# Defense in depth: even though save.php validates every upload is a real
# image before it's stored here, this stops the uploads folder from ever
# executing a script, just in case. (Apache-only — most shared hosting
# uses Apache, but this has no effect on Nginx/IIS hosting.)
<FilesMatch "\.(php|php\d?|phtml|pl|py|cgi|sh)$">
  Require all denied
</FilesMatch>

Options -Indexes
