Publicly accessibile .user.ini file
-
Hi Wordfence,
A critical issue was found on a WF scan:
Details: https://example.com/.user.ini is publicly accessible and may expose source code or sensitive information about your site. Files such as this one are commonly checked for by scanners and should be made inaccessible. Alternately, some can be removed if you are certain your site does not need them. Sites using the nginx web server may need manual configuration changes to protect such files. Learn more
The contents of the file are:
; Wordfence WAF auto_prepend_file = '/opt/bitnami/wordpress/wordfence-waf.php' ; END Wordfence WAF
Should this file be deleted?
The file permission is 664
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘Publicly accessibile .user.ini file’ is closed to new replies.