First of all, I\'m pretty sure a similar question will be on Stack Overflow, but I didn\'t really find it. Probably because I am using the wrong keywords. So don\'t shoot me
Make a .htaccess file in your includes directory
deny from all
Can't be done for client-side scripts because the browser must be able to access them. The best you can do is obfuscate them.