Wouldn't `security.limit_extensions = .php .php3 .php4 .php5` also be useful? Perhaps a warning about `cgi.fix_pathinfo`?