Hi BobRay and OpenGeek,
As I prepare to make my first MODx website go live, I did some reading up on PHP security. One suggestion was to move the ’code’ of the site out of the web root, as suggested by BobRay above.
Reading the instructions above I realise I’m probably too close to my deadline to take that approach
So, OpenGeek, can you explain how I use the .htaccess file to prevent any direct web access? I am already using it for friendly URLs. What more can I do in the .htaccess to improve the security of the site?
Any advice appreciated.
Colin