WP Clinic
Log in Sign up

SECURITY FINDING

Exposed wp-config.php~ editor backup file

What it is

An editor backup copy of wp-config.php (wp-config.php~, left behind by some text editors) is publicly downloadable, exposing the same database credentials as the real file.

How to fix it

Delete this backup file from the server immediately (or move it outside the web root) — the WordPress Plugin's Security tab can block access to files like this automatically.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.