Most of my installs run from their own directory but most of my installs are multi-site so I don’t go too far from the norm… the norm in my book is ‘WordPress in its own Directory’ running as you most likely have yours.
There is one more security step where you can take WP-config outside (above) the web root and ‘hide’ it and that very sensitive content that file contains outside of view from casual reach.
The server would normally hide the content of all PHP files but that content could become exposed when something breaks. Here’s an article that helps explain this well and can help you move this file if you wish https://www.groovypost.com/howto/improve-wordpress-securitty-wp-config-php-location/
Exposing directories is just part of the ways of how things work but most of that exposure is not exposing the actual data or data locations.
]]>