Best advice is not to expose it publicly.
If you need access outside your LAN try using a VPN to your network with wireguard (wg-easy is nice) or tailscale (there are others as well).
If it's using a domain/subdomain make sure you use secure usernames and passwords, or things like authentik, authelia and the like to buff up security.