WordPress File Permissions Explained: 644, 755 and Keeping Files Safe
What file permissions mean on a WordPress server, commonly recommended settings for files, folders and wp-config.php, why 777 is dangerous, and how to check and fix permissions safely.

On this page
- Typical settings are 755 for folders, 644 for files and stricter for wp-config.php.
- Never use 777; fix file ownership instead.
- Reset permissions after a hack and block PHP execution in uploads.
File permissions control who can read, write and run files on your server. Wrong permissions can let attackers modify your files, or can break updates and uploads. Getting them right is a simple but important part of WordPress security.
What the numbers mean
Permissions are shown as three digits, for the file's owner, its group and everyone else:
| Digit | Meaning |
|---|---|
| 7 | Read, write and execute |
| 6 | Read and write |
| 5 | Read and execute |
| 4 | Read only |
| 0 | No access |
So 644 means the owner can read and write, while everyone else can only read.
Commonly recommended settings
| Item | Typical permission |
|---|---|
| Folders | 755 |
| Files | 644 |
| wp-config.php | Stricter, such as 640, 600 or 440, depending on your server |
| .htaccess | 644 |
The right values depend on how your server runs PHP and who owns the files, so check your host's recommendations.
Never use 777
777 lets anyone on the server write to the file or folder. It's sometimes suggested as a quick fix for upload errors, but it's a serious security risk. Fix ownership or use the correct permission instead.
Ownership matters too
Files should be owned by your hosting account's user. Wrong ownership, often after a migration or manual upload, can cause update failures that tempt people into using unsafe permissions.
How to check and change permissions
- Hosting file manager: most show a permissions column and let you change it
- SFTP client: right-click a file and choose permissions
- Command line: for developers with SSH access
Some hosts have a tool to reset permissions across the whole site.
Other hardening steps
- Block PHP execution in the uploads folder
- Disable file editing in the WordPress dashboard
- Protect wp-config.php; see hardening wp-config.php
After a hack, check permissions
Attackers sometimes change permissions to make their files harder to remove, or to keep write access. Resetting permissions is part of a proper malware clean-up.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


