i think you have to user include_path and set it not on the same place with the doc_root ! (ex : /usr/local/php/include) for this problem ! even the "badguy" already know your file name, he can't download it ! because it can reached with browser ! and they never never see your source code in the browser !
edit your php.ini :
include_path = "/usr/local/php/include"
thats all !
Best Regards,
Wendi Lie
indonesia