File and folder permissions control who can read, change and run the files on your website. Most sites need only two settings: 644 for files and 755 for folders. This guide explains what those numbers mean, how to change permissions in cPanel File Manager, and how to fix permission-related errors like "403 Forbidden".
The short answer: 644 for files, 755 for folders
| Item | Recommended permission | Why |
|---|---|---|
| Files (HTML, PHP, images, CSS, JS) | 644 | You can edit them; everyone else (including visitors via the web server) can only read them. |
| Folders | 755 | You can add and remove files; others can open the folder and read what's inside. |
wp-config.php and other files holding passwords | 600 or 640 (optional) | Tighter permissions for sensitive files. If your site shows an error after changing it, set it back to 644. |
public_html itself | Leave as it is | The server sets this folder's permissions (usually 750). Don't change them. |
On Instant Access Internet Services servers, your website's PHP code runs as your own account, so it can write to your files without needing looser permissions. That means you should never need 777.
What the numbers mean
Each permission has three digits. From left to right they apply to:
- User - you, the owner of the account
- Group - the group the file belongs to
- World - everyone else
Each digit is the sum of the rights it grants:
| Value | Right | For a file | For a folder |
|---|---|---|---|
| 4 | Read | See the file's contents | List what's in the folder |
| 2 | Write | Change the file | Add, rename or delete files inside |
| 1 | Execute | Run it as a program | Open (enter) the folder |
So 7 = 4+2+1 (read, write, execute), 6 = 4+2 (read and write), 5 = 4+1 (read and execute) and 4 = read only. That makes 644 "owner can read and write, everyone else can only read", and 755 "owner can do everything, everyone else can read and open".
Why you should never use 777
777 means anyone on the system can change the file or folder. Old tutorials sometimes suggest it to "fix" upload errors, but it's a security risk and it isn't needed here. On many servers, including ours, the web server may also refuse to run scripts that are writable by everyone, so 777 can actually cause errors. If a plugin or script tells you to use 777, use 755 for folders and 644 for files instead.
How to change permissions in cPanel File Manager
- In cPanel, go to Files > File Manager.
- Browse to the file or folder. The current setting is shown in the Permissions column.
- Click the item once to select it (hold Ctrl or Command to select several of the same type).
- Click Permissions in the toolbar, or right-click and choose Change Permissions.
- Tick the boxes for User, Group and World, or check the number shown underneath matches what you want (for example 0644).
- Click Change Permissions.
File Manager changes only the items you selected - it doesn't apply changes to everything inside a folder. If you have many files to fix, an FTP program like FileZilla can apply permissions recursively: right-click a folder, choose File permissions..., tick Recurse into subdirectories and choose Apply to files only or Apply to directories only. See How to Connect to Your Website with FileZilla (FTPS).
Troubleshooting
"403 Forbidden" on a page or image
Check the file is 644 and every folder above it is 755. A file set to 600 or a folder set to 700 can't be read by the web server. Also check there's an index file in the folder if you're visiting a folder address - see How to Turn Directory Listings On or Off in cPanel (Indexes).
WordPress can't upload images or install plugins
Make sure wp-content and wp-content/uploads are 755. If they already are, the problem is usually disk space or a PHP limit rather than permissions - see Understanding cPanel Statistics: Disk Space, Bandwidth and Databases and How to Change PHP Settings (memory_limit, upload_max_filesize).
"500 Internal Server Error" after changing permissions
Set PHP files back to 644 and folders to 755. Scripts that are writable by group or world can be blocked by the server. Your error log will usually say so - see How to Check Your Website Error Log and Recent Visitors.
WP Toolkit says my file permissions are insecure
WP Toolkit's security check can fix common WordPress permission problems for you - see How to Secure WordPress with WP Toolkit Security Hardening.
Related guides
- How to Use cPanel File Manager to Manage Your Website Files
- How to Secure WordPress with WP Toolkit Security Hardening
- How to Fix the WordPress White Screen and 500 Errors
- How to Check Your Website Error Log and Recent Visitors
- How to Connect to Your Website with FileZilla (FTPS)
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
