One of the biggest offenses I've seen lately in this regard are developers that keep their database name, username and passwords in their CMS_config (wp-config.php is a big one.)
Wordpress seems to be well behind in good dev practices. I do know Drupal adds the settings.php to the default .gitignore. It would take a bit more than simple ignorance to add setting to the repo.