I am using Laravel for web app. Uploaded everything on production and found out that some of the files can be directly accessed by url - for example http://example.com/compo
You Can Deny files in .htaccess too.
Order Allow,Deny Deny from all