Hi kuroi,
I'll second that. My suggestion would of course be to have any records maintained outside the site's web root. Only files which need to be publicly accessible should be in the site's web root. (Unlike Zen Cart does, I wouldn't even include any code library files in the web root but that's more than we need to talk about here..).
All the best..
Conor
ceon
Bookmarks