Type something to search...
How to set correct file permissions in WordPress?

How to set correct file permissions in WordPress?

The standard, correct file permissions for most WordPress sites are 755 for directories, 644 for files, and something tighter like 640 or 600 for wp-config.php. Just as important is ownership: files should be owned by your user account rather than being writable by everyone, and nothing on your site should ever be set to 777. Getting permissions right limits what an attacker can change if they find a way in, while still letting WordPress update itself and upload media.

Permissions can feel confusing at first because they involve numbers, users, and groups, and the ideal setup depends on how your server runs PHP. This guide explains what file permissions mean, the recommended values for WordPress, how ownership fits in, and how to check and fix permissions using SSH, SFTP, or your hosting control panel, along with how to troubleshoot common problems.

What Are File Permissions?

On Linux servers, which host the vast majority of WordPress sites, every file and directory has permissions that control who can do what with it. There are three types of access:

  • Read (r): View the contents of a file, or list the contents of a directory.
  • Write (w): Modify a file, or create, rename, and delete files inside a directory.
  • Execute (x): Run a file as a program, or enter (traverse) a directory.

These permissions are assigned to three classes of users:

  • Owner (user): The account that owns the file.
  • Group: Users who belong to the file's group.
  • Others (world): Everyone else on the system.

How Numeric Permissions Work

Permissions are usually written as a three-digit number. Each digit represents one class (owner, group, others), and each digit is the sum of:

  • 4 = read
  • 2 = write
  • 1 = execute

So:

  • 7 = 4 + 2 + 1 = read, write, execute
  • 6 = 4 + 2 = read, write
  • 5 = 4 + 1 = read, execute
  • 4 = read only
  • 0 = no access

That means 755 gives the owner full access and gives the group and others read and execute access. 644 gives the owner read and write access, and everyone else read-only access.

When you run ls -l, you'll see the same permissions in symbolic form:

drwxr-xr-x  5 deploy www-data 4096 Sep  7 09:00 wp-content
-rw-r--r--  1 deploy www-data  405 Sep  7 09:00 index.php
-rw-r-----  1 deploy www-data 3412 Sep  7 09:00 wp-config.php

The first character is d for directories or - for files. The next nine characters are three groups of rwx for owner, group, and others.

Recommended WordPress File Permissions

Here are the widely accepted defaults, in line with the WordPress developer documentation on file permissions:

  • All directories: 755
  • All files: 644
  • wp-config.php: 640 or 600 (some hosts recommend 440 or 400)
  • .htaccess: 644 (or 444 if you don't want WordPress to change it)
  • wp-content/uploads: 755 for directories, 644 for files, and it must be writable by whichever user PHP runs as

Why Not 777?

Setting 777 means every user on the server can read, write, and execute the file or directory. On shared hosting, that could let another compromised account modify your site. Even on a dedicated server, it means any process, including a compromised plugin, can change anything. Tutorials that suggest 777 to "fix" upload errors are solving an ownership problem the dangerous way. There's almost always a better fix.

Why Directories Need Execute Permission

For directories, "execute" means the ability to enter them and access files inside. Without it, the web server can't reach the files within, even if those files are readable. That's why directories are 755 while files are 644.

Understanding File Ownership

Permissions only make sense together with ownership. The key question is: which user does PHP run as?

There are two common setups:

Setup 1: PHP Runs as Your User

Many modern hosts, and servers using PHP-FPM with a dedicated pool per site, run PHP as the same user who owns the files. In this case:

  • Files owned by your user with 644 are writable by PHP (because PHP is the owner).
  • WordPress can install updates and plugins directly without asking for FTP credentials.
  • wp-config.php can be 600 or 640.

Setup 2: PHP Runs as the Web Server User

On some servers, PHP runs as the web server's user, such as www-data on Ubuntu/Debian or apache or nginx on RHEL-based systems. In this case:

  • Files owned by your user with 644 are readable but not writable by PHP.
  • WordPress will prompt for FTP credentials when updating, unless wp-content is writable by the web server user.
  • The usual solution is to make the web server's group the file group and give the group write access only where needed, such as wp-content/uploads.

You can check which user PHP runs as by creating a temporary file (and deleting it straight away afterwards):

<?php
// Save as whoami-check.php in your site root, visit it once, then delete it.
$user = function_exists( 'posix_getpwuid' ) ? posix_getpwuid( posix_geteuid() )['name'] : 'posix extension not available';
echo htmlspecialchars( $user, ENT_QUOTES, 'UTF-8' );

Don't leave this file on your server, since it reveals system information. Alternatively, on the command line, check the PHP-FPM pool configuration:

grep -E "^(user|group)" /etc/php/8.3/fpm/pool.d/*.conf

Adjust the PHP version in the path to match your server.

How to Check Your Current Permissions

Using SSH

From your WordPress root, list permissions of key files:

ls -la
ls -la wp-content
stat -c "%a %U:%G %n" wp-config.php .htaccess

Find anything that's world-writable, which should almost never exist:

find . -perm -o+w -not -type l

Find files and folders that don't match the recommended defaults:

# Directories that aren't 755
find . -type d -not -perm 755

# Files that aren't 644 (excluding wp-config.php)
find . -type f -not -perm 644 -not -name wp-config.php

Using an SFTP Client

In FileZilla, right-click any file or folder and choose File permissions... to see and change its numeric value. Cyberduck offers the same through Get Info > Permissions.

Using Your Hosting File Manager

In cPanel's File Manager, the Permissions column shows the numeric value for each item, and you can right-click and choose Change Permissions. Plesk and other panels have similar options.

Using Site Health

WordPress's Tools > Site Health > Info > Filesystem Permissions section shows whether key directories, like the WordPress directory, wp-content, uploads, plugins, and themes, are writable. It doesn't show exact values, but it's useful for spotting problems quickly.

How to Set Correct Permissions

Always take a full backup before changing permissions in bulk.

Method 1: Using SSH (Recommended)

Navigate to your WordPress root first. Double-check you're in the right folder, since these commands apply recursively:

cd /var/www/example.com/public_html
pwd

Set all directories to 755 and all files to 644:

find . -type d -exec chmod 755 {} +
find . -type f -exec chmod 644 {} +

Then tighten wp-config.php:

chmod 640 wp-config.php

If PHP runs as your user and the site still works, you can go to 600. If you see a database connection error after this change, PHP can't read the file; revert to 640 or 644 and check ownership.

Setting Ownership

If files are owned by the wrong user, for example after being uploaded as root, fix ownership. Replace deploy with your SSH/SFTP user and www-data with your web server group:

sudo chown -R deploy:www-data /var/www/example.com/public_html

If PHP runs as the web server user and needs to write to uploads, give the group write access there only:

sudo find wp-content/uploads -type d -exec chmod 775 {} +
sudo find wp-content/uploads -type f -exec chmod 664 {} +

Only do this if PHP runs as a separate user in the same group. If PHP runs as the file owner, 755 and 644 are already enough.

Method 2: Using an SFTP Client

In FileZilla:

  1. Select the WordPress root folder: Right-click it and choose File permissions....

  2. Set directories: Enter 755, tick Recurse into subdirectories, and choose Apply to directories only. Click OK.

  3. Set files: Right-click again, enter 644, tick Recurse into subdirectories, and choose Apply to files only. Click OK.

  4. Set wp-config.php: Right-click wp-config.php and set it to 640 or 600.

This can take a while on large sites because the client changes each file individually.

Method 3: Using Your Host's Tools

Many hosts offer a one-click "fix permissions" tool in their dashboard. Managed WordPress hosts often manage permissions for you and may not let you change them at all, which is fine. If you're unsure, ask your host's support team what values they recommend for their environment.

Securing Specific Files and Folders

wp-config.php

This file holds your database credentials and security keys, so it deserves the tightest permissions your server allows. 640 is a good default; 600 or 400 if PHP runs as the file owner.

.htaccess

.htaccess needs to be readable by Apache. 644 is standard. If you set it to 444, WordPress can't update it automatically when you change permalink settings under Settings > Permalinks, and it will show you the rules to add manually instead.

wp-content/uploads

This folder must be writable by PHP so you can upload media. It's also a common place for attackers to try to drop malicious scripts, so pair correct permissions with a rule that blocks PHP execution in uploads.

wp-content/plugins and wp-content/themes

These need to be writable by PHP only if you want to install and update plugins and themes from the dashboard. On sites deployed via Git, you can make them read-only for PHP and handle updates through your deployment process.

Configuring WordPress Filesystem Access

If WordPress keeps asking for FTP credentials when you install or update plugins, it means PHP can't write to the files directly. You have a few options:

  • Fix ownership so PHP can write to wp-content (preferred on servers you control).
  • Use SFTP credentials by entering them in the prompt, or define them in wp-config.php above the "That's all, stop editing!" line:
define( 'FS_METHOD', 'ssh2' );
define( 'FTP_HOST', 'example.com' );
define( 'FTP_USER', 'deploy' );
define( 'FTP_PUBKEY', '/home/deploy/.ssh/id_ed25519.pub' );
define( 'FTP_PRIKEY', '/home/deploy/.ssh/id_ed25519' );

The ssh2 method requires the PHP SSH2 extension. Avoid storing plain FTP passwords in wp-config.php if you can, and never use unencrypted FTP.

  • Force direct writes only if PHP already has write access:
define( 'FS_METHOD', 'direct' );

Don't combine FS_METHOD set to direct with loosened permissions like 777 just to make updates work.

You can also control the permissions WordPress uses when it creates new files and folders:

define( 'FS_CHMOD_DIR', ( 0755 & ~ umask() ) );
define( 'FS_CHMOD_FILE', ( 0644 & ~ umask() ) );

Troubleshooting Permission Problems

"Unable to create directory" or upload errors: PHP can't write to wp-content/uploads. Check the folder's ownership and permissions. Fix ownership rather than setting 777.

403 Forbidden errors: Directories may be missing execute permission, or files may not be readable by the web server. Reset directories to 755 and files to 644.

"Error establishing a database connection" after changing wp-config.php permissions: PHP can't read the file. Loosen to 640 or 644 and check which user PHP runs as.

WordPress asks for FTP details when updating: PHP doesn't own or can't write to the files. Fix ownership, configure SSH2 credentials, or update via WP-CLI.

Changes revert after a while: Some hosts run scheduled scripts that reset permissions. Check with your host before fighting it.

Keep Permissions Correct Over Time

Permissions can drift when files are uploaded by different users, restored from backups, or modified by plugins. Build a quick check into your maintenance routine:

# Report anything world-writable or not matching defaults
find /var/www/example.com/public_html -perm -o+w -not -type l
find /var/www/example.com/public_html -type d -not -perm 755 | head
find /var/www/example.com/public_html -type f -not -perm 644 -not -name wp-config.php | head

Security plugins such as Solid Security and All-In-One Security (AIOS) also include file permission checks that flag risky settings on key files.


FAQ: WordPress File Permissions

Use 755 for directories and 644 for files. Set wp-config.php more strictly, usually 640 or 600, depending on how PHP runs on your server.

No. 777 lets anyone on the server read, write, and execute the file or folder. If something needs to be writable, fix the ownership instead of opening permissions to everyone.

640 is a safe default on most servers. If PHP runs as the file owner, 600 or 400 is even better. If the site breaks after tightening, check which user PHP runs as.

Because PHP can't write to your WordPress files directly. This is usually an ownership issue. Fixing ownership, configuring SSH2 credentials, or updating with WP-CLI resolves it.

Yes. Most SFTP clients, such as FileZilla, and hosting file managers, such as cPanel, let you change permissions, including recursively for folders.

Ownership decides which user and group a file belongs to. Permissions decide what the owner, the group, and everyone else can do with it. Both need to be correct.

Usually, yes. Many managed hosts set and maintain permissions automatically and may not allow changes. Check your host's documentation if you're unsure.


Conclusion

Correct file permissions are a quiet but important layer of WordPress security. The standard setup of 755 for directories, 644 for files, and a tighter 640 or 600 for wp-config.php keeps your site working while limiting what an attacker, or a misbehaving plugin, can change. Understanding which user PHP runs as is the key to getting ownership right and avoiding the temptation to use 777.

Check your permissions after migrations, restores, and major changes, and include a quick scan in your regular maintenance routine. Combined with blocking PHP in uploads, disabling the file editor, and keeping everything updated, sensible permissions make your WordPress site a much harder target.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper