# BEGIN LSCACHE ## LITESPEED WP CACHE PLUGIN - Do not edit the contents of this block! ## RewriteEngine on CacheLookup on RewriteRule .* - [E=Cache-Control:no-autoflush] RewriteRule litespeed/debug/.*\.log$ - [F,L] RewriteRule \.litespeed_conf\.dat - [F,L] ### marker ASYNC start ### RewriteCond %{REQUEST_URI} /wp-admin/admin-ajax\.php RewriteCond %{QUERY_STRING} action=async_litespeed RewriteRule .* - [E=noabort:1] ### marker ASYNC end ### ### marker DROPQS start ### CacheKeyModify -qs:fbclid CacheKeyModify -qs:gclid CacheKeyModify -qs:utm* CacheKeyModify -qs:_ga ### marker DROPQS end ### ## LITESPEED WP CACHE PLUGIN - Do not edit the contents of this block! ## # END LSCACHE # BEGIN NON_LSCACHE ## LITESPEED WP CACHE PLUGIN - Do not edit the contents of this block! ## ## LITESPEED WP CACHE PLUGIN - Do not edit the contents of this block! ## # END NON_LSCACHE # ==== Security: block direct PHP everywhere (allowlist core WP) ==== RewriteEngine On # Block any direct .php/.phtml/.phar request by default RewriteCond %{REQUEST_URI} \.(?:php(?:[0-9]?|s)?|phtml|phar)$ [NC] # Allow ONLY these entry points / areas: RewriteCond %{REQUEST_URI} !^/index\.php$ [NC] RewriteCond %{REQUEST_URI} !^/wp-login\.php$ [NC] RewriteCond %{REQUEST_URI} !^/wp-cron\.php$ [NC] RewriteCond %{REQUEST_URI} !^/xmlrpc\.php$ [NC] RewriteCond %{REQUEST_URI} !^/wp-comments-post\.php$ [NC] RewriteCond %{REQUEST_URI} !^/wp-admin/ [NC] RewriteCond %{REQUEST_URI} !^/wp-includes/ [NC] # Everything else -> 403 RewriteRule .* - [F,L] # ==== /Security ==== # Never execute PHP inside uploads (extra guard from root) RewriteEngine On RewriteRule ^wp-content/uploads/.*\.(?:php(?:[0-9]?|s)?|phtml|phar)$ - [F,NC,L] # Block sensitive files Require all denied # Disable directory listing Options -Indexes # BEGIN WordPress # The directives (lines) between "BEGIN WordPress" and "END WordPress" are # dynamically generated, and should only be modified via WordPress filters. # Any changes to the directives between these markers will be overwritten. RewriteEngine On # keep Authorization header (API / Application Passwords) RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] # END WordPress King of Slots Archives - WISTERIABET