ssv scan: list the files that hold secrets
ssv scan lists the configuration files on the server that hold secrets, with their owner, permissions, size and checksum. It never shows what is inside them. To rate each file's risk, use ssv audit.
sudo ssv scan
ServerSecretVault 0.2.0
Sensitive configuration files: 6
Laravel /home/alice/app/.env
owner=alice:alice mode=0600 size=24 sha256=2dbee5d49a1e…
WordPress /home/alice/public_html/wp-config.php
owner=alice:www-data mode=0640 size=33 sha256=8e9c8696677e…
WordPress /home/alice/public_html/wp-config.php.bak
owner=alice:alice mode=0644 size=33 sha256=8e9c8696677e…
Node.js /home/bob/public_html/.env
owner=bob:bob mode=0644 size=14 sha256=123dc34ec1be…
Node.js /home/bob/public_html/.env.example
owner=bob:bob mode=0644 size=13 sha256=e9d25efc17b9…
Magento /var/www/shop/app/etc/env.php
owner=www-data:www-data mode=0660 size=17 sha256=440b2e7377bc…
Values hidden. Nothing was modified.
Each file is listed with its owner and group, permission mode, size in bytes, and the start of its SHA-256 checksum. Identical checksums mean identical contents; above, wp-config.php.bak is an exact copy of the live wp-config.php. Comparing checksums between runs shows which files changed, without revealing what is in them.
Problems that don't stop the scan, such as a directory that can't be read, are listed afterwards on standard error as warnings.
File names are chosen by the server's users. If a name contains control characters (a newline or terminal escape code, which could be an attempt to tamper with the report), ssv shows them escaped, as in .env\n or \x1b.
Choosing where to look
By default ssv searches /home, /var/www and /srv/www, skipping any that don't exist. Use --root to search somewhere else. It can be repeated, and it replaces the defaults:
sudo ssv audit --root /home --root /opt/sites
- A directory you name with
--rootmust exist; otherwisessvstops with an error. - A root may be a symbolic link (for example
/var/wwwpointing to/data/www). Links inside a root are never followed. .git,.svn,.hg,node_modules,vendorand.cachedirectories are skipped, and so are/proc,/sysand/devif you scan/.- Files larger than 16 MiB are skipped with a warning; configuration files are tiny.
JSON output
sudo ssv scan --json > inventory.json
The output is an object with a data list of files and, if there were any, a warnings list of messages:
{
"data": [
{
"path": "/home/alice/public_html/wp-config.php.bak",
"application": "WordPress",
"kind": "application-config",
"owner": "alice",
"group": "alice",
"uid": 1001,
"gid": 1001,
"permissions": "0644",
"mode": 420,
"size": 33,
"modified": "2026-10-07T21:26:36.595834725Z",
"sha256": "8e9c8696677e44b2e26445acecf03c9631a42300a51b294ac2ba1c3eef855d50",
"under_web_root": true,
"backup_like": true
}
],
"warnings": ["walk /home/carol: open /home/carol: permission denied"]
}
| Field | Meaning |
|---|---|
kind |
environment (dotenv), environment-template or application-config |
permissions / mode |
the permission bits, as octal text and as a number |
modified |
last modification time, in UTC |
under_web_root |
the path is inside a directory that is commonly served by the web server (see what counts as a web root) |
backup_like |
the name looks like a backup or old copy |
Last updated 2026-10-08 · for ssv 0.2.0