Website Exposed Files Scanner
We scan 189 paths for exposed .env files, API keys, and AI system prompts. Find out what attackers can see in seconds. Free and no signup.
What Our Security Scanner Detects
We check 9 categories of sensitive files across 189 common paths.
| Category | Files Checked | Risk Level | Paths |
|---|---|---|---|
| AI / LLM Files | SKILL.md, .cursorrules, CLAUDE.md, system prompts | HIGH | 36 paths |
| Secrets & Env Files | .env, API keys, Firebase config, AWS credentials | CRITICAL | 27 paths |
| Git Exposure | .git/config, HEAD, refs | CRITICAL | 10 paths |
| Package & Build | package.json, Dockerfile, netlify.toml | MEDIUM | 31 paths |
| Server Config | wp-config.php, .htaccess, phpinfo | HIGH | 19 paths |
| Backups & Debug | SQL dumps, error logs, .DS_Store | HIGH | 22 paths |
How It Works
A simple, non-invasive process to secure your domain in seconds.
Enter Domain
Simply type in the domain name you want to check. No signup or installation required.
Fast Scanning
Our tool makes lightweight HTTP requests to 189 commonly exposed sensitive file paths.
Get Report
Review your findings instantly. Secure exposed files and protect your web application.
Pricing
From free scans to continuous monitoring
Free
- 5 scans per day
- All 189 paths
- Severity ratings
- Shareable report link
Pro
- Unlimited scans
- Weekly monitoring on 5 domains
- Email & Slack alerts
- File content previews
- Scan history & trends
- PDF reports
Agency
- Everything in Pro
- 50 monitored domains
- White-label PDF reports
- Client dashboard
- Bulk CSV scan import
- API access
FAQ
Is it legal to scan someone else's domain?
Is it safe to run a scan on my website?
Will you store or share my scan results?
What exactly do you scan for?
Does the free scan affect my site's performance?
What's the difference between this and a full penetration test?
Why did my scan show a false positive?
How often should I scan my domain?
What happens when you find something exposed?
Can I scan subdomains?
What's in the shareable report link?
How does continuous monitoring work?
What is an exposed .env file and why is it dangerous?
What is Git directory exposure?
See what attackers can see on your domain
Run a free exposure scan in under 15 seconds. No signup required.