| .env.production183 B · SHA-256 c7ba5fd40063… | Sensitive exposure Environment configuration may expose credentials or secrets3 matched signals- Environment configuration may expose credentials or secrets
sensitive.environment_file - Credential assignment marker detected without displaying its value
sensitive.credential_assignment - Finding is in a commonly web-accessible location
sensitive.exposed_location
| Critical100/100High confidence | production text/plain | 2026-09-24 12:51:19 | |
| wp-config.php.bak222 B · SHA-256 0a81dcbe22ef… | Sensitive exposure Unexpected WordPress configuration copy or backup4 matched signals- Unexpected WordPress configuration copy or backup
sensitive.wp_config_backup - Backup or editor copy may expose the original file contents
sensitive.backup_copy - WordPress database credential marker detected in an unexpected file
sensitive.wordpress_credentials - Finding is in a commonly web-accessible location
sensitive.exposed_location
| Critical100/100High confidence | bak text/x-php | 2026-09-24 12:51:19 | |
| wp-content/uploads/2026/09/avatar.php.jpg145 B · SHA-256 0fd32e987b4e… | Upload threat PHP-like double extension may disguise executable content4 matched signals- PHP-like double extension may disguise executable content
uploads.double_extension - File uses an image extension but has no valid image header
uploads.invalid_image - Detected MIME type conflicts with the image extension
uploads.mime_mismatch - PHP code marker detected inside the uploaded file
uploads.embedded_php
| Critical100/100High confidence | jpg text/x-php | 2026-09-24 12:51:19 | |
| wp-content/uploads/2026/09/shell_console.phtml92 B · SHA-256 be517c8a07b6… | Upload threat Server-executable file type found in Media uploads2 matched signals- Server-executable file type found in Media uploads
uploads.server_executable - PHP code marker detected inside the uploaded file
uploads.embedded_php
| Critical100/100High confidence | phtml text/x-php | 2026-09-24 12:51:19 | |
| wp-content/uploads/2026/web_shell.php300 B · SHA-256 47da41221ef6… | Upload threat Server-executable file type found in Media uploads2 matched signals- Server-executable file type found in Media uploads
uploads.server_executable - PHP code marker detected inside the uploaded file
uploads.embedded_php
| Critical100/100High confidence | php text/x-php | 2026-09-24 12:51:19 | |
| private-demo.key110 B · SHA-256 49ef4e569c95… | Sensitive exposure Private key or credential container found under the web root2 matched signals- Private key or credential container found under the web root
sensitive.private_key - Finding is in a commonly web-accessible location
sensitive.exposed_location
| Critical90/100High confidence | key text/plain | 2026-09-24 12:51:18 | |
| mysql_backup.sql457 B · SHA-256 61d39d19f54a… | Sensitive exposure Database file or dump may expose site data and credentials2 matched signals- Database file or dump may expose site data and credentials
sensitive.database_dump - Finding is in a commonly web-accessible location
sensitive.exposed_location
| Critical85/100High confidence | sql text/plain | 2026-09-24 12:51:18 | |
| wp-content/plugins/wordpress_store_2026.sql198 B · SHA-256 c4a247d189d9… | Sensitive exposure Database file or dump may expose site data and credentials1 matched signal- Database file or dump may expose site data and credentials
sensitive.database_dump
| High70/100High confidence | sql text/plain | 2026-09-24 12:51:19 | |
| wp-content/themes/credentials-demo.yml137 B · SHA-256 f5ce8c94761b… | Sensitive exposure Credential assignment marker detected without displaying its value1 matched signal- Credential assignment marker detected without displaying its value
sensitive.credential_assignment
| Medium55/100Medium confidence | yml text/plain | 2026-09-24 12:51:18 | |
| database_archive.sql.bak125 B · SHA-256 40b8e0f0bea1… | Sensitive exposure Backup or editor copy may expose the original file contents2 matched signals- Backup or editor copy may expose the original file contents
sensitive.backup_copy - Finding is in a commonly web-accessible location
sensitive.exposed_location
| Medium50/100Medium confidence | bak text/plain | 2026-09-24 12:51:18 | |
| site-backup-demo.zip404 B · SHA-256 f801102cd636… | Sensitive exposure Backup or source archive may be downloadable from the web root2 matched signals- Backup or source archive may be downloadable from the web root
sensitive.public_archive - Finding is in a commonly web-accessible location
sensitive.exposed_location
| Medium50/100Medium confidence | zip application/zip | 2026-09-24 12:51:19 | |
| wp-content/debug.log99 B · SHA-256 3185012f2485… | Sensitive exposure Diagnostic or system file may disclose sensitive information1 matched signal- Diagnostic or system file may disclose sensitive information
sensitive.diagnostic_or_system_file
| Medium45/100Medium confidence | log text/plain | 2026-09-24 12:51:18 | |