Tip: if you cannot see the .htaccess file in cPanel File Manager, enable Show Hidden Files (dotfiles) in File Manager settings.
To prevent visitors from accessing your .htaccess file directly, add this rule to the file in your site’s document root:
# Protect .htaccess
<Files ".htaccess">
Require all denied
</Files>
Save the file and verify that your website still loads as expected. The Require all denied directive is supported by Apache 2.4. On older Apache versions, use this syntax instead:
<Files ".htaccess">
Order allow,deny
Deny from all
</Files>
