I was using cPanel imunifyAV to scan the website and I got the results.
https://paste.pics/2130406e07aece246110c0a4c1926be2
What if I set the filetypes to only jpg and want to restrict all other extension.
BUT the uploader still able to upload other file types by modify the extension.
For instance image.pdf, this suppose not accepted if I set the filetypes to jpg only. But they can modify the image.pdf to image.jpg.