● Linux CLI for x86_64 and ARM64 servers

Find every .env and wp-config file on your Linux server.

ServerSecretVault (ssv) finds .env, wp-config.php, Magento, Joomla and Drupal config files across every hosting account, flags world-readable files and backup copies inside web roots, and makes an age-encrypted backup. It never prints a secret.

$ curl -fsSL https://serversecretvault.com/install.sh | sudo sh
✓ Read-only scan ✓ No network requests ✓ No account required ✓ Restore with age and tar
root@web01: ~
$ sudo ssv scan
ServerSecretVault 0.2.0
Sensitive configuration files: 6
Laravel/home/alice/app/.env owner=alice:alice mode=0600 size=1184 sha256=2dbee5d49a1e… WordPress/home/alice/public_html/wp-config.php owner=alice:www-data mode=0640 size=3301 sha256=8e9c8696677e… WordPress/home/alice/public_html/wp-config.php.bak owner=alice:alice mode=0644 size=3301 sha256=8e9c8696677e…
Node.js/home/bob/public_html/.env owner=bob:bob mode=0644 size=412 sha256=123dc34ec1be… Node.js/home/bob/public_html/.env.example owner=bob:bob mode=0644 size=389 sha256=e9d25efc17b9… Magento/var/www/shop/app/etc/env.php owner=www-data:www-data mode=0660 size=1876 sha256=440b2e7377bc…
Values hidden. Nothing was modified.
$ sudo ssv audit
ServerSecretVault 0.2.0 — audit
Files: 6
SECURE1 REVIEW2 HIGH2 CRITICAL1
CRITICAL/home/alice/public_html/wp-config.php.bak
  • file is world-readable; review server isolation and ownership
  • filename looks like a backup or obsolete copy
  • backup-like secret file is under a common web document root and may be downloadable
HIGH/home/bob/public_html/.env
  • file is world-readable; review server isolation and ownership
  • .env file is under a common web document root; web-server deny rules should be verified
✓Values hidden. ✓Nothing was modified.
DISCOVER · AUDIT · PROTECT

Scan, audit and back up every config file that holds a secret.

01 Discover

Discover sensitive configuration and credential files across your entire server.

Automatically discover .env, WordPress, Laravel, Magento, Joomla and other credential-bearing configuration files.

How ssv scan works →
/home
├── acme/public_html
│   ├── wp-config.php       WordPress
│   └── wp-config.php.bak   backup
├── shop/app/etc/env.php    Magento
├── portal/configuration.php Joomla
└── api/.env.production     Laravel
02 Audit

Identify risky permissions and secrets inside web roots.

Flag world-readable and group-writable files, forgotten backup copies, and secrets stored inside web roots, where they may be downloadable.

Severity rules →
0600Secure 0640Usually acceptable 0644Review 0666Critical 0777Critical

Each file gets the highest severity any rule gives it: permissions, backup-like names and web-root location.

03 Protect

Create one strongly encrypted backup.

Securely archive important configuration files without creating plaintext temporary backups.

Encrypted backups with age →
files ↓ archive stream ↓ age encryption ↓ web01-20261007.age

No plaintext archive is written to disk.

WHAT IT FINDS

Which files does ServerSecretVault find?

Dotenv files

.env.env.production.env.local.env~

Dotenv templates

.env.example.env.sample.env.dist

WordPress

wp-config.phpwp-config.php.bakwp-config-old.php

Laravel, Symfony, Node.js

.envFramework named from the files beside it.

Magento 2

app/etc/env.phpenv.php.old

Joomla

configuration.phpconfiguration.php~

Drupal

sites/*/settings.phpsettings.php.save

Backup and editor copies

*.bak*.old*.save*~*.1

Yellow marks backup copies, the most dangerous files ssv finds: a web server runs wp-config.php as code, but sends wp-config.php.bak to anyone who asks for it, as plain text.

ssv won't find every secret on a server. Credentials in databases, environment variables or other files are out of scope. Full list of detected files →

HOW IT WORKS

Audit a Linux server for exposed secrets in three commands.

  1. 1

    Discover

    Searches /home, /var/www and /srv/www, where cPanel, Plesk, DirectAdmin and CloudPanel keep their sites, and recognises public_html, httpdocs and htdocs web roots. Use --root to search somewhere else.

    $ sudo ssv scan $ sudo ssv scan --root /var/www
  2. 2

    Audit

    Every file gets its owner, permissions, size, modification date, SHA-256 hash, web-root status and a severity: SECURE, REVIEW, HIGH or CRITICAL. Secret values are never displayed.

    $ sudo ssv audit
    CRITICAL/home/alice/public_html/wp-config.php.bak
    backup-like secret file is under a common web document root and may be downloadable
    HIGH/home/bob/public_html/.env
    .env file is under a common web document root; web-server deny rules should be verified
    REVIEW/home/alice/public_html/wp-config.php
    sensitive configuration is under a common web document root
  3. 3

    Protect

    Encrypt every file into one archive with age public keys (recommended, and works from cron), SSH keys or a passphrase. Files stream straight into age, so no plaintext archive is written. Needs the age tool installed.

    $ sudo ssv backup --recipient age1... --output /root/web01.age
SEVERITY RULES

How ssv rates each file it finds.

Every file gets the highest severity any rule gives it, with the reasons listed. ssv only reports; the fixes are yours to choose.

CRITICAL

  • Anyone on the server can modify the file
  • A backup or old copy is inside a web root

HIGH

  • The file's group can modify it
  • A .env file is inside a web root

REVIEW

  • Anyone on the server can read the file
  • The name looks like a backup or old copy
  • A template or other config file is inside a web root

SECURE

  • None of the above

"Inside a web root" means the file may be downloadable, not that it is. Confirm with curl -sI https://example.com/.env: you want 403 or 404, not 200. Severity rules and typical fixes →

AUTOMATION

Run it every night from cron, CI or monitoring.

  • --fail-on high exits with status 3 when any file is HIGH or worse.
  • --json output for jq, dashboards and tickets.
  • Key-based backups run unattended, and the decryption key never has to be on the server.
Cron example and exit codes →
$ sudo ssv audit --fail-on high >/dev/null ssv: 3 file(s) at or above HIGH $ echo $? 3
# /etc/cron.d/ssv: mail the report only when something is HIGH or worse 15 3 * * * root ssv audit --fail-on high >/var/log/ssv-audit.log 2>&1 || cat /var/log/ssv-audit.log
SECURITY

Your secrets never leave your server.

  • Runs locally
  • Read-only scanning by default
  • No account required
  • No credentials uploaded
  • Secret values hidden from reports
  • No plaintext backup archive
  • Open encryption format
Your Linux Server
ServerSecretVault
Discover Audit Protect
↓
encrypted backup.age
Nothing needs to pass through an external server.

Backups use the open age format. Even if ServerSecretVault disappeared, you can still decrypt them with standard tools.

How ssv handles your secrets →
DOTENV SCANNER

Why not just run find / -name ".env"?

$ find /home -name ".env"
/home/acme/public_html/.env
/home/api/.env
/home/customer/public_html/.env
Finds files.
$ sudo ssv audit
  • Finds files
  • Identifies applications
  • Checks permissions
  • Detects backup copies
  • Flags files inside web roots
  • Assigns risk
  • Creates encrypted backup
Dotenv files, templates and the backup copies it recognises
.env .env.production .env.local .env.example .env.sample .env.template .env.dist .env-old .env_backup .env~ .env copy env.bak
Explore the Dotenv Scanner →
FAQ

Frequently asked questions.

Is ServerSecretVault a secrets manager like HashiCorp Vault?

No. ServerSecretVault doesn't store, serve or rotate secrets. It finds the configuration files on a server that already hold them, rates their risk and makes encrypted backups. That inventory is a useful first step before moving secrets into a secrets manager.

Does ssv read or upload my secrets?

It reads file contents only to compute SHA-256 checksums and to make backups. It never prints secret values and never makes network requests, so nothing leaves the server. See how ssv handles your secrets.

Will it change permissions or delete backup copies?

No. ssv only reports. Each finding lists its reasons, and the audit docs give the typical fix for each severity.

How does it decide a file may be downloadable?

A file counts as inside a web root when it is in a directory named public_html, httpdocs, htdocs, webroot, www, web or public, which includes everything under /var/www and /srv/www. That means it may be downloadable, not that it is: ssv makes no network requests, so confirm with curl -sI https://example.com/.env and look for 403 or 404.

Do I need root?

Only to see other accounts' files. Without root, ssv sees the files your own account can read. Run it with sudo to cover every hosting account.

What do I need for encrypted backups, and how do I restore one?

ssv backup needs the age encryption tool (apt install age or dnf install age). Restoring needs only age and tar, not ssv. See restoring from a backup.

Which Linux servers does it run on?

Any Linux server with an x86_64 or ARM64 processor, including Ubuntu, Debian, RHEL, Rocky Linux, AlmaLinux and CloudLinux. ssv is a single self-contained program with no runtime or libraries to install.

Can I run it from cron or CI?

Yes. ssv audit --fail-on high exits with status 3 when any file is HIGH or worse, and --json gives machine-readable output. See running ssv on a schedule.

How do I verify the download?

The installer checks each package against its SHA-256 checksum and stops if they don't match. To check by hand, download SHA256SUMS next to the package and run sha256sum -c --ignore-missing SHA256SUMS. See the install guide.

How do I uninstall it?

Delete /usr/local/bin/ssv, and /usr/bin/ssv if the installer created that link. ssv creates no configuration files, services or caches.

Install ServerSecretVault in one command.

$ curl -fsSL https://serversecretvault.com/install.sh | sudo sh
$ sudo ssv scan
$ sudo ssv audit
ssv 0.2.0 · Linux packages SHA256SUMS
x86_64 amd64ssv-0.2.0-linux-amd64.tar.gz 1.1 MB ↓ ARM64 aarch64ssv-0.2.0-linux-arm64.tar.gz 1.0 MB ↓

ssv is proprietary software. Downloading or installing it means accepting its license.

UbuntuDebianAlmaLinuxRocky LinuxCloudLinux

Backups also need age. If it's missing, ssv backup prints the commands that install it on your server. How to install age