﻿# Upload directory security
# Never allow uploaded files to execute as server-side code.

<IfModule mod_php.c>
    php_flag engine off
</IfModule>

<IfModule mod_php7.c>
    php_flag engine off
</IfModule>

<IfModule mod_php8.c>
    php_flag engine off
</IfModule>

<FilesMatch "\.(php|php3|php4|php5|php7|php8|phtml|pht|phar|cgi|pl|py|sh|asp|aspx|jsp|jspx|exe|dll)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

RemoveHandler .php .php3 .php4 .php5 .php7 .php8 .phtml .pht .phar .cgi .pl .py .sh
RemoveType .php .php3 .php4 .php5 .php7 .php8 .phtml .pht .phar .cgi .pl .py .sh

Options -Indexes -ExecCGI
