I would suggest this approach instead:
Using this .htaccess approach helps ensure you don’t accidentally make the .env file with all credentials available for public download.
.env