If you use nginx over apache for serving static content, it's possible that protected files remain accessible via their real paths. An therefore you'd better check and edit the list of extensions in nginx.conf. Maybe this fact is worth mentioning in documentation.