Incorrect file permissions are a common cause of 500 errors, security vulnerabilities, and non-working uploads. For most websites, a simple rule of thumb applies: folders get permission 755 and files 644, while configuration files with sensitive data often require stricter settings. In this article, you’ll learn exactly what permissions mean, which values to use where, and how to adjust them via SSH or Plesk.
What are file permissions
On Linux, every file and folder has three types of rights: read (r), write (w), and execute (x). These rights apply separately to the owner, the group, and other users. The combination is usually displayed as a three-digit number, for example 755 or 644. Each digit is the sum of read (4), write (2), and execute (1) for the owner, group, and others respectively.
For example, 755 means the owner is allowed to do everything (7 = 4+2+1), while the group and others can only read and execute (5 = 4+1). For folders, execute rights are needed to navigate into them; for files, it determines whether a script may be executed.
Correct values per file type
Not every file needs the same permissions. A good basic breakdown:
- Folders: 755 (owner can do everything, others can read and open)
- Regular files such as HTML, CSS, and images: 644
- PHP scripts: usually 644, sometimes 755 if the script itself needs to be executable
- Configuration files with passwords or database details: 600, so only the owner can read and write
- Upload folders that need to be written to by CMS systems: sometimes 775, but preferably not broader than necessary
Avoid 777 on files or folders. That gives everyone on the system write access and is a major security risk, even if it seems like a quick fix for an error message.
Adjusting permissions with chmod and chown
Via SSH, you adjust permissions with the chmod command, and the owner with chown. A few practical examples:
Connect via SSH
Log in to your server with SSH and navigate to your website’s folder, for example with cd httpdocs.
Set folders to 755
Use the command find . -type d -exec chmod 755 {} ; to recursively set all folders to 755.
Set files to 644
Use find . -type f -exec chmod 644 {} ; to set all files to 644.
Check owner and group
Use chown username:group filename to set the correct owner, so your hosting account and the web server don’t conflict with each other.
Use Plesk as an alternative
If you’d rather avoid SSH commands, you can right-click a file or folder in Plesk’s file manager and choose to change permissions. This can be found in the Plesk control panel, which is available by default with web hosting at Tandata.
Common mistakes and security
The most common mistake is applying 777 everywhere because a plugin or upload isn’t working. This temporarily solves the problem but makes the site vulnerable to abuse, as malicious actors can then also overwrite files. Instead, first check whether the file owner is correct.
Another common mistake is accidentally applying file permissions to folders or vice versa via an incorrect find command, causing folders to become inaccessible (missing execute bit) or scripts to no longer run.
Also pay attention when it comes to email configuration and credentials: files with passwords, API keys, or database settings should not be readable by other users on the system. This is just as important as correct DNS and SPF configuration for business email, which Tandata’s email hosting takes into account for a good security score.
If you get stuck or are unsure about the correct settings for your CMS, you can search further in the knowledge base or contact support via WhatsApp, ticket, or email, even at night.
Frequently Asked Questions
What’s the difference between chmod 644 and 755?
644 gives the owner read and write rights and others only read rights, without execute rights. 755 gives the owner full rights and others read and execute rights, which is needed to be able to open folders.
Why doesn’t my upload function work despite correct permissions?
This is often due to the owner of the folder rather than the permission itself. Check with ls -la whether the folder belongs to the correct user account, and adjust this with chown.
Is 777 ever a good solution?
No, 777 gives everyone on the system full rights and is almost never needed. Use 755 or 775 instead and check the file’s owner.
Can I also adjust permissions without SSH?
Yes, you can set permissions per file or folder via the file manager in Plesk without using the command line.
Do I need to adjust permissions after switching to a new hosting provider?
Sometimes, because file ownership can change during migration. When switching to Tandata, this is taken into account during the transfer, but it’s always wise to check this after migration.
Conclusion
Correct file permissions are essential for a secure and stable website. Keep 755 for folders, 644 for files, and stricter values such as 600 for configuration files with sensitive data. Avoid 777 and, if problems arise, first check the file’s owner before adjusting permissions.