Remove a public .env file
exposed-env
Your .env file is readable over HTTP. It holds database passwords, API keys and signing secrets, and scanners look for it constantly. Remove it.
Why this matters
Your .env file is sitting in the open. It has your database passwords, API keys, and secrets in it. Anyone who knows to look (and many do) can read it right now. Remove it from your web server.
CDN and edge
Web servers
Frameworks
Vercel
- 1 Vercel does not serve dotfiles by default
- 2 If exposed, check your build output and public/ directory
Does your app still have this?
Scan your domain