The .user.ini file is readable by web users?
"The .user.ini file is readable by web users" is what my security plugin, which I just installed, tells me.
How do I secure the .user.ini file? Do I simply need to change the chmod permissions via FTP? And if so, which permissions?
Of course, you also need to consider which Ownership/ Group is set on the .user.ini, and with which user the php processes run so that the whole is really safer.
I have the security plugin on 3 of my sites that I maintain and on one comes hold this error message – see Image.