SECURITY FINDING
Exposed wp-config.php~ editor backup file
What it is
An editor backup copy of wp-config.php (wp-config.php~, left behind by some text editors) is publicly downloadable, exposing the same database credentials as the real file.
How to fix it
Delete this backup file from the server immediately (or move it outside the web root) — the WordPress Plugin's Security tab can block access to files like this automatically.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.