# 1. EVITAR EXPLORACIÓN DE DIRECTORIOS
# Evita que alguien vea la lista de archivos si no hay un index.php
Options -Indexes

# 2. PROTEGER WP-CONFIG.PHP
# Es el archivo más importante, nadie debe verlo vía web
<Files wp-config.php>
    Order allow,deny
    Deny from all
</Files>

# 3. PROTEGER EL PROPIO .HTACCESS
<Files .htaccess>
    Order allow,deny
    Deny from all
</Files>

# 4. BLOQUEAR SCRIPTS SOSPECHOSOS Y XML-RPC (Opcional pero recomendado)
# XML-RPC suele usarse para ataques de fuerza bruta. 
# Si no usas la App de WP o Jetpack, bloquéalo.
<Files xmlrpc.php>
    Order allow,deny
    Deny from all
</Files>

# 5. REGLAS ESTÁNDAR DE WORDPRESS
<IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteBase /
    RewriteRule ^index\.php$ - [L]
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule . /index.php [L]
</IfModule>

# 6. SEGURIDAD EXTRA: Bloquear inyección de scripts
<IfModule mod_rewrite.c>
    RewriteCond %{QUERY_STRING} (<|%3C).*script.*(>|%3E) [NC,OR]
    RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
    RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
    RewriteRule ^(.*)$ index.php [F,L]
</IfModule>
# BEGIN WordPress
# The directives (lines) between "BEGIN WordPress" and "END WordPress" are
# dynamically generated, and should only be modified via WordPress filters.
# Any changes to the directives between these markers will be overwritten.
<IfModule mod_expires.c>
	ExpiresActive On
	ExpiresByType image/jpg "access plus 24 hours"
	ExpiresByType image/jpeg "access plus 24 hours"
	ExpiresByType image/gif "access plus 24 hours"
	ExpiresByType image/png "access plus 24 hours"
	ExpiresByType text/css "access plus 24 hours"
	ExpiresByType application/pdf "access plus 1 week"
	ExpiresByType text/javascript "access plus 24 hours"
	ExpiresByType text/html "access plus 2 hours"
	ExpiresByType image/x-icon "access plus 1 year"
	ExpiresDefault "access plus 24 hours"
</IfModule>
Options -Indexes
<IfModule mod_headers.c>
	Header set X-Endurance-Cache-Level "2"
	Header set X-nginx-cache "WordPress"
</IfModule>
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>

# END WordPress