Most "403 Forbidden" and a fair share of "500 Internal Server Error" pages on shared hosting come down to permissions. The numbers look cryptic, but there are only two you need for almost everything, and a short rule for when to use each.
What the three digits mean
Each file and folder has three sets of rights: one for the owner (your hosting account), one for the group, and one for everyone else. Each digit is a sum:
- 4 = read
- 2 = write
- 1 = execute (for a folder, this means "may enter it")
So 644 is read + write for the owner (4+2), and read only for the group and everyone else. 755 is everything for the owner (4+2+1), and read + enter for the others (4+1).
The rule that covers nearly every case
- Files: 644. Pages, images, stylesheets, scripts, PHP files.
- Folders: 755. Every directory inside
public_html. - Files holding passwords: 600. Configuration files such as
wp-config.phpcan be tightened so only your account can read them. On hosting where PHP runs as your own user, which is the normal cPanel setup, the site keeps working.
Leave public_html itself alone. cPanel sets it to 750 with a special group so the web server can get in, and changing it can take the whole site offline.
Why 777 is never the fix
When an upload fails or a plugin cannot write a file, old tutorials say to set the folder to 777, which gives everyone on the server the right to write there. On modern cPanel hosting PHP already runs as your account, so it has the owner's rights and 755 is enough. Opening the folder further gains nothing and creates two problems. Any other compromised account on the same server may be able to drop files into it. And many servers refuse to run a script that is writable by the group or by everyone, answering with a 500 error instead. If a guide tells you to use 777, the real problem is somewhere else, usually file ownership or a full disk.
Reading the symptoms
- 403 on one file: that file is missing the read right for "everyone". Set it to 644.
- 403 on everything in a folder: the folder is missing the enter right. Set it to 755.
- 500 on a PHP page straight after changing permissions: the file or its folder is writable by group or world. Put them back to 644 and 755.
- "Could not write file" in an app: check the disk quota in cPanel's sidebar first, then check that the files are owned by your account, which matters if someone uploaded them as another user.
Changing permissions in File Manager
- Open File Manager and select the file or folder.
- Right-click and choose Change Permissions.
- Tick the boxes or type the number, then save.
Resetting a whole site at once
After a messy migration it is quicker to reset everything. In cPanel's Terminal, or over SSH, these two commands set every folder to 755 and every file to 644 under public_html:
find ~/public_html -type d -exec chmod 755 {} \;
find ~/public_html -type f -exec chmod 644 {} \;
Afterwards, tighten any configuration files back to 600. If the site uses scripts that must be run from the command line, give those the execute right again with chmod 755 on the individual file.
One habit that prevents most of this
Upload through cPanel's File Manager or an SFTP login for your own account, not as root and not through a shared team login for a different user. Files created by your own account get sensible permissions and the right owner from the start.
Common questions
What about 640 or 600 on ordinary files?
Those remove the read right for "everyone", and on most cPanel servers the web server reads static files as that outside user. The result is a 403 for anything set that way. That is a problem for a page or an image and exactly what you want for a note or a backup you do not want downloadable. PHP files are different: PHP runs as your account, so a PHP file set to 600 still runs.
Do uploads from a plugin get the right permissions?
Normally yes. Files created by PHP on a cPanel server are owned by your account and come out as 644, folders as 755. If a plugin creates files as 666 or folders as 777, it has an old setting that assumes a different kind of hosting; look in its options for a permissions or "chmod" value.
Is execute ever needed on a file?
Not for web pages or PHP scripts served through the site; the server reads them and never executes the file directly. It is needed for scripts you launch yourself from the command line or from cron by their own path, such as a shell script. Give those 755, or 700 if only you run them.