Security hardening starts with proper file permissions, then web server rules to reduce attack surfaces.
1. File Permissions (base requirement)
Apply these permissions before webserver rules. Never use 777 globally.
- Folders: 755
- PHP, twig, html, css, js files: 644
- Writeable directories (only these folders need write permission):image/, system/storage/cache/, system/storage/logs/, system/storage/download/, system/storage/upload/Set these writable folders to 755 (or 775 if…