WP Clinic
Log in Sign up

SECURITY FINDING

Exposed WordPress debug.log file

What it is

WordPress's debug.log file is publicly downloadable. It can contain file paths, plugin/theme errors and, occasionally, sensitive data from failed operations — all useful reconnaissance for an attacker.

How to fix it

Delete this file, and disable public access to debug.log — the WordPress Plugin's Security tab can block access to files like this automatically.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.