This is the correct way to allow a sub-directory of a server-level password protected directory to be accessed without a password.
I would like to note that ever since Joomla! 1.5.0, released ten years ago in January 2007, using an /administrator URL for any kind of static media content (Javascript, CSS, images, ...) is obsolete and discouraged. The /media directory on your site has assumed this role. Using software which has not figured out how to catch up with a ten year old best practice recommendation is ill-advised at best. It tells me, as a developer, that its developer doesn't really care to follow Joomla standards and raises questions about which other standards he bends. Is he using any of the security features in Joomla or is he also side-stepping them? I would contact that developer and ask them to fix this issue. In case he denies I'd go with another component altogether.
Nicholas K. Dionysopoulos
Lead Developer and Director
🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!