# Uploaded files (photos, logos, documents) must NEVER be executable as
# PHP. Without this, a malicious upload disguised as an image (e.g.
# shell.php.jpg, or a .php file if extension checks are ever bypassed)
# could be run directly by visiting its URL -- one of the most common
# real-world ways a file upload feature turns into a full server compromise.
<FilesMatch "\.(php|php3|php4|php5|php7|phtml|pl|py|cgi|asp|aspx|exe|sh)$">
    Require all denied
</FilesMatch>
Options -Indexes -ExecCGI
