i would be carefull with this! / #2127

Problem is, not everybody has/needs the same configuration. And there are some differences between Windows-PHP-Servers and LINUX-PHP-Servers.
Last, the php.ini could (or even should) differ between different versions of PHP.

Therefore we should add some comments to the manual on how to lock up strebers installation, but adding configuration files for webservers is too dangerous in my opinion. Not every admin is that good, to see the danger in replacing php.ini. Perhaps on the same server there are different applications running and for them the php.ini (or .htaccess) was edited for.

long story short: i agree with making an "streber server security HowTo", but i don't agree with making .htaccess and php.ini part of the repository or install-version.