File permissions explained: what 755, 644 and 777 mean

The short answer: on an ordinary hosting account, folders should be 755 and files 644. Files holding secrets, such as wp-config.php, can be tighter still (600). And never 777: it means “anyone may write here”, and whoever tells you to set 777 to “fix” an error is treating the symptom and opening the door.

How to read the number

It is three digits, one for each group: the owner (your account), the group, and everyone else. Each digit adds up what that group may do: 4 = read, 2 = write, 1 = execute (for a folder, to enter it). So 7 = 4+2+1 (everything), 5 = 4+1 (read and execute), 6 = 4+2 (read and write), 4 = read only.

Number Owner / group / others When it is used
755 everything / read and enter / read and enter Folders. Only the owner changes them; the server can still enter to serve the site.
644 read and write / read / read Ordinary site files: pages, images, stylesheets.
600 read and write / nothing / nothing Files with secrets, such as wp-config.php, which holds the database password.
777 everything / everything / everything Never. Any program running on the server can change the content.

How to see and change permissions

1 In cPanel, open File Manager, right-click the file or folder and choose “Change Permissions”. You get the number and the read, write and execute boxes.
2 In FileZilla, right-click the file and choose “File permissions”. You can apply it to folders only or to files only: use this to set folders to 755 and files to 644 separately. See FileZilla day to day.
3 If your account has SSH access, you can set everything at once from the site folder. Folders first, find public_html -type d -exec chmod 755 {} +, then files, find public_html -type f -exec chmod 644 {} +. Check the folder name before you run it: the command is yours.
4 Test the site after the change. If a page starts to fail, note what you changed and undo it on that file.
The symptom of wrong permissions is misleading. A 403 “Forbidden” or a 500 error after an FTP upload is often a folder or file with unsuitable permissions (too tight or too open). On many servers a 777 folder even causes a 500 error, because the server refuses to run programs from somewhere anyone can write. See error 403: permissions, .htaccess and blocked IPs.
WordPress plugins that ask for 777 on the uploads folder are badly written or badly installed. The folder works at 755 if it belongs to your account. If it does not, the file owner may be wrong, which is worth a support ticket, not a 777.

A 403 or 500 error that only appears after you touched permissions? Tell us the address and what you changed.

Open a support ticket

SEE ALSO

Error 403 Forbidden: permissions, .htaccess and blocked IPs

Protecting the WordPress login: three steps in order of effect

Day to day in FileZilla: syncing, permissions and hidden files

Linux file permissions on a VPS

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from R118.80/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?