Wordpress Alert: Public .git directories
A deployed repository directory is web-accessible. Source code and sometimes secrets may be retrievable.
What it looks like
A deployed repository directory is web-accessible.
Why it matters
Source code and sometimes secrets may be retrievable.
What to check
Keep repository metadata outside the web root or deny access.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress hardening guide.
- Categories: WordPress
- Tags: #WordPress Security, #Hosting Security