Security

WordPress File Permissions Explained: 644, 755 and Keeping Files Safe

What file permissions mean on a WordPress server, commonly recommended settings for files, folders and wp-config.php, why 777 is dangerous, and how to check and fix permissions safely.

WordPress File Permissions Explained: 644, 755 and Keeping Files Safe
On this page
  1. What the numbers mean
  2. Commonly recommended settings
  3. Never use 777
  4. Ownership matters too
  5. How to check and change permissions
  6. Other hardening steps
  7. After a hack, check permissions
Key takeaways
  • Typical settings are 755 for folders, 644 for files and stricter for wp-config.php.
  • Never use 777; fix file ownership instead.
  • Reset permissions after a hack and block PHP execution in uploads.

File permissions control who can read, write and run files on your server. Wrong permissions can let attackers modify your files, or can break updates and uploads. Getting them right is a simple but important part of WordPress security.

What the numbers mean

Permissions are shown as three digits, for the file's owner, its group and everyone else:

DigitMeaning
7Read, write and execute
6Read and write
5Read and execute
4Read only
0No access

So 644 means the owner can read and write, while everyone else can only read.

ItemTypical permission
Folders755
Files644
wp-config.phpStricter, such as 640, 600 or 440, depending on your server
.htaccess644

The right values depend on how your server runs PHP and who owns the files, so check your host's recommendations.

Never use 777

777 lets anyone on the server write to the file or folder. It's sometimes suggested as a quick fix for upload errors, but it's a serious security risk. Fix ownership or use the correct permission instead.

Ownership matters too

Files should be owned by your hosting account's user. Wrong ownership, often after a migration or manual upload, can cause update failures that tempt people into using unsafe permissions.

How to check and change permissions

  • Hosting file manager: most show a permissions column and let you change it
  • SFTP client: right-click a file and choose permissions
  • Command line: for developers with SSH access

Some hosts have a tool to reset permissions across the whole site.

Other hardening steps

  • Block PHP execution in the uploads folder
  • Disable file editing in the WordPress dashboard
  • Protect wp-config.php; see hardening wp-config.php

After a hack, check permissions

Attackers sometimes change permissions to make their files harder to remove, or to keep write access. Resetting permissions is part of a proper malware clean-up.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now