Area: Website and certificates
Standard public files
Reads the three files a website publishes on purpose at fixed, standard locations: robots.txt, sitemap.xml and /.well-known/security.txt. One request to each, nothing more. It doesn't open any of the paths they mention or try others: Ward doesn't probe paths.
What it can report
Open each one to see what it means and how to fix it.
robots.txt lists sensitive paths
What it means
What could happen
How an attacker would use it
How to fix it
- Go through the list and note what each path is for: a panel, a private area, an internal tool or something that no longer exists.
- For each one still in use, check that it asks for a password and, ideally, for two-step verification.
- Limit the sensitive areas (admin panels, internal tools) to your office addresses or a VPN if you can.
- Remove from the file the paths that no longer exist, so it doesn't point to old areas.
- Don't rely on robots.txt to hide anything: whatever must be private needs a login, not just a line in a file.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
sitemap.xml lists sensitive pages
What it means
What could happen
How to fix it
- Open your sitemap.xml in the browser and skim the list of pages.
- Look for pages that shouldn't be public: drafts, tests, internal areas or old campaigns.
- Ask whoever manages your website to remove them from the sitemap.
- If any of those pages must stay private, protect it with a login: removing it from the sitemap only hides it from searches.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
security.txt has problems
What it means
What could happen
How to fix it
- Check that the contact in the file still works and that someone reads that mailbox.
- Renew the “Expires” date before it passes: an expired file is treated as outdated.
- Decide who answers a report and how fast. Even a short acknowledgement is enough.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
No security.txt
What it means
What could happen
How an attacker would use it
How to fix it
- Choose a mailbox that someone reads, such as security@yourcompany.com, or a page with a contact form.
- Write a text file with a “Contact:” line (for example mailto:security@yourcompany.com) and an “Expires:” date no more than a year away.The format is the RFC 9116 standard; the file is plain text.
- Ask whoever manages your website to publish it at the fixed address /.well-known/security.txt.
- Decide who answers a report and how fast. Even a short acknowledgement is enough.
- Set a yearly reminder to renew the “Expires” date.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.