# This file is automatically generated by WP Toolkit.
# Please do not modify the contents of this file, because this can lead to reduced security or malfunctioning of your website.
# If the file was accidentally modified or otherwise damaged, you can regenerate it by deleting it and reapplying all security
# measures for this site in WP Toolkit UI.

    # "Block access to wp-config.php"
    # To remove this rule, revert this security measure on each WordPress installation on this domain
    <Files wp-config.php>
                    Require all denied
            </Files>

    # "Block access to xmlrpc.php"
    # To remove this rule, revert this security measure on each WordPress installation on this domain
    <Files xmlrpc.php>
                    Require all denied
            </Files>

# "Block directory browsing"
# To remove this rule, revert this security measure on each WordPress installation on this domain
<Directory "/home/fhbhealt/public_html">
    Options -Indexes
</Directory>

                            # "Block author scans"
        # To remove this rule, revert this security measure for WordPress installation #30
        <IfModule mod_rewrite.c>
            <Directory "/home/fhbhealt/public_html/test">
                RewriteEngine on
                RewriteCond %{QUERY_STRING} author=\d+
                RewriteCond %{REQUEST_FILENAME} "!^/home/fhbhealt/public_html/test/wp\-admin/" [NC]
                RewriteRule .* - [F,L]
            </Directory>
        </IfModule>

                # "Forbid execution of PHP scripts in the wp-content/uploads directory"
        # To remove this rule, revert this security measure for WordPress installation #31
        <Directory "/home/fhbhealt/public_html/wp-content/uploads">
            <FilesMatch \.php$>
                            Require all denied
                        </FilesMatch>
        </Directory>

                # "Enable hotlink protection"
        # To remove this rule, turn off this feature for WordPress installation #31
        <IfModule mod_rewrite.c>
            <Directory "/home/fhbhealt/public_html/wp-content/uploads">
                RewriteEngine on
                RewriteCond %{HTTP_REFERER} !^$
                                RewriteCond %{HTTP_REFERER} !^https?://(.*\.)?fhb.health.gov.lk(:|/|$) [NC]
                                RewriteCond %{HTTP_REFERER} !^https?://(.*\.)?fhb.health.gov.lk.66-85-158-91.cpanel.site(:|/|$) [NC]
                                RewriteCond %{HTTP_REFERER} !^https?://(.*\.)?google.com(:|/|$) [NC]
                                RewriteRule \.(gif|png|jpeg|jpg|svg)$ "/home/fhbhealt/public_html/wpt\-hotlinked\-image\-stub\.png" [NC]
            </Directory>
            <Directory "/home/fhbhealt/public_html">
                <Files "wpt-hotlinked-image-stub.png">
                    RewriteEngine on
                    RewriteCond %{REQUEST_FILENAME} !-f
                    RewriteRule .* - [NC,F,L]
                </Files>
            </Directory>
        </IfModule>

                # "Forbid execution of PHP scripts in the wp-includes directory"
        # To remove this rule, revert this security measure for WordPress installation #31
        <IfModule mod_rewrite.c>
            <Directory "/home/fhbhealt/public_html/wp-includes">
                <FilesMatch \.php$>
                    RewriteEngine on
                    RewriteCond %{REQUEST_FILENAME} "!^/home/fhbhealt/public_html/wp\-includes/js/tinymce/wp\-tinymce\.php$" [NC]
                    RewriteRule .* - [NC,F,L]
                </FilesMatch>
            </Directory>
        </IfModule>

                # "Disable scripts concatenation for WordPress admin panel"
        # To remove this rule, revert this security measure for WordPress installation #31
        <Directory "/home/fhbhealt/public_html/wp-admin">
        <FilesMatch (load-styles|load-scripts)\.php$>
                            Require all denied
                    </FilesMatch>
        </Directory>

                # "Block author scans"
        # To remove this rule, revert this security measure for WordPress installation #31
        <IfModule mod_rewrite.c>
            <Directory "/home/fhbhealt/public_html">
                RewriteEngine on
                RewriteCond %{QUERY_STRING} author=\d+
                RewriteCond %{REQUEST_FILENAME} "!^/home/fhbhealt/public_html/wp\-admin/" [NC]
                RewriteRule .* - [F,L]
            </Directory>
        </IfModule>

        # "Block access to sensitive files"
    # To remove this rule, revert this security measure on each WordPress installation on this domain
    <LocationMatch "(?i:(?:wp-config\\.bak|\\.wp-config\\.php\\.swp|(?:readme|license|changelog|-config|-sample)\\.(?:php|md|txt|htm|html)))">
                    Require all denied
            </LocationMatch>

    # "Block access to potentially sensitive files"
    # To remove this rule, revert this security measure on each WordPress installation on this domain
    <LocationMatch ".+\\.(?i:psd|log|cmd|exe|bat|csh|ini|sh)$">
                    Require all denied
            </LocationMatch>

    # "Disable PHP execution in cache directories"
    # To remove this rule, revert this security measure on each WordPress installation on this domain
    <LocationMatch "(?i:.*/cache/.*\\.ph(?:p[345]?|t|tml))">
                    Require all denied
            </LocationMatch>

    # "Block access to .htaccess and .htpasswd"
    # To remove this rule, revert this security measure on each WordPress installation on this domain
    <FilesMatch ^(?i:\.ht.*)$>
                    Require all denied
            </FilesMatch>

    # "Enable bot protection"
    # To remove this rule, revert this security measure on each WordPress installation on this domain
    <IfModule mod_rewrite.c>
        <Directory "/home/fhbhealt/public_html">
            RewriteEngine on
            RewriteCond %{HTTP_USER_AGENT} "(?:acunetix|BLEXBot|domaincrawler\\.com|LinkpadBot|MJ12bot/v|majestic12\\.co\\.uk|AhrefsBot|TwengaBot|SemrushBot|nikto|winhttp|Xenu\\s+Link\\s+Sleuth|Baiduspider|HTTrack|clshttp|harvest|extract|grab|miner|python-requests)" [NC]
            RewriteRule .* - [F,L]
        </Directory>
    </IfModule>

