Exposed .env File: How to Check If Your Website Leaks Its Passwords

Updated 6 min read

A .env file is a plain text list of the passwords and keys your website uses: the database password, the email account, payment and cloud keys. It belongs on the server, but out of public reach. If anyone can open yoursite.com/.env in a browser, treat everything in it as stolen.

In short

  • Open yoursite.com/.env in a private window. You should get an error page, not a list of settings.
  • Bots look for this file on a huge scale: one criminal campaign checked more than 230 million addresses, Unit 42 reported in 2024.
  • If yours was open, block or remove it, then change every password and key inside. Deleting the file doesn’t undo the leak.

What a .env file is

Many web frameworks, such as Laravel, keep the settings that differ between a developer’s laptop and the live site in a file called .env. It looks something like this, with real values instead of the dots:

APP_KEY=base64:...
DB_PASSWORD=...
MAIL_PASSWORD=...
STRIPE_SECRET=sk_live_...
AWS_SECRET_ACCESS_KEY=...

Each line is a key to something: your database, your email account, your payments, your cloud storage. Laravel’s documentation says the file shouldn’t go into source control either, because anyone who got into the code repository would see every credential in it.

WordPress keeps the same kind of secrets in wp-config.php. That file is normally safe, because the server runs it as code instead of showing it. Copies with other endings, such as wp-config.php.bak, can be handed out as plain text.

How it ends up public

  • The whole project sits in the public folder. Laravel expects only its public folder to be reachable from the web. Its deployment guide warns that serving the application from the project root will expose many sensitive configuration files to the internet.
  • The server hands out files that start with a dot. Unless it’s told not to, a web server can serve .env like any other file. Laravel’s own sample nginx configuration includes a rule that refuses all such files, except the .well-known folder.
  • Copies and backups: .env.bak, .env.old, .env.save or a zipped backup left in the web folder.
  • Debug mode left on. Laravel warns that with APP_DEBUG set to true on a live site, error pages risk exposing sensitive configuration values to visitors.

Who is looking for it

  • In August 2024, Unit 42, the research team at Palo Alto Networks, described a criminal campaign that scanned more than 230 million addresses by requesting /.env from each one. It found exposed files on 110,000 domains and collected more than 90,000 unique variables, including 7,000 for cloud services and 1,515 for social media accounts. The attackers then copied data out of victims’ cloud storage, deleted it, and left ransom notes. Unit 42 traced the problem to misconfiguration by the victims, not to a flaw in any vendor’s product.
  • In January 2024, CISA and the FBI warned about Androxgh0st, malware that runs a botnet to find Laravel sites with an exposed .env file and steal the credentials inside, such as AWS keys, email (SMTP) logins, and Office 365, SendGrid and Twilio accounts.

Check your site in a minute

  1. Open a private window and go to https://yoursite.com/.env.
  2. Safe: a “404 Not Found” or “403 Forbidden” page, or your site’s normal “page not found” page.
  3. Not safe: lines like DB_PASSWORD= or APP_KEY=. Close the tab and go to the next section.
  4. Try the usual copies too: /.env.bak, /.env.old and /.env.production, and on WordPress /wp-config.php.bak and /wp-config.php.old.

If your site runs on Shopify, Wix or Squarespace, there’s no .env file of yours on the web. The same idea still applies to any keys you paste into custom code: see API keys in your code.

If it was open: what to do, in this order

1. Block it or move it

Take the file out of the public folder, or ask your developer or host to block it. On Apache hosting, that’s a rule in the .htaccess file:

<FilesMatch "^\.env">
  Require all denied
</FilesMatch>

On nginx, Laravel’s sample configuration uses:

location ~ /\.(?!well-known).* {
    deny all;
}

Then open the address again in a private window to check it’s gone.

2. Change every password and key in it

Start with the database, email, payment and cloud keys. Blocking the file stops new visitors, but anyone who opened it before still has a copy, and the Unit 42 campaign shows stolen keys being used afterwards. Changing a key is the only thing that makes the old one useless.

3. Look for signs they were used

Check your cloud account for users, keys or servers you didn’t create, your email account for messages you didn’t send, and your payment dashboard for activity you don’t recognise.

4. Decide whether you have to report it

If the file gave access to personal data, such as a customer database, and that’s likely to put people’s rights and freedoms at risk, UK organisations must report it to the ICO within 72 hours of becoming aware of it.

Where secrets should live instead

  • On hosting platforms such as Vercel, you enter these values in the project’s settings as environment variables. Vercel keeps them encrypted and outside your code, so they never sit in a file on the web.
  • On your own server, keep the .env file outside the public folder, readable only by you and the web server.
  • In a code repository, never commit a plain .env file. If you need it there, Laravel can encrypt it first with php artisan env:encrypt.

What Teyna checks

Teyna’s free check looks for settings files, backups and forgotten copies that your site hands out to anyone, including .env files and copies like wp-config.php.bak. When it finds one, it asks for the file twice, about 30 seconds apart, and checks that a made-up file name gets a plain “not found”, so a server that answers yes to everything isn’t reported as a leak. It reads only enough to tell what the file is, and never stores the passwords inside. On Pro, it also reads your code repositories for settings files that shouldn’t be there and keys still hiding in old commits.

Is your website safe? Find out in a minute.

The free check reads only what anyone on the internet can already see: the padlock, email protection, open backups and signs of a hack. No sign-up and no card. We only ask for your email to send you the link to your report.

Scan my site for free

Questions

Is it safe to have a .env file on my server?

Yes, as long as the web can’t reach it. It should sit outside the folder your site is served from, or the server should refuse to hand it out. The one-minute check above tells you which situation you’re in.

I’ve deleted the exposed file. Am I safe now?

Not yet. Anyone who opened it before you deleted it still has the passwords and keys. Change every one of them, starting with the database, email, payment and cloud accounts.

How quickly do attackers find an exposed .env file?

Nobody publishes a reliable average, but the searching is automated and enormous: the campaign Unit 42 described checked more than 230 million addresses, and Androxgh0st uses a botnet to scan for exposed files. If yours was open, assume it was found.

Does this affect WordPress sites?

WordPress uses wp-config.php instead, which is safe as long as the server runs it as PHP. The risk is copies with a different ending, like wp-config.php.bak or wp-config.php.old, which a server may hand out as plain text. Check for those the same way.

Should my .env file be in Git?

No. Laravel’s documentation says it shouldn’t be committed to source control, because anyone who got into the repository would see every credential. If you need it there, encrypt it first with Laravel’s built-in command.

sources