Exposed Backup and Temporary Files

Medium Severity Technical Guide

Vulnerability Description

Leaving compressed archives, .bak, .zip, or .old files in the public directory allows attackers to download snapshots of your source code and configurations.

Remediation Guide

To resolve this vulnerability, follow these config changes or developer practices:

Never perform database backups or save temporary files in the public directory of your web server. Automate cleanups of editor swap files (e.g. .swp).

Verify Your Fix

After applying the remediation, run an external attack-surface scan to verify that the vulnerability is no longer detected by WebScanify.

Is your website vulnerable?

Run a free security scan now to identify missing headers, outdated JS, and other deployment vulnerabilities.