Options -Indexes
# Block executable scripts
<FilesMatch "\.(php|phtml|php3|php4|php5|phps|pl|py|cgi|asp|aspx|sh|shtml)$">
    Deny from all
</FilesMatch>

# Allow static assets (images, docs, etc.)
<FilesMatch "\.(jpg|jpeg|png|gif|webp|svg|ico|bmp|pdf|txt|mp4|mp3)$">
    Allow from all
    Satisfy Any
</FilesMatch>