File permissions control who can read, write, or execute your files. Permissions that are too open let attackers modify your site, while permissions that are too strict can break it. The standard values below are safe for most cPanel sites.
Recommended Permissions
| Item | Permission | | --- | --- | | Folders | 755 | | Files | 644 | | wp-config.php | 600 or 640 | | .htaccess | 644 |
Never set files or folders to 777, as it allows anyone to write to them.
Change Permissions in cPanel
- Log in to cPanel and open File Manager.
- Navigate to the file or folder.
- Right-click it and choose Change Permissions.
- Tick the read, write, and execute boxes to match the values above.
- Click Change Permissions to save.
Apply Permissions in Bulk
For many files at once, use the Terminal in cPanel if it is enabled:
find . -type d -exec chmod 755 {} \;
find . -type f -exec chmod 644 {} \;
Run these from inside your public_html directory. The first line fixes folders, the second fixes files.
Protect Sensitive Files
- Lower
wp-config.phpto 600 so only the owner can read it. - Keep configuration files outside the public root where possible.
- Verify upload folders are not set to 777.
After changing permissions, load your site to confirm nothing broke. If a script needs to write to a folder, such as a cache or uploads directory, 755 is usually enough on shared hosting. Avoid loosening permissions unless an application clearly requires it.