Directory Listing Enabled
This directory returns an index of its contents instead of a page, so anyone can browse the files it holds rather than needing to guess names.
Why it matters
This directory returns an index of its contents instead of a page, so anyone can browse the files it holds rather than needing to guess names. It commonly exposes build artefacts, backups and configuration that were never meant to be reachable.
How ShipReady detects it
Disclosure derived from a PAGE's own scripts: published source maps, and directory listings on the folders those scripts live in. Both are page-scoped because both are computed from the bundle the page links, and route-split builds serve different bundles from different directories.
Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.2.0.
How to fix it
This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.
Directory listing is enabled on '{directory}'. This allows attackers to view the contents of your server directories. Disable autoindex or directory listing in your web server configuration.Frequently asked questions
- What does "Directory Listing Enabled" mean?
- This directory returns an index of its contents instead of a page, so anyone can browse the files it holds rather than needing to guess names.
- How serious is it?
- ShipReady rates this medium. Fix soon. Meaningfully weakens a defence or degrades how the site works.
- How do I fix it?
- Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
- Can I check my own site?
- Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check.
Related checks
Does your site have this?
ShipReady checks this and 73 other things across up to ten pages of your site. Free, no signup.
Scan my site