Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

Secrets committed to Git: why deleting them isn’t enough

Once credentials enter Git history, deleting the file doesn’t make them secret again. Rotate first, then clean history and prevent it happening again.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·7 min read
QUICK ANSWER

Once credentials enter Git history, deleting the file doesn’t make them secret again. Rotate first, then clean history and prevent it happening again.

FROM OUR ENGINEERING WORKREAL CASE

Real Composer/vendor credentials were present in repository history. They had to be treated as exposed and rotated — removing them from the latest commit wasn’t enough.

KEY TAKEAWAYS
✓Anything committed to Git should be treated as exposed.
✓Rotate the credential first — cleaning history comes second.
✓Use secret scanning and environment variables to prevent repeats.
INTERACTIVE CHECKLIST
Leaked secret response
0 of 6 done0%

Why deletion isn’t enough

Git keeps every version. Clones, forks, CI caches and backups may already contain the secret.

RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Protect your site before it’s hackedManaged security with WAF, scanning and unlimited cleanups.Get a free security scan →

What to do

  • Revoke and rotate the credential immediately
  • Check logs for misuse
  • Remove it from history (git filter-repo) if needed
  • Move secrets to environment variables or a vault
  • Enable secret scanning and pre-commit hooks

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get a free security scan →Free · No obligation · Reply within 24 hours

Frequently asked questions

Which secrets leak most?

Composer/Marketplace keys, cloud keys, API tokens and database passwords.

Is a private repo safe?

Safer, but still exposed to everyone with access and any leaks.

Can you audit our repos?

Yes.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINHow to stop spam and bot attacks on Adobe Commerce CloudRead →SECURITY · 9 MINWordPress security checklist: 15 steps to protect your site in 2026Read →SECURITY · 8 MINMagecart and card skimming: how to protect your checkoutRead →
FREE · NO OBLIGATION

Protect your site before it’s hacked

Managed security with WAF, scanning and unlimited cleanups.

Get a free security scan →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.