MCP server · Security
Web Exposure MCP server
by Perufitlife
Check a live website for secret files like .git, .env, backups and source maps that anyone can read.

This is a small helper that lets your AI look at a live website and tell you whether private files are accidentally open to the public. You point it at a web address, and it checks things like .git folders, .env files with passwords, backup files and source maps. It is handy for developers, IT staff and anyone who runs a website and wants to know what strangers can actually see.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to something outside the chat. This one gives your AI the ability to visit a web address and inspect what files the site is serving. So instead of guessing, your AI can actually go and check the site for you when you ask.
What this MCP server does
You give your AI a web address, like your company site or a test site. The AI passes that address to this helper. The helper then sends normal, harmless requests to that site, asking for common secret file paths one by one. It reads what comes back and checks whether the content really looks like a secret file, not just a generic page. Then it tells you exactly which files are open and how serious each one is.
Click to zoomWhat you can do with it
- Check whether a live site is serving its .git folder to the public
- See if a .env file with passwords and keys is readable by anyone
- Find JavaScript source maps that reveal your original code
- Spot backup or SQL dump files that are downloadable
- Detect open folder listings that show all your uploaded files
- Find exposed dotfiles like .htpasswd, .npmrc or .aws credentials
- Run just the checks you care about instead of the full list
Try asking your AI
- “Scan https://staging.myapp.com for publicly exposed secret files”
- “Does my site at https://example.com leak its .env file?”
- “Check https://demo.example.com but only for git and env exposure”
- “List all the exposure checks you can run”
What it gives back to you
You get back a short list of confirmed findings, each with a severity level like critical, high or medium. For every finding it shows the file path and a short piece of evidence, for example that a .git config was served or that an .env file contained real key and value lines. If nothing is exposed, it tells you that too. It only reports things it actually fetched and verified, so you are not flooded with maybes.
Before you start
What you need
- The Claude desktop app or another AI client that supports MCP servers
- Node.js version 18 or newer on your computer
- The web address you want to check
Good to know
Only scan websites you own or have permission to test, because checking someone else's site without permission can get you into trouble.
Install it with your AI
Add Web Exposure MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check Web Exposure MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Developers, IT admins and small teams who run websites and want a quick, honest check of what is publicly visible.





