{"id":11917,"date":"2026-07-06T10:14:20","date_gmt":"2026-07-06T08:14:20","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=11917"},"modified":"2026-07-06T10:14:27","modified_gmt":"2026-07-06T08:14:27","slug":"why-env-files-must-never-be-public","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/","title":{"rendered":"Why .env files must never be public"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">A <code>.env<\/code> file is commonly used by websites and applications to store environment-specific configuration. It may contain database credentials, API keys, application secrets, email settings, and other sensitive values needed for the application to run.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This file must never be publicly accessible from a browser. If a <code>.env<\/code> file can be opened online, sensitive information may be exposed and the website, database, email accounts, or connected services may be at risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#What_a_env_file_is\" >What a .env file is<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#Why_env_files_are_sensitive\" >Why .env files are sensitive<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#What_can_happen_if_a_env_file_is_public\" >What can happen if a .env file is public<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#Public_folder_vs_private_application_files\" >Public folder vs. private application files<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#Hidden_file_does_not_mean_protected_file\" >Hidden file does not mean protected file<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#Debug_mode_can_increase_the_risk\" >Debug mode can increase the risk<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#How_to_protect_env_files\" >How to protect .env files<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#What_to_check\" >What to check<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#If_a_env_file_was_exposed\" >If a .env file was exposed<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#env_files_and_backups\" >.env files and backups<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#Practical_meaning_for_users\" >Practical meaning for users<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-env-files-must-never-be-public\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_a_env_file_is\"><\/span>What a .env file is<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-82738683\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">A <code>.env<\/code> file stores configuration values outside the main application code.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Applications often use it to define settings such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>database hostname<\/li>\n\n\n\n<li>database name<\/li>\n\n\n\n<li>database username<\/li>\n\n\n\n<li>database password<\/li>\n\n\n\n<li>application secret keys<\/li>\n\n\n\n<li>API keys<\/li>\n\n\n\n<li>SMTP credentials<\/li>\n\n\n\n<li>payment service keys<\/li>\n\n\n\n<li>third-party integration tokens<\/li>\n\n\n\n<li>debug settings<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This helps developers keep configuration separate from the application files. It also makes it easier to use different settings for development, staging, and production environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_env_files_are_sensitive\"><\/span>Why .env files are sensitive<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A <code>.env<\/code> file often contains information that gives access to other systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, database credentials can allow access to website content and user data. API keys can allow access to external services. SMTP credentials can allow email sending from a domain or mailbox.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because of this, a <code>.env<\/code> file should be treated like a password file. It is not meant to be downloaded, indexed, shared, or visible through the website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_can_happen_if_a_env_file_is_public\"><\/span>What can happen if a .env file is public<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a <code>.env<\/code> file becomes publicly accessible, someone may be able to read the secrets inside it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Depending on what the file contains, this can lead to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>unauthorized database access<\/li>\n\n\n\n<li>exposed application secrets<\/li>\n\n\n\n<li>email abuse through SMTP credentials<\/li>\n\n\n\n<li>stolen API keys or tokens<\/li>\n\n\n\n<li>access to payment, storage, or automation services<\/li>\n\n\n\n<li>website compromise<\/li>\n\n\n\n<li>spam sending<\/li>\n\n\n\n<li>data leaks<\/li>\n\n\n\n<li>service abuse or unexpected costs<\/li>\n\n\n\n<li>domain or email reputation issues<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The risk depends on the contents of the file, but any public <code>.env<\/code> file should be treated as a security incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Public_folder_vs_private_application_files\"><\/span>Public folder vs. private application files<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A common mistake is placing the <code>.env<\/code> file inside a public web directory.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The public web directory is the folder served directly by the web server. Files inside it may be accessible from a browser if no protection rule blocks them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, if a website\u2019s public folder is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>public_html\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">then placing a <code>.env<\/code> file here may expose it at a URL such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>https:&#47;&#47;example.com\/.env\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A safer structure keeps the <code>.env<\/code> file outside the public web directory whenever the application supports it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Hidden_file_does_not_mean_protected_file\"><\/span>Hidden file does not mean protected file<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The dot at the beginning of <code>.env<\/code> means the file is hidden in many file managers and command-line views. It does not automatically mean the file is protected from web access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whether the file can be opened from a browser depends on the server configuration and where the file is stored.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A hidden file can still be public if it is placed in a directory served by the website and access is not blocked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Debug_mode_can_increase_the_risk\"><\/span>Debug mode can increase the risk<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some applications use <code>.env<\/code> values to control debug mode.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If debug mode is enabled on a live website, error pages may reveal file paths, configuration details, database errors, stack traces, or other technical information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Debug mode should normally be disabled on production websites. It is useful during development, but it can expose information that should not be visible to visitors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_protect_env_files\"><\/span>How to protect .env files<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The safest approach is to keep <code>.env<\/code> files outside the public web directory when possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the application requires the <code>.env<\/code> file inside the project directory, make sure the web server blocks direct access to it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Apache-based setups, access can often be blocked with rules in <code>.htaccess<\/code>, depending on the hosting configuration. For Nginx-based setups, access is usually blocked through the server configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exact method depends on the application and hosting environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_check\"><\/span>What to check<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Check the following:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Confirm where the <code>.env<\/code> file is located.<\/li>\n\n\n\n<li>Confirm whether it is inside a public web directory.<\/li>\n\n\n\n<li>Try opening <code>https:\/\/example.com\/.env<\/code> in a browser.<\/li>\n\n\n\n<li>Confirm that the file is not visible or downloadable.<\/li>\n\n\n\n<li>Check whether backups, archives, or old copies contain <code>.env<\/code> files.<\/li>\n\n\n\n<li>Check that <code>.env<\/code> is excluded from public repositories.<\/li>\n\n\n\n<li>Disable debug mode on production websites.<\/li>\n\n\n\n<li>Review file permissions.<\/li>\n\n\n\n<li>Review web server rules that block sensitive files.<\/li>\n\n\n\n<li>Rotate exposed secrets if the file was ever public.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">A blocked <code>.env<\/code> file may return a 403, 404, or similar response. The important point is that its contents must not be displayed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"If_a_env_file_was_exposed\"><\/span>If a .env file was exposed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If a <code>.env<\/code> file was publicly accessible, do not only move or hide the file.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Assume the values inside it may have been copied. Any exposed secret should be replaced, including database passwords, API keys, SMTP passwords, application keys, and tokens.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After rotating the secrets, review the website and connected services for suspicious activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"env_files_and_backups\"><\/span>.env files and backups<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Backups, ZIP archives, old project folders, and deployment copies can expose the same information if they are placed in public directories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples include:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>.env.backup\n.env.old\nbackup.zip\nsite-backup.tar.gz\nproject-copy\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">These files should not be publicly accessible. Old copies can be just as dangerous as the active <code>.env<\/code> file because they may contain valid credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Practical_meaning_for_users\"><\/span>Practical meaning for users<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A <code>.env<\/code> file should be handled as sensitive configuration, not as a normal website file.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It should not be visible in the browser, included in public downloads, left inside public backups, or committed to public code repositories. If an application depends on it, the file should be stored and protected according to the application\u2019s requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If there is any chance that the file was exposed, the safest next step is to rotate the secrets rather than only changing the file location.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>.env<\/code> files must never be public because they often contain credentials, API keys, tokens, and application secrets. If exposed, they can give unauthorized access to databases, email services, third-party platforms, or the website itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <code>.env<\/code> file should be stored outside the public web directory when possible, blocked from browser access, excluded from public repositories, and reviewed carefully after any suspected exposure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10],"manual_kb_tag":[],"class_list":["post-11917","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11917\/revisions"}],"predecessor-version":[{"id":11918,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/11917\/revisions\/11918"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=11917"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=11917"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=11917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}