User-agent: * Disallow: /includes/ # You can and should secure other folders too, like... Disallow: /images/ Disallow: /db/ Disallow: /admin/ Disallow: /db/admin/