The short answer: on an ordinary hosting account, folders should be 755 and files 644. Files holding secrets, such as wp-config.php, can be tighter still (600). And never 777: it means “anyone may write here”, and whoever tells you to set 777 to “fix” an error is treating the symptom and opening the door.
How to read the number
It is three digits, one for each group: the owner (your account), the group, and everyone else. Each digit adds up what that group may do: 4 = read, 2 = write, 1 = execute (for a folder, to enter it). So 7 = 4+2+1 (everything), 5 = 4+1 (read and execute), 6 = 4+2 (read and write), 4 = read only.
| Number |
Owner / group / others |
When it is used |
| 755 |
everything / read and enter / read and enter |
Folders. Only the owner changes them; the server can still enter to serve the site. |
| 644 |
read and write / read / read |
Ordinary site files: pages, images, stylesheets. |
| 600 |
read and write / nothing / nothing |
Files with secrets, such as wp-config.php, which holds the database password. |
| 777 |
everything / everything / everything |
Never. Any program running on the server can change the content. |
How to see and change permissions
| 1 |
In cPanel, open File Manager, right-click the file or folder and choose “Change Permissions”. You get the number and the read, write and execute boxes.
|
|
| 2 |
In FileZilla, right-click the file and choose “File permissions”. You can apply it to folders only or to files only: use this to set folders to 755 and files to 644 separately. See FileZilla day to day.
|
|
| 3 |
If your account has SSH access, you can set everything at once from the site folder. Folders first, find public_html -type d -exec chmod 755 {} +, then files, find public_html -type f -exec chmod 644 {} +. Check the folder name before you run it: the command is yours.
|
|
| 4 |
Test the site after the change. If a page starts to fail, note what you changed and undo it on that file.
|
|
|
The symptom of wrong permissions is misleading. A 403 “Forbidden” or a 500 error after an FTP upload is often a folder or file with unsuitable permissions (too tight or too open). On many servers a 777 folder even causes a 500 error, because the server refuses to run programs from somewhere anyone can write. See error 403: permissions, .htaccess and blocked IPs.
|
WordPress plugins that ask for 777 on the uploads folder are badly written or badly installed. The folder works at 755 if it belongs to your account. If it does not, the file owner may be wrong, which is worth a support ticket, not a 777.
|
|
A 403 or 500 error that only appears after you touched permissions? Tell us the address and what you changed.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from £5.28/mo (3-year plan, with coupon) See plans |