Short answer
Outside
public_html and outside your repository, in a configuration file the application reads at runtime. Anything inside public_html can potentially be served to a browser, and anything committed to a repository is very hard to remove afterwards.Learn more
- Storing configuration and secrets outside public_htmlKeep database passwords, API keys and SMTP credentials out of the web root with config files above public_html, .env files and protective .htaccess rules.
- Deploying a PHP application (Composer, Laravel and frameworks)How to deploy a Composer-based PHP app such as Laravel or Symfony on shared hosting: building locally, keeping code outside public_html and environment files.
- Adding security headers with .htaccessAdd HTTP security headers — HSTS, X-Content-Type-Options, Referrer-Policy, frame protection and Permissions-Policy — safely with .htaccess.
Step-by-step
- Deploy a Laravel application to TraxioAdvanced · 60 min · 11 steps
New to Traxio? The PHP hosting page lists the PHP versions, database and tools every account gets, free for the first 30 days.