ssv audit: rate each file's risk
ssv audit scans like ssv scan, then gives every file a severity (SECURE, REVIEW, HIGH or CRITICAL) and the reasons for it. It only reports: nothing on the server is changed.
sudo ssv audit
ServerSecretVault 0.2.0 โ audit
Files: 6 SECURE: 1 REVIEW: 2 HIGH: 2 CRITICAL: 1
[CRITICAL] /home/alice/public_html/wp-config.php.bak
- file is world-readable; review server isolation and ownership
- filename looks like a backup or obsolete copy
- backup-like secret file is under a common web document root and may be downloadable
[HIGH] /home/bob/public_html/.env
- file is world-readable; review server isolation and ownership
- .env file is under a common web document root; web-server deny rules should be verified
[HIGH] /var/www/shop/app/etc/env.php
- file is group-writable
- sensitive configuration is under a common web document root
[REVIEW] /home/alice/public_html/wp-config.php
- sensitive configuration is under a common web document root
[REVIEW] /home/bob/public_html/.env.example
- file is world-readable; review server isolation and ownership
- dotenv template is under a common web document root; verify it holds no real credentials
[SECURE] /home/alice/app/.env
- no obvious filesystem exposure issue detected
Values hidden. Nothing was modified.
Severity rules
Files are listed most severe first. Each file gets the highest severity that any rule gives it:
| Rule | Severity |
|---|---|
| Anyone on the server can modify the file (world-writable) | CRITICAL |
| A backup or old copy is under a web root | CRITICAL |
| The file's group can modify it (group-writable) | HIGH |
A .env file is under a web root |
HIGH |
| Anyone on the server can read the file (world-readable) | REVIEW |
| The name looks like a backup or old copy | REVIEW |
| A dotenv template or other configuration file is under a web root | REVIEW |
| None of the above | SECURE |
What counts as a web root
A path counts as under a web root when it is inside a directory named public_html, httpdocs, htdocs, webroot, www, web or public. That includes everything under /var/www and /srv/www; Debian's default Apache configuration allows web access to everything under /var/www.
"Under a web root" means the file may be downloadable, not that it is. ssv makes no network requests. To check a site yourself, request the file and confirm you get 403 or 404, not 200:
curl -sI https://example.com/.env | head -1
curl -sI https://example.com/wp-config.php.bak | head -1
What to do about each severity
ssv reports only; making changes is up to you.
| Severity | Typical fix |
|---|---|
| CRITICAL | Delete stray backup copies from the web root once you've confirmed nothing uses them, or move them out of it. Remove write access for others: chmod o-w FILE. |
| HIGH | Remove group write access (chmod g-w FILE). Move .env files out of the web root, or make sure the web server refuses to serve dotfiles, and check with curl as above. |
| REVIEW | Make sure only the owner and, if needed, the web server's group can read the file, for example chmod 640 with the web server's group, or chmod 600. On shared servers, 0644 lets every account read the file. Check templates contain no real credentials. |
| SECURE | Nothing obvious to fix. |
Failing on findings
For scripts and scheduled checks, --fail-on makes ssv exit with status 3 when any file is at or above a severity (review, high or critical):
sudo ssv audit --fail-on high
ssv: 3 file(s) at or above HIGH
The report is printed as usual, and the summary line above goes to standard error.
JSON output
sudo ssv audit --json gives the same data/warnings structure as scan. Each item has the file under finding plus severity and reasons. For example, to list just the serious files with jq:
sudo ssv audit --json | jq -r '.data[] | select(.severity == "CRITICAL" or .severity == "HIGH") | "\(.severity) \(.finding.path)"'
CRITICAL /home/alice/public_html/wp-config.php.bak
HIGH /home/bob/public_html/.env
HIGH /var/www/shop/app/etc/env.php
Last updated 2026-10-08 ยท for ssv 0.2.0