Locking down the wp-includes directory that you mentioned is a good step to prevent public access. For additional security, use the rule RewriteRule ^...
(03) 9543 7566
Unit 33 15 Ricketts Rd, Mount Waverley VIC 3149.
(03) 9543 7566
Unit 33 15 Ricketts Rd, Mount Waverley VIC 3149.