Use 644 for files and 755 for directories. That's the standard default on almost every Linux web server. If a plugin or script asks you to "chmod" something and gives you a different number, that's usually a sign it wants looser permissions than it needs, and you should be cautious before applying it.
Permissions control who can read, write, and execute a file. Get them wrong in one direction and your site breaks (PHP can't write to a folder it needs); get them wrong in the other and you've opened a door you didn't mean to.
How the permission number works
A Linux permission is three digits, one each for owner, group, and everyone else. Each digit is a sum of:
- 4 = read
- 2 = write
- 1 = execute
644 breaks down as owner = 6 (read+write), group = 4 (read only), other = 4 (read only). Nobody but the owner can modify the file, but the web server can still read it and serve it.
755 breaks down as owner = 7 (read+write+execute), group = 5 (read+execute), other = 5 (read+execute). The execute bit on a directory is what lets you "enter" it (cd into it, or have a script traverse it) and list its contents. Execute on a regular file means "this can run as a program," which is why you don't want it set on a plain PHP or HTML file.
Why 777 is almost always wrong
777 gives everyone, including other users on a shared box and anyone who compromises a script, full read/write/execute. A plugin install guide that tells you to chmod something to 777 to "fix" an upload error is treating a symptom. The actual fix is almost always to correct file ownership, not to throw permissions wide open. If a WordPress upload folder needs to be writable by PHP, 755 (or 775 in some setups) is normally enough.
Changing permissions from File Manager
In the portal, open File Manager from your hosting's service page. File Manager has a Permissions action for files and folders where you set a numeric value like 644 or 755. This can be useful when an entire directory tree ended up with the wrong permissions after a zip extraction or a bad migration.
Changing permissions over SSH
If you have VPS root access or SSH access on shared hosting, the command is chmod:
chmod 644 wp-config.php chmod 755 wp-content/uploads
To apply a permission recursively to every file and folder under a path:
chmod -R 755 wp-content/uploads
Be careful with -R on a mixed tree of files and directories: it applies the same number to both, which means files inside end up with the execute bit set too. If you need files and directories to end up with different permissions in one pass, use find instead:
find /home/youruser/public_html -type d -exec chmod 755 {} \;
find /home/youruser/public_html -type f -exec chmod 644 {} \;
The first line sets every directory to 755, the second sets every file to 644, and neither one touches the other's type.
Shared hosting vs VPS: where root matters
On typical shared and WordPress hosting, your account is isolated to your own user, so chmod only ever affects your own files. Whatever permissions you set are the final word for your site.
On a VPS, you have root, which on Linux generally means you can chmod (and chown) files across the box, including system files. That's real power and real risk: a recursive chmod run from the wrong directory, or run as root against / instead of your app's directory, can take down services that depend on strict permission bits (SSH itself refuses to work if its key files are too open, for example). Always double-check your working directory and path before running a recursive chmod as root.
When permission errors point to something else
If you've confirmed a file is 644 (or 755 for a directory) and you're still getting a 403 Forbidden, the cause is more likely a .htaccess rule or a missing index file than ownership.
When to contact support
If you're on shared hosting and you're not sure which permission a specific file needs, or a recursive change made things worse instead of better, open a ticket from the portal under Support. It's a real person, not a bot, and they can look at your account directly rather than guessing from a general rule.