A .env file is a plain text list of the passwords and keys your website uses: the database password, the email account, payment and cloud keys. It belongs on the server, but out of public reach. If anyone can open yoursite.com/.env in a browser, treat everything in it as stolen.
In short
- Open
yoursite.com/.envin a private window. You should get an error page, not a list of settings. - Bots look for this file on a huge scale: one criminal campaign checked more than 230 million addresses, Unit 42 reported in 2024.
- If yours was open, block or remove it, then change every password and key inside. Deleting the file doesn’t undo the leak.
What a .env file is
Many web frameworks, such as Laravel, keep the settings that differ between a developer’s laptop and the live site in a file called .env. It looks something like this, with real values instead of the dots:
APP_KEY=base64:...
DB_PASSWORD=...
MAIL_PASSWORD=...
STRIPE_SECRET=sk_live_...
AWS_SECRET_ACCESS_KEY=...
Each line is a key to something: your database, your email account, your payments, your cloud storage. Laravel’s documentation says the file shouldn’t go into source control either, because anyone who got into the code repository would see every credential in it.
WordPress keeps the same kind of secrets in wp-config.php. That file is normally safe, because the server runs it as code instead of showing it. Copies with other endings, such as wp-config.php.bak, can be handed out as plain text.
How it ends up public
- The whole project sits in the public folder. Laravel expects only its
publicfolder to be reachable from the web. Its deployment guide warns that serving the application from the project root will expose many sensitive configuration files to the internet. - The server hands out files that start with a dot. Unless it’s told not to, a web server can serve
.envlike any other file. Laravel’s own sample nginx configuration includes a rule that refuses all such files, except the.well-knownfolder. - Copies and backups:
.env.bak,.env.old,.env.saveor a zipped backup left in the web folder. - Debug mode left on. Laravel warns that with
APP_DEBUGset to true on a live site, error pages risk exposing sensitive configuration values to visitors.
Who is looking for it
- In August 2024, Unit 42, the research team at Palo Alto Networks, described a criminal campaign that scanned more than 230 million addresses by requesting
/.envfrom each one. It found exposed files on 110,000 domains and collected more than 90,000 unique variables, including 7,000 for cloud services and 1,515 for social media accounts. The attackers then copied data out of victims’ cloud storage, deleted it, and left ransom notes. Unit 42 traced the problem to misconfiguration by the victims, not to a flaw in any vendor’s product. - In January 2024, CISA and the FBI warned about Androxgh0st, malware that runs a botnet to find Laravel sites with an exposed
.envfile and steal the credentials inside, such as AWS keys, email (SMTP) logins, and Office 365, SendGrid and Twilio accounts.
Check your site in a minute
- Open a private window and go to
https://yoursite.com/.env. - Safe: a “404 Not Found” or “403 Forbidden” page, or your site’s normal “page not found” page.
- Not safe: lines like
DB_PASSWORD=orAPP_KEY=. Close the tab and go to the next section. - Try the usual copies too:
/.env.bak,/.env.oldand/.env.production, and on WordPress/wp-config.php.bakand/wp-config.php.old.
If your site runs on Shopify, Wix or Squarespace, there’s no .env file of yours on the web. The same idea still applies to any keys you paste into custom code: see API keys in your code.
If it was open: what to do, in this order
1. Block it or move it
Take the file out of the public folder, or ask your developer or host to block it. On Apache hosting, that’s a rule in the .htaccess file:
<FilesMatch "^\.env">
Require all denied
</FilesMatch>
On nginx, Laravel’s sample configuration uses:
location ~ /\.(?!well-known).* {
deny all;
}
Then open the address again in a private window to check it’s gone.
2. Change every password and key in it
Start with the database, email, payment and cloud keys. Blocking the file stops new visitors, but anyone who opened it before still has a copy, and the Unit 42 campaign shows stolen keys being used afterwards. Changing a key is the only thing that makes the old one useless.
3. Look for signs they were used
Check your cloud account for users, keys or servers you didn’t create, your email account for messages you didn’t send, and your payment dashboard for activity you don’t recognise.
4. Decide whether you have to report it
If the file gave access to personal data, such as a customer database, and that’s likely to put people’s rights and freedoms at risk, UK organisations must report it to the ICO within 72 hours of becoming aware of it.
Where secrets should live instead
- On hosting platforms such as Vercel, you enter these values in the project’s settings as environment variables. Vercel keeps them encrypted and outside your code, so they never sit in a file on the web.
- On your own server, keep the
.envfile outside the public folder, readable only by you and the web server. - In a code repository, never commit a plain
.envfile. If you need it there, Laravel can encrypt it first withphp artisan env:encrypt.
What Teyna checks
Teyna’s free check looks for settings files, backups and forgotten copies that your site hands out to anyone, including .env files and copies like wp-config.php.bak. When it finds one, it asks for the file twice, about 30 seconds apart, and checks that a made-up file name gets a plain “not found”, so a server that answers yes to everything isn’t reported as a leak. It reads only enough to tell what the file is, and never stores the passwords inside. On Pro, it also reads your code repositories for settings files that shouldn’t be there and keys still hiding in old commits.