The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522c0ccc5e9
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://conceptual:64c1ae6d1b3fa54bb3e7059af6125d190c3201cd0b4d4b38273d30d02ce6c047@bitbucket.org/conceptualpathways/nfcauth_wordpress_site.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [revisr] token = TX2lahV7UJBrokX8 automatic-backups = none notifications = off uninstall-on-delete = off [user] name = nfcauthority.com email = websites@conceptual.ca
Open service 194.1.147.10:443 ยท www.nfcauthority.com
2026-01-23 08:17
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 08:17:01 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 53 Connection: close X-Powered-By: PHP/7.4.33 X-Redirect-By: WordPress Location: https://nfcauthority.com/ Vary: Accept-Encoding,Origin WPX: 1 Referrer-Policy: no-referrer-when-downgrade X-turbo-charged-by: LiteSpeed X-Edge-Location: WPX CLOUD/TOR01 alt-svc: h3=":443"; ma=86400 x-quic: h3 Server: WPX CLOUD/TOR01 X-Cache-Status: MISS <!-- moved 0 assets & minified html in 0 seconds -->