What Kavach checks

Whether your .git directory is reachable, letting anyone reconstruct your full source code and history.

Why it matters

A public .git lets an attacker download your entire codebase -- including old commits that often still contain hard-coded secrets.

How an attacker uses it

  1. Attacker finds /.git/config is downloadable.
  2. They run a tool that rebuilds your whole repo from it.
  3. They read your source, old commits, and any leaked keys.

How to fix it

Block access to /.git at the server, and deploy build artifacts without the .git directory. Rotate any secrets found in history.

Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare

Limitations

This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.

Scan your site free → Monitor it continuously