SECURITY FINDING
Publicly exposed file or information
What it is
Our scan found information or a file on this site that's publicly accessible and shouldn't be — this can range from revealing internal details (like software versions or usernames) to exposing actual credentials, depending on what was found (see the detail above).
How to fix it
Remove or restrict access to what was found. If you're not sure how, install the WordPress Plugin: its Security tab blocks most of these exposures automatically.
In depth
Your WordPress site is exposing a file or piece of information that shouldn't be visible to the public, similar to leaving a document with sensitive details on your front desk where anyone walking by can read it. This happens because WordPress creates certain files during normal operation, or plugins and themes sometimes leave behind configuration files or backup copies that remain accessible to anyone who visits your site. This matters because someone could use this exposed information to understand how your site is built, find security weaknesses, or potentially access passwords and usernames if credentials are accidentally left visible. The fix depends on what was actually exposed, but the easiest solution is to install the Wordfence Security plugin, which automatically detects and blocks these common exposures without you needing to understand the technical details. If you want to handle it manually, you can ask your hosting provider to hide or delete the exposed file, or use an .htaccess file to block public access to sensitive folders, though this requires some technical knowledge. The security plugin approach is faster and more reliable for most site owners because it continuously monitors for these problems rather than requiring you to remember to check manually.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.