[Insight] Symfony applications should not contain a config.php file - in web, line 0
krzysiekpiasecki opened this issue · comments
Krzysztof Piasecki commented
This
config.php
file should only be used to bootstrap a Symfony application. Before releasing to production, you should remove it, otherwise attackers could get valuable insight about your application.
web/
├── app.php
├── app_dev.php
├── app_heroku.php
├── apple-touch-icon.png
├── config.php
├── favicon.ico
└── robots.txt
Posted from SensioLabsInsight