Free Exposed Files Scanner

Check whether your site accidentally exposes .env, .git/config, backup archives, or other high-risk files.

Frequently asked

Do you download the file contents?

No. The tool only issues HEAD requests to check whether the file is served (HTTP status). It never reads or returns file contents.

Which paths are checked?

A small allow-list of the most commonly leaked files: /.env, /.git/config, /.git/HEAD, /backup.zip, /wp-config.php.bak, /.DS_Store, /config.json, /api/swagger.json.

Related tools

  • SSL Checker · Instantly verify a site's SSL certificate · issuer, expiration date, TLS version, and hostname match.
  • Security Headers Checker · Get an A-F grade on your site's HTTP security headers, including CSP, HSTS, and cross-origin isolation policies.
  • Email Security Checker · Check your domain's email authentication · SPF, DKIM, and DMARC · and see if you're vulnerable to spoofing.

Run a full security scan →