ssv scan: list the files that hold secrets

ssv scan lists the configuration files on the server that hold secrets, with their owner, permissions, size and checksum. It never shows what is inside them. To rate each file's risk, use ssv audit.

sudo ssv scan
ServerSecretVault 0.2.0

Sensitive configuration files: 6

Laravel      /home/alice/app/.env
             owner=alice:alice mode=0600 size=24 sha256=2dbee5d49a1e…
WordPress    /home/alice/public_html/wp-config.php
             owner=alice:www-data mode=0640 size=33 sha256=8e9c8696677e…
WordPress    /home/alice/public_html/wp-config.php.bak
             owner=alice:alice mode=0644 size=33 sha256=8e9c8696677e…
Node.js      /home/bob/public_html/.env
             owner=bob:bob mode=0644 size=14 sha256=123dc34ec1be…
Node.js      /home/bob/public_html/.env.example
             owner=bob:bob mode=0644 size=13 sha256=e9d25efc17b9…
Magento      /var/www/shop/app/etc/env.php
             owner=www-data:www-data mode=0660 size=17 sha256=440b2e7377bc…

Values hidden. Nothing was modified.

Each file is listed with its owner and group, permission mode, size in bytes, and the start of its SHA-256 checksum. Identical checksums mean identical contents; above, wp-config.php.bak is an exact copy of the live wp-config.php. Comparing checksums between runs shows which files changed, without revealing what is in them.

Problems that don't stop the scan, such as a directory that can't be read, are listed afterwards on standard error as warnings.

File names are chosen by the server's users. If a name contains control characters (a newline or terminal escape code, which could be an attempt to tamper with the report), ssv shows them escaped, as in .env\n or \x1b.

Choosing where to look

By default ssv searches /home, /var/www and /srv/www, skipping any that don't exist. Use --root to search somewhere else. It can be repeated, and it replaces the defaults:

sudo ssv audit --root /home --root /opt/sites
  • A directory you name with --root must exist; otherwise ssv stops with an error.
  • A root may be a symbolic link (for example /var/www pointing to /data/www). Links inside a root are never followed.
  • .git, .svn, .hg, node_modules, vendor and .cache directories are skipped, and so are /proc, /sys and /dev if you scan /.
  • Files larger than 16 MiB are skipped with a warning; configuration files are tiny.

JSON output

sudo ssv scan --json > inventory.json

The output is an object with a data list of files and, if there were any, a warnings list of messages:

{
  "data": [
    {
      "path": "/home/alice/public_html/wp-config.php.bak",
      "application": "WordPress",
      "kind": "application-config",
      "owner": "alice",
      "group": "alice",
      "uid": 1001,
      "gid": 1001,
      "permissions": "0644",
      "mode": 420,
      "size": 33,
      "modified": "2026-10-07T21:26:36.595834725Z",
      "sha256": "8e9c8696677e44b2e26445acecf03c9631a42300a51b294ac2ba1c3eef855d50",
      "under_web_root": true,
      "backup_like": true
    }
  ],
  "warnings": ["walk /home/carol: open /home/carol: permission denied"]
}
Field Meaning
kind environment (dotenv), environment-template or application-config
permissions / mode the permission bits, as octal text and as a number
modified last modification time, in UTC
under_web_root the path is inside a directory that is commonly served by the web server (see what counts as a web root)
backup_like the name looks like a backup or old copy

Last updated 2026-10-08 · for ssv 0.2.0