# Deny direct access to configuration files
<FilesMatch "\.(php)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

# Allow only includes from PHP scripts
# No direct browser access to this directory