# Uploaded files are data only. Never let the web server run anything placed here as a script,
# whatever extension tricks were used ("x.php.jpg", ".phtml", ".phar", ...).
<FilesMatch "(?i)\.(php\d?|phtml|phar|pht|phps|pl|py|cgi|sh|shtml|htaccess)(\.|$)">
    Require all denied
</FilesMatch>