Check · Exposed secrets · default severity critical
Exposed .git directory
What Kavach checks
Whether your .git directory is reachable, letting anyone reconstruct your full source code and history.
Why it matters
A public .git lets an attacker download your entire codebase -- including old commits that often still contain hard-coded secrets.
How an attacker uses it
- Attacker finds /.git/config is downloadable.
- They run a tool that rebuilds your whole repo from it.
- They read your source, old commits, and any leaked keys.
How to fix it
Block access to /.git at the server, and deploy build artifacts without the .git directory. Rotate any secrets found in history.
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 2.