Exposed FilesYour .git folder is public — and that is a full source-code download If /.git is reachable on your site, an attacker can rebuild your whole repository — code, history and any secrets you ever committed. Here is how to check. Apr 23, 2026 · 2 min read