SECURITY FINDING
Exposed WordPress debug.log file
What it is
WordPress's debug.log file is publicly downloadable. It can contain file paths, plugin/theme errors and, occasionally, sensitive data from failed operations — all useful reconnaissance for an attacker.
How to fix it
Delete this file, and disable public access to debug.log — the WordPress Plugin's Security tab can block access to files like this automatically.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.