This is great use of custom rules. We may or may not do a slightly more sophisticated version of this in Vercel's platform-wide firewall by default ๐
Blocked all bots looking for php vulnerabilities with this custom rule in Vercel Firewall. Firewall โ Configure โ + New Rule Name: Block .php request paths If "Request Path" - "Contains" - ".php" AND Then "Deny" Save Rule โ Review Changes โ Publish Enjoy ๐