Skip to content
Back to Blog
WordPress10 min read

WordPress File Permissions for Beginners: A Practical Guide

Learn how to set secure WordPress file permissions from scratch. This beginner-friendly guide explains ownership, permission numbers, and the exact commands to protect your site.

Written by Abdul AbrorTechnical Hosting Support Engineer
WordPress File Permissions for Beginners: A Practical Guide
On this page

File permissions control who can read, write, or execute files on your server. Get them wrong and you'll face security vulnerabilities or broken functionality. Get them right and your WordPress site runs smoothly with minimal risk. This guide walks you through everything from what permissions actually are to the exact commands you need.

What Are File Permissions?

Every file and folder on a Linux server has three permission types assigned to three categories of users.

The three permission types:

  • Read (r): View the file's contents or list a directory's contents
  • Write (w): Modify, delete, or add to the file or directory
  • Execute (x): Run the file as a program, or access a directory to change into it

The three user categories:

  • Owner: The user account that owns the file (usually your cPanel username or www-data)
  • Group: A group of users that share access (often the web server group)
  • Others: Everyone else on the system

When you see a permission like 644 or 755, those numbers represent the combination of read, write, and execute permissions for owner, group, and others.

Understanding Permission Numbers

Linux uses octal notation where each digit represents permissions for one category.

Each permission has a numeric value:

  • Read = 4
  • Write = 2
  • Execute = 1

You add these values together:

  • 7 = read + write + execute (4+2+1)
  • 6 = read + write (4+2)
  • 5 = read + execute (4+1)
  • 4 = read only
  • 0 = no permissions

Example: 644

  • First digit (6): Owner can read and write
  • Second digit (4): Group can read only
  • Third digit (4): Others can read only

Example: 755

  • First digit (7): Owner can read, write, and execute
  • Second digit (5): Group can read and execute
  • Third digit (5): Others can read and execute

Directories need execute permission so users can access them. Files rarely need execute permission unless they're scripts.

WordPress Standard Permissions

WordPress follows a security principle: give the minimum permissions needed for the site to function.

Standard file permissions: 644

  • Owner can edit files
  • Web server can read files to serve pages
  • Nobody else can modify anything

Standard directory permissions: 755

  • Owner can create, delete, and navigate folders
  • Web server can read and navigate folders
  • Others can read and navigate but not modify

Exception: wp-config.php should be 440 or 400

This file contains your database credentials. Restrict it so only the owner and web server (or only the owner) can read it. The web server doesn't need write access.

Why Permissions Matter for Security

Too permissive (777 or 666):

If you set everything to 777, any user on the server can modify your files. This includes:

  • Attackers who compromise another site on shared hosting
  • Malicious scripts that exploit vulnerabilities
  • Accidents from other applications

Setting files to 777 is never necessary for WordPress and creates unnecessary risk.

Too restrictive (400 or 444):

If files are read-only for everyone including the owner, WordPress can't update itself, install plugins, or upload media. You'll see permission errors when trying to save posts or update themes.

The balance:

WordPress needs to read files to display your site and write to specific directories like wp-content/uploads for media uploads. Standard permissions achieve this without exposing your site to unnecessary risk.

Understanding File Ownership

Permissions work alongside ownership. Even if permissions are correct, the wrong owner causes problems.

Two ownership attributes:

  • User owner: Usually your cPanel username or the web server user (www-data, apache, nginx)
  • Group owner: Often matches the user owner or is set to the web server group

Typical ownership patterns:

Shared hosting (cPanel):

  • User: your cPanel username
  • Group: your cPanel username
  • Web server runs as your user through suPHP or PHP-FPM

VPS or dedicated server:

  • User: www-data or apache
  • Group: www-data or apache
  • Web server runs as its own user

To see ownership, use:

ls -la /path/to/wordpress/

You'll see output like:

drwxr-xr-x 5 username username 4096 Jul 08 10:30 wp-content
-rw-r--r-- 1 username username 3164 Jul 08 10:30 wp-config.php

The third and fourth columns show the user owner and group owner.

How to Check Current Permissions

Via SSH:

Connect to your server and navigate to your WordPress directory:

cd /home/username/public_html
ls -la

Look at the first column. It shows permissions in letter format:

  • drwxr-xr-x = directory with 755 permissions
  • -rw-r--r-- = file with 644 permissions
  • -rw-r----- = file with 640 permissions

To see numeric permissions:

stat -c '%a %n' wp-config.php

Output: 644 wp-config.php

Via FTP:

Most FTP clients show permissions in the file properties. Right-click a file or folder and select "File Permissions" or "Properties." You'll see checkboxes for read, write, and execute or a numeric field.

Via cPanel File Manager:

  1. Log into cPanel
  2. Open File Manager
  3. Navigate to public_html
  4. Right-click any file or folder
  5. Select "Permissions"
  6. The dialog shows both checkboxes and the numeric value

Setting WordPress Permissions Correctly

Before you start:

Back up your site. If something goes wrong, you can restore quickly.

Via SSH (recommended for speed):

Connect to your server and navigate to your WordPress root:

cd /home/username/public_html

Set all directories to 755:

find . -type d -exec chmod 755 {} \;

Set all files to 644:

find . -type f -exec chmod 644 {} \;

Secure wp-config.php:

chmod 440 wp-config.php

These commands recursively process your entire WordPress installation. The find command locates all directories (-type d) or files (-type f), and chmod changes their permissions.

Via cPanel File Manager:

  1. Log into cPanel and open File Manager
  2. Navigate to public_html (or wherever WordPress lives)
  3. Select all files and folders
  4. Click "Permissions" at the top
  5. For folders: Check read, write, and execute for owner; read and execute for group and public (755)
  6. For files: Check read and write for owner; read only for group and public (644)
  7. Check "Recurse into subdirectories"
  8. Click "Change Permissions"

Then manually adjust wp-config.php to 440 or 400.

Via FTP:

This method is slower but works if SSH and cPanel aren't available:

  1. Connect with your FTP client (FileZilla, Cyberduck, etc.)
  2. Navigate to your WordPress directory
  3. Select all folders, right-click, choose "File Permissions"
  4. Enter 755 and apply recursively
  5. Select all files, right-click, choose "File Permissions"
  6. Enter 644 and apply recursively
  7. Find wp-config.php specifically and set it to 440

Fixing Ownership Issues

If WordPress throws permission errors after setting permissions correctly, ownership is likely wrong.

Check who should own files:

On shared hosting, your cPanel username should own everything. On a VPS, the web server user (usually www-data or apache) should own files.

To check the web server user:

ps aux | grep -E 'apache|nginx|httpd'

Look at the first column of the output to identify the user.

Fix ownership recursively:

Replace username with your actual username or the web server user:

sudo chown -R username:username /home/username/public_html

On Ubuntu/Debian with Apache:

sudo chown -R www-data:www-data /var/www/html

The -R flag applies ownership changes recursively to all files and subdirectories.

Shared hosting note:

You typically can't run chown on shared hosting because you don't have sudo access. If ownership is wrong, contact your host's support team. They can reset ownership from their end.

Common Permission Problems and Fixes

"Unable to create directory" when uploading media:

Cause: The uploads directory isn't writable.

Fix:

chmod 755 wp-content/uploads
find wp-content/uploads -type d -exec chmod 755 {} \;
find wp-content/uploads -type f -exec chmod 644 {} \;

"Cannot modify header information" or "wp-config.php" errors:

Cause: Permissions on wp-config.php are too restrictive or the file has incorrect line endings.

Fix:

chmod 440 wp-config.php

If that doesn't work, try 640 temporarily to see if the issue resolves.

"Failed to write file to disk" during plugin installation:

Cause: WordPress can't write to wp-content.

Fix:

chmod 755 wp-content
chmod 755 wp-content/plugins
chmod 755 wp-content/themes

"The update cannot be installed" when updating WordPress core:

Cause: Core files aren't writable by the web server, or ownership is incorrect.

Fix:

find /path/to/wordpress -type d -exec chmod 755 {} \;
find /path/to/wordpress -type f -exec chmod 644 {} \;

If the issue persists, check ownership.

Special Considerations for Automatic Updates

WordPress can automatically update itself, plugins, and themes if configured. This requires write permissions on:

  • All WordPress core files
  • wp-content/plugins
  • wp-content/themes
  • wp-content/uploads

If automatic updates fail:

WordPress may ask for FTP credentials. This happens when the web server user doesn't own the files. You have three options:

  1. Fix ownership so the web server owns files (best for VPS)
  2. Add FTP credentials to wp-config.php so WordPress can connect as a user with write access
  3. Disable automatic updates and update manually via SSH or FTP

To add FTP credentials, insert these lines in wp-config.php before "That's all, stop editing":

define('FS_METHOD', 'ftpext');
define('FTP_HOST', 'localhost');
define('FTP_USER', 'your-ftp-username');
define('FTP_PASS', 'your-ftp-password');

This approach is less secure because credentials are stored in plain text. Fixing ownership is preferable.

Maintaining Permissions Long-Term

After plugin or theme installation:

New files may have incorrect permissions. Run your permission-fixing commands after major updates:

find /path/to/wordpress -type d -exec chmod 755 {} \;
find /path/to/wordpress -type f -exec chmod 644 {} \;
chmod 440 wp-config.php

Set up a cron job (advanced):

You can automate permission checks with a cron job, but be cautious. If you accidentally reset permissions on system files outside WordPress, you can break your server.

Create a script:

#!/bin/bash
find /home/username/public_html -type d -exec chmod 755 {} \;
find /home/username/public_html -type f -exec chmod 644 {} \;
chmod 440 /home/username/public_html/wp-config.php

Save it as fix-wp-permissions.sh, make it executable, and add it to cron to run weekly. Only do this if you're comfortable with cron and shell scripting.

Monitor for permission changes:

If permissions reset unexpectedly, something on your server is changing them. Common causes:

  • Poorly written plugins
  • Compromised administrator accounts
  • Server misconfigurations
  • Automated security scripts from your host

Check your WordPress activity logs and server logs to identify the cause.

Conclusion

WordPress file permissions balance functionality with security. Directories should be 755, files should be 644, and wp-config.php should be 440 or 400. Correct ownership ensures the web server can read and write where needed without exposing your site to unnecessary risk.

Check permissions whenever you encounter upload errors, update failures, or installation issues. Use SSH for speed or cPanel and FTP when terminal access isn't available. Avoid 777 permissions in all cases. With proper permissions and ownership, your WordPress site runs smoothly and stays secure against common threats.