If a folder has no index page such as index.php or index.html, the web server may display its contents as a list. This can expose files that should not be public. Two short rules in your .htaccess file improve security.
Open the .htaccess file
- Log in to cPanel and open the File Manager.
- Click Settings in the top right corner, enable Show Hidden Files (dotfiles) and save.
- Open the
public_htmlfolder, right-click.htaccessand choose Edit. If the file does not exist, create it with + File.
Disable directory listing
Add this line:
Options -Indexes
Folders without an index page will then show an error (403) instead of a file list.
Protect the .htaccess file
To prevent anyone from retrieving the file via a browser, add:
<Files .htaccess>
Order Allow,Deny
Deny from all
</Files>
Then click Save Changes.
Note: Make a copy of .htaccess before every change. If your website then shows a 500 error, restore the copy and check the syntax.