WordPress

WordPress File Permissions Fix

Correct WordPress file and folder permissions that are either too loose (a security risk) or too tight (breaking uploads/updates).

The Problem

Permission errors show up as "unable to write to directory" or plugin update failures, or in the other direction, permissions are wide open and acting as an easy way in for attackers.

About this problem

WordPress needs to write to specific folders, such as wp-content/uploads, and read everywhere else. When files are uploaded by a different user, restored from a backup or moved between hosts, ownership and permission bits often end up mismatched, so WordPress cannot write where it should. Fixing this by setting everything to 777 makes errors disappear but leaves the site open to tampering.

People usually look for this after messages such as unable to create directory, failed updates asking for FTP credentials, or after a security scan flags writable files. It is also common right after a migration or restore.

What's Included

What's NOT Included

How It Works

  1. I list the current ownership and permissions of the WordPress core, wp-content, uploads and wp-config.php.
  2. I compare these with the recommended values, normally 755 for directories and 644 for files, with stricter settings for wp-config.php.
  3. I correct ownership so that the web server user and the file owner match what the hosting setup expects.
  4. I fix the permissions in bulk with targeted commands, avoiding recursive blanket changes that would make files writable unnecessarily.
  5. I test an upload, a plugin install and a core update to confirm that writing works where it should.
  6. I check that no sensitive files or folders have been left world-writable.

In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.

Frequently Asked Questions

What are the correct file permissions for WordPress?
Commonly 755 for folders and 644 for files, with wp-config.php more restricted. The correct ownership matters as much as the numbers.
Why does WordPress ask for FTP credentials to update?
Usually because the web server user cannot write to the files due to an ownership mismatch. Fixing ownership normally removes the prompt.
Is setting everything to 777 okay?
No, it works but leaves files writable by anyone on the server and is a real security risk.
Can you fix permissions on shared hosting?
Only where the host lets you control them. If the host restricts permission changes, this service cannot override that.
Does this remove malware?
No. If the site is already compromised, you need the malware scan and removal service.
Do you monitor permissions afterwards?
No, ongoing monitoring is not included. This is a one-time correction.
Please note: the price shown applies to a standard case matching the description above. Every situation is different, and if your request falls outside the normal scope of this service, I will explain this before doing any additional chargeable work. I will never silently turn a small job into an expensive project.
Running into an issue with a service you've already bought, or unsure which one fits your problem? Message me directly on WhatsApp — no ticket system, no bot.