I'm sorry but a friend showed me that this site can hack easily.
So I would put one. htaccess on pages who are uploading
<Files "*.php">
Order allow, deny
Deny from all
</ Files>
AddHandler text / html. Php. Php3. Php4. Php5. Phtml. Phps. Pl. Py. Cgi :)