File permissions control who can read, write, or execute files on your server. Get them wrong and you'll face security vulnerabilities or broken functionality. Get them right and your WordPress site runs smoothly with minimal risk. This guide walks you through everything from what permissions actually are to the exact commands you need.
What Are File Permissions?
Every file and folder on a Linux server has three permission types assigned to three categories of users.
The three permission types:
- Read (r): View the file's contents or list a directory's contents
- Write (w): Modify, delete, or add to the file or directory
- Execute (x): Run the file as a program, or access a directory to change into it
The three user categories:
- Owner: The user account that owns the file (usually your cPanel username or
www-data) - Group: A group of users that share access (often the web server group)
- Others: Everyone else on the system
When you see a permission like 644 or 755, those numbers represent the combination of read, write, and execute permissions for owner, group, and others.
Understanding Permission Numbers
Linux uses octal notation where each digit represents permissions for one category.
Each permission has a numeric value:
- Read = 4
- Write = 2
- Execute = 1
You add these values together:
- 7 = read + write + execute (4+2+1)
- 6 = read + write (4+2)
- 5 = read + execute (4+1)
- 4 = read only
- 0 = no permissions
Example: 644
- First digit (6): Owner can read and write
- Second digit (4): Group can read only
- Third digit (4): Others can read only
Example: 755
- First digit (7): Owner can read, write, and execute
- Second digit (5): Group can read and execute
- Third digit (5): Others can read and execute
Directories need execute permission so users can access them. Files rarely need execute permission unless they're scripts.
WordPress Standard Permissions
WordPress follows a security principle: give the minimum permissions needed for the site to function.
Standard file permissions: 644
- Owner can edit files
- Web server can read files to serve pages
- Nobody else can modify anything
Standard directory permissions: 755
- Owner can create, delete, and navigate folders
- Web server can read and navigate folders
- Others can read and navigate but not modify
Exception: wp-config.php should be 440 or 400
This file contains your database credentials. Restrict it so only the owner and web server (or only the owner) can read it. The web server doesn't need write access.
Why Permissions Matter for Security
Too permissive (777 or 666):
If you set everything to 777, any user on the server can modify your files. This includes:
- Attackers who compromise another site on shared hosting
- Malicious scripts that exploit vulnerabilities
- Accidents from other applications
Setting files to 777 is never necessary for WordPress and creates unnecessary risk.
Too restrictive (400 or 444):
If files are read-only for everyone including the owner, WordPress can't update itself, install plugins, or upload media. You'll see permission errors when trying to save posts or update themes.
The balance:
WordPress needs to read files to display your site and write to specific directories like wp-content/uploads for media uploads. Standard permissions achieve this without exposing your site to unnecessary risk.
Understanding File Ownership
Permissions work alongside ownership. Even if permissions are correct, the wrong owner causes problems.
Two ownership attributes:
- User owner: Usually your cPanel username or the web server user (
www-data,apache,nginx) - Group owner: Often matches the user owner or is set to the web server group
Typical ownership patterns:
Shared hosting (cPanel):
- User: your cPanel username
- Group: your cPanel username
- Web server runs as your user through suPHP or PHP-FPM
VPS or dedicated server:
- User:
www-dataorapache - Group:
www-dataorapache - Web server runs as its own user
To see ownership, use:
ls -la /path/to/wordpress/
You'll see output like:
drwxr-xr-x 5 username username 4096 Jul 08 10:30 wp-content
-rw-r--r-- 1 username username 3164 Jul 08 10:30 wp-config.php
The third and fourth columns show the user owner and group owner.
How to Check Current Permissions
Via SSH:
Connect to your server and navigate to your WordPress directory:
cd /home/username/public_html
ls -la
Look at the first column. It shows permissions in letter format:
drwxr-xr-x= directory with 755 permissions-rw-r--r--= file with 644 permissions-rw-r-----= file with 640 permissions
To see numeric permissions:
stat -c '%a %n' wp-config.php
Output: 644 wp-config.php
Via FTP:
Most FTP clients show permissions in the file properties. Right-click a file or folder and select "File Permissions" or "Properties." You'll see checkboxes for read, write, and execute or a numeric field.
Via cPanel File Manager:
- Log into cPanel
- Open File Manager
- Navigate to public_html
- Right-click any file or folder
- Select "Permissions"
- The dialog shows both checkboxes and the numeric value
Setting WordPress Permissions Correctly
Before you start:
Back up your site. If something goes wrong, you can restore quickly.
Via SSH (recommended for speed):
Connect to your server and navigate to your WordPress root:
cd /home/username/public_html
Set all directories to 755:
find . -type d -exec chmod 755 {} \;
Set all files to 644:
find . -type f -exec chmod 644 {} \;
Secure wp-config.php:
chmod 440 wp-config.php
These commands recursively process your entire WordPress installation. The find command locates all directories (-type d) or files (-type f), and chmod changes their permissions.
Via cPanel File Manager:
- Log into cPanel and open File Manager
- Navigate to public_html (or wherever WordPress lives)
- Select all files and folders
- Click "Permissions" at the top
- For folders: Check read, write, and execute for owner; read and execute for group and public (755)
- For files: Check read and write for owner; read only for group and public (644)
- Check "Recurse into subdirectories"
- Click "Change Permissions"
Then manually adjust wp-config.php to 440 or 400.
Via FTP:
This method is slower but works if SSH and cPanel aren't available:
- Connect with your FTP client (FileZilla, Cyberduck, etc.)
- Navigate to your WordPress directory
- Select all folders, right-click, choose "File Permissions"
- Enter 755 and apply recursively
- Select all files, right-click, choose "File Permissions"
- Enter 644 and apply recursively
- Find wp-config.php specifically and set it to 440
Fixing Ownership Issues
If WordPress throws permission errors after setting permissions correctly, ownership is likely wrong.
Check who should own files:
On shared hosting, your cPanel username should own everything. On a VPS, the web server user (usually www-data or apache) should own files.
To check the web server user:
ps aux | grep -E 'apache|nginx|httpd'
Look at the first column of the output to identify the user.
Fix ownership recursively:
Replace username with your actual username or the web server user:
sudo chown -R username:username /home/username/public_html
On Ubuntu/Debian with Apache:
sudo chown -R www-data:www-data /var/www/html
The -R flag applies ownership changes recursively to all files and subdirectories.
Shared hosting note:
You typically can't run chown on shared hosting because you don't have sudo access. If ownership is wrong, contact your host's support team. They can reset ownership from their end.
Common Permission Problems and Fixes
"Unable to create directory" when uploading media:
Cause: The uploads directory isn't writable.
Fix:
chmod 755 wp-content/uploads
find wp-content/uploads -type d -exec chmod 755 {} \;
find wp-content/uploads -type f -exec chmod 644 {} \;
"Cannot modify header information" or "wp-config.php" errors:
Cause: Permissions on wp-config.php are too restrictive or the file has incorrect line endings.
Fix:
chmod 440 wp-config.php
If that doesn't work, try 640 temporarily to see if the issue resolves.
"Failed to write file to disk" during plugin installation:
Cause: WordPress can't write to wp-content.
Fix:
chmod 755 wp-content
chmod 755 wp-content/plugins
chmod 755 wp-content/themes
"The update cannot be installed" when updating WordPress core:
Cause: Core files aren't writable by the web server, or ownership is incorrect.
Fix:
find /path/to/wordpress -type d -exec chmod 755 {} \;
find /path/to/wordpress -type f -exec chmod 644 {} \;
If the issue persists, check ownership.
Special Considerations for Automatic Updates
WordPress can automatically update itself, plugins, and themes if configured. This requires write permissions on:
- All WordPress core files
- wp-content/plugins
- wp-content/themes
- wp-content/uploads
If automatic updates fail:
WordPress may ask for FTP credentials. This happens when the web server user doesn't own the files. You have three options:
- Fix ownership so the web server owns files (best for VPS)
- Add FTP credentials to wp-config.php so WordPress can connect as a user with write access
- Disable automatic updates and update manually via SSH or FTP
To add FTP credentials, insert these lines in wp-config.php before "That's all, stop editing":
define('FS_METHOD', 'ftpext');
define('FTP_HOST', 'localhost');
define('FTP_USER', 'your-ftp-username');
define('FTP_PASS', 'your-ftp-password');
This approach is less secure because credentials are stored in plain text. Fixing ownership is preferable.
Maintaining Permissions Long-Term
After plugin or theme installation:
New files may have incorrect permissions. Run your permission-fixing commands after major updates:
find /path/to/wordpress -type d -exec chmod 755 {} \;
find /path/to/wordpress -type f -exec chmod 644 {} \;
chmod 440 wp-config.php
Set up a cron job (advanced):
You can automate permission checks with a cron job, but be cautious. If you accidentally reset permissions on system files outside WordPress, you can break your server.
Create a script:
#!/bin/bash
find /home/username/public_html -type d -exec chmod 755 {} \;
find /home/username/public_html -type f -exec chmod 644 {} \;
chmod 440 /home/username/public_html/wp-config.php
Save it as fix-wp-permissions.sh, make it executable, and add it to cron to run weekly. Only do this if you're comfortable with cron and shell scripting.
Monitor for permission changes:
If permissions reset unexpectedly, something on your server is changing them. Common causes:
- Poorly written plugins
- Compromised administrator accounts
- Server misconfigurations
- Automated security scripts from your host
Check your WordPress activity logs and server logs to identify the cause.
Conclusion
WordPress file permissions balance functionality with security. Directories should be 755, files should be 644, and wp-config.php should be 440 or 400. Correct ownership ensures the web server can read and write where needed without exposing your site to unnecessary risk.
Check permissions whenever you encounter upload errors, update failures, or installation issues. Use SSH for speed or cPanel and FTP when terminal access isn't available. Avoid 777 permissions in all cases. With proper permissions and ownership, your WordPress site runs smoothly and stays secure against common threats.
