Skip to main content
VaultDevLabs
Evidence guide

WordPress exposed files checklist

What to check when backup, debug, log, or configuration-adjacent files may be publicly reachable on a WordPress site.

Evidence before edits
No automatic changes
Clear next action
Decision map

01 · Observed signal

Exposed files are often left behind after migrations, plugin debugging, hosting moves, or emergency fixes. A signal does not prove compromise, but it can justify fast cleanup and review.

02 · Evidence to inspect

Look for publicly reachable debug, log, backup, archive, SQL, and environment-like filenames.

03 · Safe next move

Run the free diagnostic to collect evidence before changing live orders or payment settings.

Start here

Understand the problem before changing the system.

Exposed files are often left behind after migrations, plugin debugging, hosting moves, or emergency fixes. A signal does not prove compromise, but it can justify fast cleanup and review.

Possible causes

What may have interrupted the expected path.

  • Old backups, exports, or zip files were left in public web directories.
  • Debug logs or temporary files were created during troubleshooting and never removed.
  • Server rules do not block access to sensitive file extensions or common WordPress paths.
  • A staging or migration process copied operational files into the public site root.

Evidence checks

What to verify first.

  • Look for publicly reachable debug, log, backup, archive, SQL, and environment-like filenames.
  • Review hosting file manager or deployment artifacts for files that should not be web-accessible.
  • Check whether web server rules block common sensitive extensions.
  • Remove exposed files and rotate secrets if any sensitive values were exposed.

Decision path

Move from signal to evidence to action.

Use the smallest safe step that resolves uncertainty. Implementation comes after the evidence is clear.

  1. 01Run the free diagnostic to collect evidence before changing live orders or payment settings.
  2. 02Request a Payment Rescue Review if the evidence is unclear or the risk affects customers, fulfilment, or support.
  3. 03Custom setup or fix work is quoted after review, once the likely cause and scope are clear.

Quick answer

What does this usually mean?

Exposed files are often left behind after migrations, plugin debugging, hosting moves, or emergency fixes. A signal does not prove compromise, but it can justify fast cleanup and review.

First check

What should be checked first?

Look for publicly reachable debug, log, backup, archive, SQL, and environment-like filenames.

Need a human decision?

Check the evidence before changing a live system.

Use the free scanner as a first signal. If exposed files, backups or config-adjacent paths matter commercially, Security Snapshot gives an authorised public exposure review with evidence, limitations, fixes and retest proof.