ssv audit: rate each file's risk

ssv audit scans like ssv scan, then gives every file a severity (SECURE, REVIEW, HIGH or CRITICAL) and the reasons for it. It only reports: nothing on the server is changed.

sudo ssv audit
ServerSecretVault 0.2.0 โ€” audit

Files: 6  SECURE: 1  REVIEW: 2  HIGH: 2  CRITICAL: 1

[CRITICAL] /home/alice/public_html/wp-config.php.bak
  - file is world-readable; review server isolation and ownership
  - filename looks like a backup or obsolete copy
  - backup-like secret file is under a common web document root and may be downloadable
[HIGH] /home/bob/public_html/.env
  - file is world-readable; review server isolation and ownership
  - .env file is under a common web document root; web-server deny rules should be verified
[HIGH] /var/www/shop/app/etc/env.php
  - file is group-writable
  - sensitive configuration is under a common web document root
[REVIEW] /home/alice/public_html/wp-config.php
  - sensitive configuration is under a common web document root
[REVIEW] /home/bob/public_html/.env.example
  - file is world-readable; review server isolation and ownership
  - dotenv template is under a common web document root; verify it holds no real credentials
[SECURE] /home/alice/app/.env
  - no obvious filesystem exposure issue detected

Values hidden. Nothing was modified.

Severity rules

Files are listed most severe first. Each file gets the highest severity that any rule gives it:

Rule Severity
Anyone on the server can modify the file (world-writable) CRITICAL
A backup or old copy is under a web root CRITICAL
The file's group can modify it (group-writable) HIGH
A .env file is under a web root HIGH
Anyone on the server can read the file (world-readable) REVIEW
The name looks like a backup or old copy REVIEW
A dotenv template or other configuration file is under a web root REVIEW
None of the above SECURE

What counts as a web root

A path counts as under a web root when it is inside a directory named public_html, httpdocs, htdocs, webroot, www, web or public. That includes everything under /var/www and /srv/www; Debian's default Apache configuration allows web access to everything under /var/www.

"Under a web root" means the file may be downloadable, not that it is. ssv makes no network requests. To check a site yourself, request the file and confirm you get 403 or 404, not 200:

curl -sI https://example.com/.env | head -1
curl -sI https://example.com/wp-config.php.bak | head -1

What to do about each severity

ssv reports only; making changes is up to you.

Severity Typical fix
CRITICAL Delete stray backup copies from the web root once you've confirmed nothing uses them, or move them out of it. Remove write access for others: chmod o-w FILE.
HIGH Remove group write access (chmod g-w FILE). Move .env files out of the web root, or make sure the web server refuses to serve dotfiles, and check with curl as above.
REVIEW Make sure only the owner and, if needed, the web server's group can read the file, for example chmod 640 with the web server's group, or chmod 600. On shared servers, 0644 lets every account read the file. Check templates contain no real credentials.
SECURE Nothing obvious to fix.

Failing on findings

For scripts and scheduled checks, --fail-on makes ssv exit with status 3 when any file is at or above a severity (review, high or critical):

sudo ssv audit --fail-on high
ssv: 3 file(s) at or above HIGH

The report is printed as usual, and the summary line above goes to standard error.

JSON output

sudo ssv audit --json gives the same data/warnings structure as scan. Each item has the file under finding plus severity and reasons. For example, to list just the serious files with jq:

sudo ssv audit --json | jq -r '.data[] | select(.severity == "CRITICAL" or .severity == "HIGH") | "\(.severity) \(.finding.path)"'
CRITICAL /home/alice/public_html/wp-config.php.bak
HIGH /home/bob/public_html/.env
HIGH /var/www/shop/app/etc/env.php

Last updated 2026-10-08 ยท for ssv 0.2.0