Apply Kernel-based symlink protection
block default SMTP port
Disable potentially unsafe functions via disable_functions directive in php.ini
Example: disable_functions=dl,system,exec,passthru,shell_exec,stream_select,popen,proc_open,proc_nice,ini_set