Commit 2a85a6f
committed
Security: Block access to sensitive files in WordPress NGINX config
Added security blocks to prevent access to:
• .git directories
• Environment files (.env, .env.*)
• Configuration/log files (.ini, .log, .conf, etc.)
• Hidden files/directories (/.)
All blocked requests return 403 Forbidden, with logging disabled to reduce noise. This hardens the
WordPress installation against information disclosure attacks and unauthorized access to sensitive
development/config files.1 parent 0cbcc53 commit 2a85a6f
1 file changed
+24
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
35 | 59 | | |
36 | 60 | | |
37 | 61 | | |
| |||
0 commit comments