And then your text editor might leave a backup copy with filename "xyz.php~" which PHP won't interpret and Apache will happily serve to a curious user as plain text.
So I've heard :-)
<Files "*~">
Require all denied
</Files>
<Files "DEADJOE">
Require all denied
</Files>
(last one assuming you're using joe)
Sometimes you can edit someone else’s live PHP files right on their server.
I miss the days when this was normal for production websites. I wrote delete query once but forgot the where clause so I nuked the prod DB.