File: /var/www/html/cisuenolar.sumar.com.py/.htaccess
# Bloquear ejecución de scripts potencialmente maliciosos
<FilesMatch "\.(py|exe|phar|php5|phtml|suspected)$">
Require all denied
</FilesMatch>
# Permitir archivos legítimos de WordPress
<FilesMatch "^(index\.php|wp-blog-header\.php|wp-login\.php|wp-settings\.php|wp-config\.php)$">
Require all granted
</FilesMatch>
# Reglas estándar de WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>