Quick answer
What does this usually mean?
Exposed files are often left behind after migrations, plugin debugging, hosting moves, or emergency fixes. A signal does not prove compromise, but it can justify fast cleanup and review.
What to check when backup, debug, log, or configuration-adjacent files may be publicly reachable on a WordPress site.
01 · Observed signal
Exposed files are often left behind after migrations, plugin debugging, hosting moves, or emergency fixes. A signal does not prove compromise, but it can justify fast cleanup and review.
02 · Evidence to inspect
Look for publicly reachable debug, log, backup, archive, SQL, and environment-like filenames.
03 · Safe next move
Run the free diagnostic to collect evidence before changing live orders or payment settings.
Start here
Exposed files are often left behind after migrations, plugin debugging, hosting moves, or emergency fixes. A signal does not prove compromise, but it can justify fast cleanup and review.
Possible causes
Evidence checks
Decision path
Use the smallest safe step that resolves uncertainty. Implementation comes after the evidence is clear.
Quick answer
Exposed files are often left behind after migrations, plugin debugging, hosting moves, or emergency fixes. A signal does not prove compromise, but it can justify fast cleanup and review.
First check
Look for publicly reachable debug, log, backup, archive, SQL, and environment-like filenames.
Need a human decision?
Use the free scanner as a first signal. If exposed files, backups or config-adjacent paths matter commercially, Security Snapshot gives an authorised public exposure review with evidence, limitations, fixes and retest proof.