
How to set correct file permissions in WordPress?
- Sajjad
- WordPress, Security
- 07 Sep, 2026
The standard, correct file permissions for most WordPress sites are 755 for directories, 644 for files, and something tighter like 640 or 600 for wp-config.php. Just as important is ownership: files should be owned by your user account rather than being writable by everyone, and nothing on your site should ever be set to 777. Getting permissions right limits what an attacker can change if they find a way in, while still letting WordPress update itself and upload media.
Permissions can feel confusing at first because they involve numbers, users, and groups, and the ideal setup depends on how your server runs PHP. This guide explains what file permissions mean, the recommended values for WordPress, how ownership fits in, and how to check and fix permissions using SSH, SFTP, or your hosting control panel, along with how to troubleshoot common problems.
What Are File Permissions?
On Linux servers, which host the vast majority of WordPress sites, every file and directory has permissions that control who can do what with it. There are three types of access:
- Read (r): View the contents of a file, or list the contents of a directory.
- Write (w): Modify a file, or create, rename, and delete files inside a directory.
- Execute (x): Run a file as a program, or enter (traverse) a directory.
These permissions are assigned to three classes of users:
- Owner (user): The account that owns the file.
- Group: Users who belong to the file's group.
- Others (world): Everyone else on the system.
How Numeric Permissions Work
Permissions are usually written as a three-digit number. Each digit represents one class (owner, group, others), and each digit is the sum of:
4= read2= write1= execute
So:
7= 4 + 2 + 1 = read, write, execute6= 4 + 2 = read, write5= 4 + 1 = read, execute4= read only0= no access
That means 755 gives the owner full access and gives the group and others read and execute access. 644 gives the owner read and write access, and everyone else read-only access.
When you run ls -l, you'll see the same permissions in symbolic form:
drwxr-xr-x 5 deploy www-data 4096 Sep 7 09:00 wp-content
-rw-r--r-- 1 deploy www-data 405 Sep 7 09:00 index.php
-rw-r----- 1 deploy www-data 3412 Sep 7 09:00 wp-config.php
The first character is d for directories or - for files. The next nine characters are three groups of rwx for owner, group, and others.
Recommended WordPress File Permissions
Here are the widely accepted defaults, in line with the WordPress developer documentation on file permissions:
- All directories:
755 - All files:
644 - wp-config.php:
640or600(some hosts recommend440or400) - .htaccess:
644(or444if you don't want WordPress to change it) - wp-content/uploads:
755for directories,644for files, and it must be writable by whichever user PHP runs as
Why Not 777?
Setting 777 means every user on the server can read, write, and execute the file or directory. On shared hosting, that could let another compromised account modify your site. Even on a dedicated server, it means any process, including a compromised plugin, can change anything. Tutorials that suggest 777 to "fix" upload errors are solving an ownership problem the dangerous way. There's almost always a better fix.
Why Directories Need Execute Permission
For directories, "execute" means the ability to enter them and access files inside. Without it, the web server can't reach the files within, even if those files are readable. That's why directories are 755 while files are 644.
Understanding File Ownership
Permissions only make sense together with ownership. The key question is: which user does PHP run as?
There are two common setups:
Setup 1: PHP Runs as Your User
Many modern hosts, and servers using PHP-FPM with a dedicated pool per site, run PHP as the same user who owns the files. In this case:
- Files owned by your user with
644are writable by PHP (because PHP is the owner). - WordPress can install updates and plugins directly without asking for FTP credentials.
wp-config.phpcan be600or640.
Setup 2: PHP Runs as the Web Server User
On some servers, PHP runs as the web server's user, such as www-data on Ubuntu/Debian or apache or nginx on RHEL-based systems. In this case:
- Files owned by your user with
644are readable but not writable by PHP. - WordPress will prompt for FTP credentials when updating, unless
wp-contentis writable by the web server user. - The usual solution is to make the web server's group the file group and give the group write access only where needed, such as
wp-content/uploads.
You can check which user PHP runs as by creating a temporary file (and deleting it straight away afterwards):
<?php
// Save as whoami-check.php in your site root, visit it once, then delete it.
$user = function_exists( 'posix_getpwuid' ) ? posix_getpwuid( posix_geteuid() )['name'] : 'posix extension not available';
echo htmlspecialchars( $user, ENT_QUOTES, 'UTF-8' );
Don't leave this file on your server, since it reveals system information. Alternatively, on the command line, check the PHP-FPM pool configuration:
grep -E "^(user|group)" /etc/php/8.3/fpm/pool.d/*.conf
Adjust the PHP version in the path to match your server.
How to Check Your Current Permissions
Using SSH
From your WordPress root, list permissions of key files:
ls -la
ls -la wp-content
stat -c "%a %U:%G %n" wp-config.php .htaccess
Find anything that's world-writable, which should almost never exist:
find . -perm -o+w -not -type l
Find files and folders that don't match the recommended defaults:
# Directories that aren't 755
find . -type d -not -perm 755
# Files that aren't 644 (excluding wp-config.php)
find . -type f -not -perm 644 -not -name wp-config.php
Using an SFTP Client
In FileZilla, right-click any file or folder and choose File permissions... to see and change its numeric value. Cyberduck offers the same through Get Info > Permissions.
Using Your Hosting File Manager
In cPanel's File Manager, the Permissions column shows the numeric value for each item, and you can right-click and choose Change Permissions. Plesk and other panels have similar options.
Using Site Health
WordPress's Tools > Site Health > Info > Filesystem Permissions section shows whether key directories, like the WordPress directory, wp-content, uploads, plugins, and themes, are writable. It doesn't show exact values, but it's useful for spotting problems quickly.
How to Set Correct Permissions
Always take a full backup before changing permissions in bulk.
Method 1: Using SSH (Recommended)
Navigate to your WordPress root first. Double-check you're in the right folder, since these commands apply recursively:
cd /var/www/example.com/public_html
pwd
Set all directories to 755 and all files to 644:
find . -type d -exec chmod 755 {} +
find . -type f -exec chmod 644 {} +
Then tighten wp-config.php:
chmod 640 wp-config.php
If PHP runs as your user and the site still works, you can go to 600. If you see a database connection error after this change, PHP can't read the file; revert to 640 or 644 and check ownership.
Setting Ownership
If files are owned by the wrong user, for example after being uploaded as root, fix ownership. Replace deploy with your SSH/SFTP user and www-data with your web server group:
sudo chown -R deploy:www-data /var/www/example.com/public_html
If PHP runs as the web server user and needs to write to uploads, give the group write access there only:
sudo find wp-content/uploads -type d -exec chmod 775 {} +
sudo find wp-content/uploads -type f -exec chmod 664 {} +
Only do this if PHP runs as a separate user in the same group. If PHP runs as the file owner, 755 and 644 are already enough.
Method 2: Using an SFTP Client
In FileZilla:
-
Select the WordPress root folder: Right-click it and choose File permissions....
-
Set directories: Enter
755, tick Recurse into subdirectories, and choose Apply to directories only. Click OK. -
Set files: Right-click again, enter
644, tick Recurse into subdirectories, and choose Apply to files only. Click OK. -
Set wp-config.php: Right-click
wp-config.phpand set it to640or600.
This can take a while on large sites because the client changes each file individually.
Method 3: Using Your Host's Tools
Many hosts offer a one-click "fix permissions" tool in their dashboard. Managed WordPress hosts often manage permissions for you and may not let you change them at all, which is fine. If you're unsure, ask your host's support team what values they recommend for their environment.
Securing Specific Files and Folders
wp-config.php
This file holds your database credentials and security keys, so it deserves the tightest permissions your server allows. 640 is a good default; 600 or 400 if PHP runs as the file owner.
.htaccess
.htaccess needs to be readable by Apache. 644 is standard. If you set it to 444, WordPress can't update it automatically when you change permalink settings under Settings > Permalinks, and it will show you the rules to add manually instead.
wp-content/uploads
This folder must be writable by PHP so you can upload media. It's also a common place for attackers to try to drop malicious scripts, so pair correct permissions with a rule that blocks PHP execution in uploads.
wp-content/plugins and wp-content/themes
These need to be writable by PHP only if you want to install and update plugins and themes from the dashboard. On sites deployed via Git, you can make them read-only for PHP and handle updates through your deployment process.
Configuring WordPress Filesystem Access
If WordPress keeps asking for FTP credentials when you install or update plugins, it means PHP can't write to the files directly. You have a few options:
- Fix ownership so PHP can write to
wp-content(preferred on servers you control). - Use SFTP credentials by entering them in the prompt, or define them in
wp-config.phpabove the "That's all, stop editing!" line:
define( 'FS_METHOD', 'ssh2' );
define( 'FTP_HOST', 'example.com' );
define( 'FTP_USER', 'deploy' );
define( 'FTP_PUBKEY', '/home/deploy/.ssh/id_ed25519.pub' );
define( 'FTP_PRIKEY', '/home/deploy/.ssh/id_ed25519' );
The ssh2 method requires the PHP SSH2 extension. Avoid storing plain FTP passwords in wp-config.php if you can, and never use unencrypted FTP.
- Force direct writes only if PHP already has write access:
define( 'FS_METHOD', 'direct' );
Don't combine FS_METHOD set to direct with loosened permissions like 777 just to make updates work.
You can also control the permissions WordPress uses when it creates new files and folders:
define( 'FS_CHMOD_DIR', ( 0755 & ~ umask() ) );
define( 'FS_CHMOD_FILE', ( 0644 & ~ umask() ) );
Troubleshooting Permission Problems
"Unable to create directory" or upload errors: PHP can't write to wp-content/uploads. Check the folder's ownership and permissions. Fix ownership rather than setting 777.
403 Forbidden errors: Directories may be missing execute permission, or files may not be readable by the web server. Reset directories to 755 and files to 644.
"Error establishing a database connection" after changing wp-config.php permissions: PHP can't read the file. Loosen to 640 or 644 and check which user PHP runs as.
WordPress asks for FTP details when updating: PHP doesn't own or can't write to the files. Fix ownership, configure SSH2 credentials, or update via WP-CLI.
Changes revert after a while: Some hosts run scheduled scripts that reset permissions. Check with your host before fighting it.
Keep Permissions Correct Over Time
Permissions can drift when files are uploaded by different users, restored from backups, or modified by plugins. Build a quick check into your maintenance routine:
# Report anything world-writable or not matching defaults
find /var/www/example.com/public_html -perm -o+w -not -type l
find /var/www/example.com/public_html -type d -not -perm 755 | head
find /var/www/example.com/public_html -type f -not -perm 644 -not -name wp-config.php | head
Security plugins such as Solid Security and All-In-One Security (AIOS) also include file permission checks that flag risky settings on key files.
FAQ: WordPress File Permissions
Use 755 for directories and 644 for files. Set wp-config.php more strictly, usually 640 or 600, depending on how PHP runs on your server.
No. 777 lets anyone on the server read, write, and execute the file or folder. If something needs to be writable, fix the ownership instead of opening permissions to everyone.
640 is a safe default on most servers. If PHP runs as the file owner, 600 or 400 is even better. If the site breaks after tightening, check which user PHP runs as.
Because PHP can't write to your WordPress files directly. This is usually an ownership issue. Fixing ownership, configuring SSH2 credentials, or updating with WP-CLI resolves it.
Yes. Most SFTP clients, such as FileZilla, and hosting file managers, such as cPanel, let you change permissions, including recursively for folders.
Ownership decides which user and group a file belongs to. Permissions decide what the owner, the group, and everyone else can do with it. Both need to be correct.
Usually, yes. Many managed hosts set and maintain permissions automatically and may not allow changes. Check your host's documentation if you're unsure.
Conclusion
Correct file permissions are a quiet but important layer of WordPress security. The standard setup of 755 for directories, 644 for files, and a tighter 640 or 600 for wp-config.php keeps your site working while limiting what an attacker, or a misbehaving plugin, can change. Understanding which user PHP runs as is the key to getting ownership right and avoiding the temptation to use 777.
Check your permissions after migrations, restores, and major changes, and include a quick scan in your regular maintenance routine. Combined with blocking PHP in uploads, disabling the file editor, and keeping everything updated, sensible permissions make your WordPress site a much harder target.


