Blog

Is your website leaking customer data? Five places to check in ten minutes


Most sites that leak customer data aren’t hacked. Something was left lying around.

This is a check for your own site. You’ll need your hosting login (the one you got when the site was built, or ask whoever manages it), a web browser, and about ten minutes. Nothing here needs code. If you find something, the last section says what to do.

1. Old backups sitting in the site’s folders

Log in to your host and open the file manager (it’s usually under “Files” or “File Manager”). Look at the top-level folder of your website, the one with your site’s files in it.

You’re looking for files that aren’t part of the site: names ending in .zip, .sql, .gz, .bak or .old, or anything named “backup,” “old,” “copy” or “dump.” A backup should live in your host’s backup tool or somewhere private, not inside the folder the public can reach.

If you find one, don’t delete it yet. Skip to the last section first.

2. Folders that list their contents

Some servers will show a plain list of every file in a folder when you open it in a browser, instead of a web page. It looks like a bare list headed “Index of.”

On a WordPress site, try your own site’s address followed by /wp-content/uploads/. If you get a blank page, an error, or your normal site, good. If you get a list of files and folders, that’s a problem: anyone can browse everything in it, including files you uploaded for a customer and forgot about.

3. Debug and error logs

When a site is being fixed, a developer sometimes turns on logging, and the log lands in a folder on the site. Those files record errors, and errors often contain file paths, email addresses, and sometimes more. In the file manager, look for files named debug.log or error_log, or anything ending in .log, inside your site’s folders.

A log isn’t a disaster by itself. A log that’s publicly readable and months old is worth five minutes of your attention.

4. Admin pages and old accounts

Open your site’s admin users list (on WordPress: Users, then filter by Administrator). Ask of each name: who is this, and do they still work for us?

Former developers, former employees and an agency you stopped paying years ago are the common ones. Each account is a key. Remove the ones you can’t account for, and make sure the rest use a strong password and two-step login if your site supports it.

While you’re there, ask your host or developer whether xmlrpc is switched on. It’s an old remote-access feature that most sites don’t need and attackers love to hammer. If nothing you use depends on it, turn it off.

5. Settings and hidden files

Back in the file manager, look at the top-level folder for copies of configuration files. On WordPress that means anything that starts with wp-config but isn’t exactly wp-config.php (for example a copy ending in .bak or .old). Also look for a file called .env, or a folder called .git.

These hold your database password and other secrets, and a stray copy can sometimes be read as plain text from outside. If you can see one in your folder and you didn’t put it there on purpose, treat it as a problem.

If you found something

Don’t panic, and don’t start deleting.

  • Write down what it is and where it was, and when you first saw it.
  • Move it out of the public folder, don’t just rename it. Keep a copy somewhere private so you know what it contained.
  • Change the passwords it might have held: the database, your admin login, any keys. Your host or developer can do the database one.
  • Ask your host whether they keep access logs, and if they do, whether anyone downloaded the file. That tells you whether it was seen or just reachable.
  • If it held customer information, talk to a lawyer about whether you owe those customers a notice. That depends on what was in it and where they live, and it isn’t something to guess at.

What this check can’t tell you

It catches the obvious leftovers. It won’t find a vulnerability in an old plugin or a weakness in how your email is set up, and it won’t tell you if something has already been taken. An audit does those things. I wrote up what one actually finds, and the audits I offer are on the website audits page.

If you’re not sure what you’re looking at, send me a screenshot at [email protected]. Free, and I’ll tell you honestly whether it matters.