Certain credentials are exposed due to the exposure of .env file.
https://fms.credentia.biz/.env
.env should be removed and/or hidden by the webserver
APP_NAME=CREDENTIA
APP_ENV=local
APP_KEY=base64:<redacted>
APP_DEBUG=true
APP_URL=http://localhost:/crendentia
LOG_CHANNEL=stack
DB_CONNECTION=mysql_credentia
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=live_credentia_default
DB_USERNAME=root
DB_PASSWORD=<redacted>
BROADCAST_DRIVER=log
CACHE_DRIVER=file
QUEUE_CONNECTION=sync
SESSION_DRIVER=file
SESSION_LIFETIME=120
REDIS_HOST=127.0.0.1
REDIS_PASSWORD=null
REDIS_PORT=6379
MAIL_DRIVER=smtp
MAIL_HOST=smtp.gmail.com
MAIL_PORT=587
MAIL_USERNAME=jaspreet@credentia.biz
MAIL_PASSWORD=<redacted>
MAIL_ENCRYPTION=tls
AWS_ACCESS_KEY_ID=
AWS_SECRET_ACCESS_KEY=
AWS_DEFAULT_REGION=us-east-1
AWS_BUCKET=
PUSHER_APP_ID=
PUSHER_APP_KEY=
PUSHER_APP_SECRET=
PUSHER_APP_CLUSTER=mt1
EUROSIGN=£
PERCENTAGESIGN=%
VOLUME=Litres
GROSSMARGIN=ppl
LITRE=ℓ
MIX_PUSHER_APP_KEY="${PUSHER_APP_KEY}"
MIX_PUSHER_APP_CLUSTER="${PUSHER_APP_CLUSTER}"
Looks fixed ! It's now 403.