用forbidden配置禁止访问目录。

localhost {    
    root * /var/www/html
    encode zstd gzip

    @forbidden {
        not path /wp-includes/ms-files.php
        path /wp-admin/includes/*.php
        path /wp-includes/*.php
        path /wp-config.php
        path /wp-content/uploads/*.php
        path /.user.ini
        path /wp-content/debug.log
    }
    respond @forbidden "Access denied" 403

    php_fastcgi wp-fpm:9000
    file_server
}