if you automate it and overtime you may put files in wierd places or perhaps a config file gets saved as .php.1 or something, never know and because that aint filtered, it will get picked up... anyone can download your sitemap and view everything in your subdirectories then
|