# Uploaded documents must never be executed as scripts.
Options -Indexes

<IfModule mime_module>
  RemoveHandler .php .php5 .php7 .php8 .phtml .phar .pl .py .cgi
  RemoveType .php .php5 .php7 .php8 .phtml .phar
</IfModule>

# Block script files, including double extensions such as "file.php.pdf"
<FilesMatch "(?i)\.(php[0-9]?|phtml|phar|pl|py|cgi|sh|asp|aspx|jsp|htaccess)(\.|$)">
  Require all denied
</FilesMatch>
