Sensitive Files
Shopify Log File Exposure Check
Shopify log files can reveal sensitive information about your store. Check that they are not publicly accessible to avoid data leaks.
What this test checks
This test checks whether Shopify log files (in /logs/, /var/log/, etc.) are publicly accessible. These logs contain detailed information about errors, admin accesses, API requests, and sometimes personal data. Their exposure can facilitate targeted attacks or information theft.
Our recommendation
Place log files outside your Shopify store's public directory. Use Shopify's built‑in logging tools or dedicated apps to centralise logs securely. Regularly check file permissions.
Security tests