In the main threat, I saw a couple of answers with people offering extra code to add to the .htaccess in the root folder.
When I add it, my front- and backend of the website give me a "500 internal error code".
Am I missing something?
I tried with 2 different blocks of code:
<IfModule mod_authz_core.c> <FilesMatch ".(php|phtml|php[0-9]|phps)$"> Require all denied </FilesMatch> ></IfModule>
<IfModule !mod_authz_core.c> <FilesMatch ".(php|phtml|php[0-9]|phps)$"> Order allow,deny Deny from all </FilesMatch> </IfModule>
or
<DirectoryMatch "/(media|images|uploads|tmp|cache|administrator/cache|assets|icons|fonts)(/|$)"> AllowOverride None <FilesMatch "(?i).(php|phtml|phar|php[0-9]?|php..*|shtml)$"> Require all denied </FilesMatch> </DirectoryMatch>