harden-my-host.txt
I deploy a <stack> project to <host>. Here's my file layout:
<paste the file tree>

Check what a stranger could reach:
- Which files in the web root can be downloaded that shouldn't be:
  configuration, .env files, backups, .git folders, logs, SQL dumps.
- Whether directory listings are switched on.
- Whether error pages leak paths or stack traces.
- File and folder permissions that are wider than they need to be.
- Anything left over from development: test scripts, admin tools,
  phpinfo pages, sample files.

For each, give me the fix for this host and a URL I can visit to prove
it's closed.

Try fetching /.git/config and /.env on your own site. Automated scanners request both within hours of a site going live.