A Server Hardening Checklist and Protecting Sensitive Files merged into one file for any PHP site:
# Needs: mod_alias, mod_headers; AllowOverride AuthConfig FileInfo Options
Options -Indexes
ServerSignature Off
LimitRequestBody 10485760
Header unset X-Powered-By
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
RedirectMatch 404 "/\.(?!well-known/)"
<FilesMatch "(?i)(\.(bak|old|orig|swp|sql|sqlite|log|ini|dist)|~)$">
Require all denied
</FilesMatch>
<LimitExcept GET POST HEAD OPTIONS>
Require all denied
</LimitExcept>Output
GET / 200 nosniff SAMEORIGIN strict-origin-when-cross-origin GET /.env 404 GET /.git/config 404 GET /config.php.bak 403 PUT /index.php 403 POST /index.php (11 MB) 413
Adding -MultiViews to line 2 gave a 500, since bare Options means Options=All, which excludes it. Line 4 caps bodies at 10 MiB. The test index.php sends X-Powered-By itself; line 5 removed it, but Header always unset did not. Lines 13 to 15 stop PUT and DELETE reaching PHP; an API must list them.