WP Clinic
Log in Sign up

SECURITY FINDING

Exposed .env file with secrets

What it is

A .env file is publicly downloadable. These files commonly hold API keys, database credentials or other secrets for the site or its plugins.

How to fix it

Delete or move this file outside the web root, and rotate any credential it contained — the WordPress Plugin's Security tab can block access to files like this automatically.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.