# Uploaded images should never be executable — blocks a whole class of upload-based attacks
<FilesMatch "\.(php|php3|php4|php5|phtml|pl|py|cgi)$">
    Require all denied
</FilesMatch>
