    Do you think this is necessary?

    I have password protected an entire directory using .htaccess.

    The administrator scripts are in this directory and I was wondering if you think adding something like:

    if (isset( $PHP_AUTH_USER ) && isset($PHP_AUTH_PW)) {
    //do stuff here

    would be nessesary or not. Would it add any extra security?
    Depends how paranoid you are. It can't hurt, and could come in handy if the .htaccess file was accidentally erased for some reason (or if you move to another site and somehow don't copy the file, or whatever).

    Since it's so easy to add, I'd say why not add it.

    Just a comment:

    if (isset( $PHP_AUTH_USER ) && isset($PHP_AUTH_PW)) {
    //do stuff here
    will not work when compiled as php-cgi module.

