ServerSecretVault documentation
ssv finds the configuration files on a Linux web server that hold secrets (database passwords, API keys), checks them for risky permissions and copies inside web roots, and makes encrypted backups of them.
ssv scanlists the files.ssv auditrates each file's risk.ssv backupwrites an encrypted archive of them.
ssv never prints secret values and never modifies, moves or deletes your files. It reads file contents only to compute checksums and to make backups.
Quick start
sudo ssv scan # what's on this server?
sudo ssv audit # which files are at risk?
sudo ssv backup --recipient age1... --output /root/web01.age
Run it with sudo to see every hosting account's files. To install it, run curl -fsSL https://serversecretvault.com/install.sh | sudo sh, or see Download and install for other ways.
What ssv looks for
| Application | Files |
|---|---|
| Dotenv (Laravel, Symfony, Node.js and others) | .env and variants such as .env.production, .env.local, .env-old, .env_backup, .env~, .env copy, env.bak |
| Dotenv templates | .env.example, .env.sample, .env.template, .env.dist |
| WordPress | wp-config.php and renamed copies such as wp-config-old.php (wp-config-sample.php is ignored) |
| Magento 2 | app/etc/env.php |
| Joomla | configuration.php |
| Drupal | sites/*/settings.php |
ssv also finds backup and editor copies of all of these, for example wp-config.php.bak, configuration.php~, env.php.old, settings.php.save, configuration-old.php and configuration.php.1. These copies are the most dangerous files ssv finds. A web server runs wp-config.php as code, but it sends wp-config.php.bak to anyone who asks for it, as plain text.
For dotenv files, ssv names the framework (Laravel, Symfony or Node.js) when it sees that framework's files in the same directory.
ssv won't find every secret on a server. Credentials in other files, databases or environment variables are out of scope.
In these docs
- Download and install: the one-line installer, manual installation with checksum verification, and installing
age. - ssv scan: list every file that holds secrets, choose where to look, and get JSON output.
- ssv audit: the severity rules, what counts as a web root, and the typical fix for each severity.
- Encrypted backups: back up with age keys or a passphrase, and restore with standard tools.
- Run ssv on a schedule: nightly audits and backups from cron, and exit codes for scripts.
- Troubleshooting: common error messages and what to do about them.
- Security: what ssv reads and writes, its security model and limits, verifying a download, and reporting a vulnerability.
Last updated 2026-10-08 · for ssv 0.2.0