A Hardening Block for Any Site

A Server Hardening Checklist and Protecting Sensitive Files merged into one file for any PHP site:

A hardening block for any siteApache config
# Needs: mod_alias, mod_headers; AllowOverride AuthConfig FileInfo Options
Options -Indexes
ServerSignature Off
LimitRequestBody 10485760
Header unset X-Powered-By
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
RedirectMatch 404 "/\.(?!well-known/)"
<FilesMatch "(?i)(\.(bak|old|orig|swp|sql|sqlite|log|ini|dist)|~)$">
  Require all denied
</FilesMatch>
<LimitExcept GET POST HEAD OPTIONS>
  Require all denied
</LimitExcept>
Output
GET  /                   200 nosniff SAMEORIGIN strict-origin-when-cross-origin
GET  /.env               404
GET  /.git/config        404
GET  /config.php.bak     403
PUT  /index.php          403
POST /index.php (11 MB)  413

Adding -MultiViews to line 2 gave a 500, since bare Options means Options=All, which excludes it. Line 4 caps bodies at 10 MiB. The test index.php sends X-Powered-By itself; line 5 removed it, but Header always unset did not. Lines 13 to 15 stop PUT and DELETE reaching PHP; an API must list them.