There are 2 places best set to hold the members directory. The cgi-bin, as if anyone tries to access the file directly, it'll be executed and the user will only see an ISE. The other is any folder above the webroot, so the file wouldn't be accessible from anywhere but ftp