talesh / magento-security-checklist

A Magento community sourced security pre-flight checklist.
BSD 3-Clause "New" or "Revised" License
131 stars 21 forks source link

publicly accessible .user.ini #14

Closed jigneshthummar closed 4 years ago

jigneshthummar commented 5 years ago

Server settings do you have publicly accessible '.user.ini' over HTTP / HTTPS. are you able to download https://www.yoursite.com/pub/.user.ini ?

if yes that needs to be protected

talesh commented 4 years ago

Added this note.