All fixes

Remove a public WordPress debug log

tech-wp-debug-log

debug.log is readable under wp-content and holds file paths, queries and sometimes credentials. Delete it and stop writing logs into the web root.

Why this matters

Your WordPress debug log is publicly readable. It may contain file paths, queries, and internal details — information disclosure that aids attackers but is not directly exploitable.

Nginx

  1. 1 Block access to debug.log at the web server level as a defense-in-depth measure
nginx
location = /wp-content/debug.log {
    deny all;
    return 404;
}

Does your app still have this?

Scan your domain