The find command searches a directory tree and matches files against criteria you specify: name, size, age, type, permissions. The basic shape is find /path/to/search -criteria value. Run it over SSH from your hosting account, or in a VPS terminal if you have root access.
If you just want to see what's taking up space rather than hunt for a specific file, cPanel's Disk Usage tool gives you a visual breakdown without touching the command line. See finding what's eating your disk space and inodes for that approach. Reach for find when you know roughly what you're looking for and want it by name pattern, size threshold, or last-modified date.
Find by name
The -name flag matches a filename pattern, case-sensitive. Use -iname for case-insensitive matching:
find /home/username/public_html -name "*.log" find /home/username/public_html -iname "readme*"
Quote the pattern so your shell doesn't expand the wildcard before find sees it. To search only inside a specific folder, like your WordPress uploads directory:
find /home/username/public_html/wp-content/uploads -name "*.php"
PHP files inside an uploads folder are almost always a sign of a compromised install, worth investigating right away.
Find by size
The -size flag takes a number and a unit suffix: c for bytes, k for kilobytes, M for megabytes, G for gigabytes. Prefix with + for "larger than" or - for "smaller than":
find /home/username/public_html -type f -size +50M
This finds every file over 50 MB under public_html. It's the fastest way to spot the one bloated video upload or forgotten database dump that's eating your quota. Combine it with -name to narrow further, for example hunting specifically for large backup archives:
find /home/username -type f -size +100M -name "*.tar.gz"
If you turn up old manual backups this way, you generally don't need to keep them on the server. Daily backups are already handled for you, see your backup options for how restores work without you managing your own copies.
Find by age
-mtime filters by days since last modification, and again + means older than, - means newer than:
find /home/username/public_html -type f -mtime +90
That lists files untouched in over 90 days. For finer control, -mmin does the same thing in minutes, useful when you're chasing something that changed in the last hour, like figuring out which file a compromised script just wrote:
find /home/username/public_html -type f -mmin -60
Age-based searches are handy for finding stale cache files, old log rotations, or leftover temp files that never got cleaned up.
Combine criteria and act on results
You can stack flags in one command. Large, old files in one pass:
find /home/username/public_html -type f -size +20M -mtime +180
The -type flag restricts matches to f (regular files) or d (directories), which matters once you start piping results into another command. To delete matches directly, add -delete, but run the search without it first and read the output carefully. There's no undo:
find /home/username/public_html -name "*.tmp" -mtime +30 -delete
To run a command against each match instead of deleting, use -exec:
find /home/username/public_html -name "*.log" -size +10M -exec ls -lh {} \;
The {} is a placeholder for each matched file, and the command ends with \;. This pattern works for anything, compressing old logs, changing permissions on a specific set of files, or moving matches into an archive folder before you clear them out.
Shared hosting vs VPS: permissions matter
On shared hosting, your SSH session runs as your cPanel user, so find only sees files you own inside your home directory. That's normally all you need. Connection details for SSH are the same account credentials used for FTP and SFTP accounts, just over port 22 with an SSH client instead of a file transfer client.
On a VPS, you're root, so find can search the entire filesystem, including other users' files and system directories if you have multiple accounts. That extra reach also means mistakes have more blast radius: a stray -delete at / instead of a scoped path affects the whole server, not just your account. See the VPS overview for what you're responsible for managing at the OS level versus what we handle.
When to contact support
If a find search turns up something that looks like malware, a compromised file, or unexpected content you didn't put there, stop and open a support ticket through the portal rather than deleting it yourself. Our team can confirm what happened and help you restore clean files from backup if needed. Support runs on tickets and live chat with real people, no phone queue.