Observed arrival · 2026-10-10
DotenvScan checks whether a site is exposing its secrets
An outside-in scanner checks a website for publicly reachable environment files, backups, configuration files, logs, and other sensitive artifacts.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Site owners checking for exposed server files
- Worth noticing
- Its checklist also includes phpinfo pages, Laravel logs, Subversion data, AWS credentials, and macOS folder indexes.
Field notes
The page says each check is a plain GET request, with no server changes, and that the scanner reads only enough of a response to tell a file from an error page. Its checklist reaches beyond environment files to include WordPress configuration backups, PHP information pages, Laravel logs, Git and Subversion artifacts, AWS credentials, and `.DS_Store`; linked guides offer follow-up fixes.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
One card from the complete issue