@markmcb@mas.to I do something very similar to what you do, a bit more complicated. Anyone requesting .php or a number of other paths gets a 403 and firewalled via fail2ban, no matter what the HTTP version (I don't have WP or any PHP on my site, no one should be asking for /admin, etc etc etc). And then for HTTP 1.x I allow requests for atom.xml and rss.xml; allow a list of bots I approve of; serve 418 to the rest, with a little teapot emoji as the body.