# Security headers
Header set X-Content-Type-Options "nosniff"
Header set X-Frame-Options "SAMEORIGIN"
Header set X-XSS-Protection "1; mode=block"
# Block access to sensitive directories
RewriteEngine On
RewriteRule ^includes/ - [F,L]
RewriteRule ^sql/ - [F,L]
RewriteRule ^vendor/ - [F,L]