Exposed Files Checker: Find Publicly Reachable Backups and Config Files

A single forgotten backup or config sample left in your web root can hand an attacker your database password or your exact software versions. BadgerScan's free external scan checks for the files that should never be public, and tells you which ones to lock down.

Run the free scan

One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.

What this exposed files checker looks for, and why it matters

This exposed files checker is built to catch the gap between two kinds of files. Every website has files that are meant to be public (your pages, images, stylesheets) and files that are absolutely not (database backups, configuration with passwords, internal logs). The trouble starts when a private file ends up somewhere a web browser can reach it. No login, no clever attack, just a guessable URL away from anyone on the internet.

The check tries the common spots where these files leak. Think of database dumps left in the web root after a migration (backup.sql, db.sql.gz, site.zip), configuration samples that ship with version numbers (wp-config-sample.php, .env files), readme and version files that broadcast exactly what software you run (readme.html on WordPress tells the world your core version), and folders that have no index page so the server lists every file inside them.

Why does one file matter so much? A single exposed backup is often game over. A database dump can contain your password hashes, customer records, API keys, and the secret salts that protect logged-in sessions. An exposed .env or wp-config file can hand over the live database credentials directly. Even a harmless-looking readme.html is useful to an attacker: it tells them your exact version, so they can look up which published vulnerabilities apply. This is the same outside view we cover across what attackers see outside your WordPress site.

How BadgerScan checks it

This is not a separate tool you run on its own. The exposed files checker is one part of BadgerScan's single free external scan. You enter your domain once, and the same passive scan that looks at your DNS, email security (SPF, DKIM, DMARC), TLS certificate, and HTTP security headers also probes for publicly reachable sensitive files.

The check is passive and read-only. BadgerScan requests the common exposed-file paths the way any visitor's browser would and notes what comes back: a downloadable file, a directory listing, a version-leaking page, or a clean not-found. It never logs in, never tries passwords, never uploads anything, and never exploits what it finds. BadgerScan does not do penetration testing or active exploitation, full stop. It simply reports what is already reachable from the public internet.

If you also run WordPress, the free scan can read your publicly detectable version and match it against known CVEs. Going a step further, BadgerScan Pro adds a read-only plugin that scans from the inside (exact plugin, theme, and core versions, admin configuration, 2FA, file integrity) and fuses the inside and outside views into one plain-English grade and one deduplicated fix-list. You can run the free external scan now to see your exposed-files result in seconds.

How to read your result

A clean result means BadgerScan did not find common backups, config samples, sensitive dotfiles, or open directory listings at the public paths it checked. That is the goal. It does not prove zero files are exposed anywhere on your server, only that the usual leak spots are buttoned up.

A flagged result means something reachable came back that probably should not be. Read the specific finding: a downloadable backup or database dump is the most urgent (treat it as a live data exposure), an exposed config or .env file is equally serious because it can contain credentials, an open directory listing is a medium concern because it reveals your file structure and may expose other files, and a version-leaking readme or meta tag is a lower-severity informational finding that still helps attackers target you.

Severity is qualitative and plain-English on purpose. The point is to tell you what to fix first, not to bury you in scores. If you want the inside-out picture (which of your exact plugin and theme versions actually carry known vulnerabilities), that comes from pairing this external view with the Pro plugin, covered in why an inside-and-outside scan matters.

Common fixes

Most exposed-file problems are quick to fix once you know they exist. Work down the list in order of severity:

  • Remove backups and database dumps from your web root immediately. Files like backup.zip, site.tar.gz, db.sql, and *.bak should never live under your public web directory. Move them to off-server storage, then delete the copies that were public.
  • Lock down config and environment files. Make sure .env, wp-config.php, and any *-sample or *.old config files cannot be downloaded. On WordPress, wp-config.php should be outside the web root or protected by your server config.
  • Turn off directory listing. In Apache, add Options -Indexes (or set it in your host's control panel); in Nginx, ensure autoindex off; is in place. This stops the server from listing every file in folders that lack an index page.
  • Delete or block version-leaking files. On WordPress you can safely remove readme.html, and you can strip the generator meta tag and version query strings so your exact core version is not broadcast. See WordPress.org's hardening guidance for the safe way to do this.
  • Block sensitive paths at the server. Add rules to deny direct access to .git directories, .sql files, log files, and backup extensions, so even an unknown stray file is not served to the public.
  • Re-scan after you fix. Once you have moved or blocked the files, run the free scan again to confirm the paths now return not-found.

One scanner, not a pile of separate tools

It is worth saying plainly: BadgerScan is a single scanner. The exposed-files check, the email-spoofing check, the TLS check, the headers check, the DNS check, and the CVE matching all run together in one free external scan against your domain. You do not stitch together six different tools or read six different reports.

That single, plain-English report is the whole idea. CyberBadger is an owner-operated Hamilton and Burlington, Ontario firm, and we built BadgerScan so a small business owner can see their real outside-the-walls exposure without needing a security background. If you want the full picture and a human to help you act on it, that is what Pro and our security services are for. The broader playbook lives in our WordPress security guide.

See what's reachable from the public internet

Run BadgerScan's free external scan on your domain. In one pass it checks for exposed backups, config files, open directory listings, and version leaks, alongside your DNS, email security, TLS, and headers, all in one plain-English report.

Run a free security scan

Frequently asked questions

Is the exposed files check safe to run on my live site?

Yes. It is passive and read-only. BadgerScan requests common file paths the same way a normal visitor's browser would and reports what comes back. It never logs in, uploads, deletes, or exploits anything, and it never performs penetration testing.

Why is one exposed backup such a big deal?

A single database backup can contain everything an attacker needs: password hashes, customer data, API keys, and the secret salts that protect logged-in sessions. Unlike most attacks, grabbing a public backup takes no skill, just the right URL. That is why a single exposed backup is often treated as a full data breach.

Does a clean result mean no files are exposed anywhere?

No. A clean result means BadgerScan did not find sensitive files at the common, well-known paths it checks. It is strong reassurance, not a mathematical guarantee that nothing is exposed anywhere on your server. Good file hygiene and least-privilege server config remain important.

Will removing readme.html or hiding my version actually help?

It helps a little. Hiding your version does not patch anything, but it removes an easy signpost that tells attackers exactly which published vulnerabilities to try against you. The real fix is keeping software updated; pairing this external view with BadgerScan Pro's inside scan tells you which of your exact versions actually carry known CVEs.

Sources

  1. WordPress.org, Hardening WordPress

Related

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.