I wonder if you could do some more magic by not letting *.php files in /sites/default/files be run but downloaded only?
Hi Don. Just wondering if it's possible to have a php script chron job that safely checks hourly and automatically deletes any php files in /sites/default/files. We've never found a need for new or additional php files in /sites/default/files Not sure but ?
Roger