A deny-by-default server configuration (even just through .htaccess) will also go a long way. Only explicitly allow the required PHP entry point files to be executed by the webserver, and deny...