{"id":336614,"date":"2026-07-15T15:13:48","date_gmt":"2026-07-15T15:13:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sitecare-file-permissions\/"},"modified":"2026-07-21T00:18:06","modified_gmt":"2026-07-21T00:18:06","slug":"sitecare-file-permissions","status":"publish","type":"plugin","link":"https:\/\/mri.wordpress.org\/plugins\/sitecare-file-permissions\/","author":11631598,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.3.12","stable_tag":"2.3.12","tested":"7.0.2","requires":"6.1","requires_php":"7.2","requires_plugins":null,"header_name":"SiteCare \u2013 File Permissions Manager","header_author":"SiteCare","header_description":"Safely and recursively fix file & folder permissions (chmod) across your whole WordPress site, with sensible presets and a live file tree.","assets_banners_color":"1b3360","last_updated":"2026-07-21 00:18:06","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/buymeacoffee.com\/mchncd","header_plugin_uri":"","header_author_uri":"https:\/\/sitecare.cz","rating":0,"author_block_rating":0,"active_installs":0,"downloads":213,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.1.0":{"tag":"2.1.0","author":"fstab","date":"2026-07-15 15:31:56"},"2.2.0":{"tag":"2.2.0","author":"fstab","date":"2026-07-15 15:48:01"},"2.3.0":{"tag":"2.3.0","author":"fstab","date":"2026-07-20 02:02:35"},"2.3.1":{"tag":"2.3.1","author":"fstab","date":"2026-07-20 03:18:52"},"2.3.10":{"tag":"2.3.10","author":"fstab","date":"2026-07-21 00:02:43"},"2.3.11":{"tag":"2.3.11","author":"fstab","date":"2026-07-21 00:13:16"},"2.3.12":{"tag":"2.3.12","author":"fstab","date":"2026-07-21 00:18:06"},"2.3.2":{"tag":"2.3.2","author":"fstab","date":"2026-07-20 14:23:49"},"2.3.3":{"tag":"2.3.3","author":"fstab","date":"2026-07-20 14:34:03"},"2.3.4":{"tag":"2.3.4","author":"fstab","date":"2026-07-20 14:55:50"},"2.3.5":{"tag":"2.3.5","author":"fstab","date":"2026-07-20 15:15:49"},"2.3.6":{"tag":"2.3.6","author":"fstab","date":"2026-07-20 18:18:02"},"2.3.7":{"tag":"2.3.7","author":"fstab","date":"2026-07-20 19:02:31"},"2.3.8":{"tag":"2.3.8","author":"fstab","date":"2026-07-20 19:20:58"},"2.3.9":{"tag":"2.3.9","author":"fstab","date":"2026-07-20 23:46:41"}},"upgrade_notice":{"2.3.0":"<p>Now beginner-proof: set permissions with plain checkboxes, see in plain language what they do, and dangerous values like 777 are blocked automatically. Recommended for all users.<\/p>","2.2.0":"<p>New name (SiteCare \u2013 File Permissions Manager). How the plugin works is unchanged.<\/p>","2.1.0":"<p>Adds a confirmation step before changes, native admin colours and keyboard accessibility. Recommended for all users.<\/p>","2.0.0":"<p>Redesigned, safer and translation-ready. Recommended for all users.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3614024,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3614024,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon-512x512.png":{"filename":"icon-512x512.png","revision":3614024,"resolution":"512x512","location":"assets","locale":"","width":512,"height":512},"icon.svg":{"filename":"icon.svg","revision":3614024,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3615296,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3615296,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.1.0","2.2.0","2.3.0","2.3.1","2.3.10","2.3.11","2.3.12","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3617319,"resolution":"1","location":"assets","locale":"","width":2560,"height":2000},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3617319,"resolution":"2","location":"assets","locale":"","width":2560,"height":2000}},"screenshots":{"1":"The main screen: instant risk diagnosis, beginner-friendly permission checkboxes and the live permission tree.","2":"Advanced options for sensitive files with recommended, global or custom modes."}},"plugin_section":[],"plugin_tags":[9746,239739,1329,895,600],"plugin_category":[54],"plugin_contributors":[231549],"plugin_business_model":[],"class_list":["post-336614","plugin","type-plugin","status-publish","hentry","plugin_tags-chmod","plugin_tags-file-permissions","plugin_tags-htaccess","plugin_tags-permissions","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-fstab","plugin_committers-fstab"],"banners":{"banner":"https:\/\/ps.w.org\/sitecare-file-permissions\/assets\/banner-772x250.png?rev=3615296","banner_2x":"https:\/\/ps.w.org\/sitecare-file-permissions\/assets\/banner-1544x500.png?rev=3615296","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/sitecare-file-permissions\/assets\/icon.svg?rev=3614024","icon":"https:\/\/ps.w.org\/sitecare-file-permissions\/assets\/icon.svg?rev=3614024","icon_2x":false,"generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sitecare-file-permissions\/assets\/screenshot-1.png?rev=3617319","caption":"The main screen: instant risk diagnosis, beginner-friendly permission checkboxes and the live permission tree."},{"src":"https:\/\/ps.w.org\/sitecare-file-permissions\/assets\/screenshot-2.png?rev=3617319","caption":"Advanced options for sensitive files with recommended, global or custom modes."}],"raw_content":"<!--section=description-->\n<p>File and directory permissions are one of the easiest things to get wrong on a WordPress site - and one of the most consequential. Set them too loose and you hand attackers an easy way in; set them too tight and updates, uploads, and plugins quietly stop working. The correct values are well known (755 for folders, 644 for files, locked-down config files), but applying them the usual way means FTP or SSH access, recursive <code>chmod<\/code> commands, and a real risk of breaking your site with a single typo.<\/p>\n\n<p>SiteCare File Permissions Manager removes all of that. From one screen under <strong>Tools \u2192 Permissions<\/strong>, it recursively applies the safe, recommended permissions across your entire WordPress install - no FTP, no shell, no command line. The recommended values are pre-filled, so for most people it really is a single button.<\/p>\n\n<p><strong>Features<\/strong><\/p>\n\n<ul>\n<li>One-click recursive chmod for the whole WordPress site.<\/li>\n<li><strong>Instant diagnosis<\/strong> - the screen opens with a clear \"X items are writable by everyone\" warning whenever risky permissions are found, so you know right away whether you have a problem.<\/li>\n<li>Separate, recommended values for directories (755) and files (644).<\/li>\n<li><strong>Beginner-friendly checkboxes<\/strong> for owner \/ group \/ world (read, write, execute) - no need to understand octal numbers. The matching number is filled in for you and stays in sync.<\/li>\n<li><strong>Plain-language explanation<\/strong> of exactly what each setting means (\"You: open &amp; view &amp; change. Everyone: open &amp; view\"), updated live as you change the boxes.<\/li>\n<li><strong>Dangerous values are blocked<\/strong> - world-writable permissions like 777 or 666, unreadable files (000) and non-traversable folders can never be applied, both in the browser and on the server, so you cannot lock yourself out or open your site up by mistake.<\/li>\n<li>Advanced overrides for sensitive files (.htaccess, wp-config.php, .user.ini, php.ini) with three modes: recommended read-only (444), the same value as your files, or a custom value per file.<\/li>\n<li>Live, expandable file tree that shows the current permission of every file and folder, with colour hints for safe vs. risky values.<\/li>\n<li>Real progress bar with batched processing, so it works on large sites without hitting PHP timeouts.<\/li>\n<li>Ships fully translated into five world languages - German, Spanish, French, Portuguese and Russian - plus Czech.<\/li>\n<li>No external scripts, fonts or trackers are loaded.<\/li>\n<\/ul>\n\n<p>A rule for a sensitive file (for example php.ini) is only applied when that file actually exists on the server. Missing files are simply skipped.<\/p>\n\n<!--section=installation-->\n<h4>From your WordPress dashboard (recommended)<\/h4>\n\n<ol>\n<li>Go to <strong>Plugins \u2192 Add New<\/strong> and search for \"SiteCare File Permissions Manager\".<\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<\/ol>\n\n<h4>Manual upload<\/h4>\n\n<ol>\n<li>Download the plugin .zip file.<\/li>\n<li>Go to <strong>Plugins \u2192 Add New \u2192 Upload Plugin<\/strong> and choose the .zip.<\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong>.<\/li>\n<\/ol>\n\n<h4>Getting started<\/h4>\n\n<p>Go to <strong>Tools \u2192 Permissions<\/strong> and click <strong>Start changing permissions<\/strong>. The recommended, safe values are already filled in, so you can review the live file tree and apply them in one click.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20permissions%20should%20i%20use%3F\"><h3>What permissions should I use?<\/h3><\/dt>\n<dd><p>The defaults are the widely recommended values: 755 for folders and 644 for files, and read-only 444 for sensitive configuration files. If you are not comfortable with the numbers, just use the checkboxes - the plugin explains in plain language what each choice does and fills in the number for you.<\/p><\/dd>\n<dt id=\"can%20i%20set%20777%3F%20is%20it%20safe%3F\"><h3>Can I set 777? Is it safe?<\/h3><\/dt>\n<dd><p>No, and that is on purpose. World-writable permissions such as 777 or 666 let anyone on the server write to your files and are a common way sites get hacked - there is no legitimate reason to set them site-wide. The plugin blocks them (along with other unsafe values like 000 or non-traversable folders) both in the browser and on the server, so you cannot apply them even by accident.<\/p><\/dd>\n<dt id=\"what%20if%20php.ini%20or%20.user.ini%20do%20not%20exist%20on%20my%20server%3F\"><h3>What if php.ini or .user.ini do not exist on my server?<\/h3><\/dt>\n<dd><p>Nothing happens for them. The plugin only changes files that actually exist, and missing files are skipped safely.<\/p><\/dd>\n<dt id=\"is%20it%20safe%20to%20run%20on%20a%20large%20site%3F\"><h3>Is it safe to run on a large site?<\/h3><\/dt>\n<dd><p>Yes. Processing is done in small batches with a live progress bar, so it does not hit PHP execution time limits.<\/p><\/dd>\n<dt id=\"who%20can%20use%20it%3F\"><h3>Who can use it?<\/h3><\/dt>\n<dd><p>Only administrators (users with the manage_options capability) can open the screen or run any action.<\/p><\/dd>\n<dt id=\"does%20it%20load%20anything%20from%20third-party%20servers%3F\"><h3>Does it load anything from third-party servers?<\/h3><\/dt>\n<dd><p>No. All styles and scripts are bundled with the plugin. Nothing is loaded from external servers.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.3.12<\/h4>\n\n<ul>\n<li>The permissions screen is now ad-free: notices and promos injected by other plugins no longer appear inside it.<\/li>\n<\/ul>\n\n<h4>2.3.11<\/h4>\n\n<ul>\n<li>Czech translation is back on board alongside the five world languages.<\/li>\n<\/ul>\n\n<h4>2.3.10<\/h4>\n\n<ul>\n<li>Unified translations across the SiteCare family: five world languages (German, Spanish, French, Portuguese, Russian).<\/li>\n<li>Refreshed screenshots.<\/li>\n<\/ul>\n\n<h4>2.3.9<\/h4>\n\n<ul>\n<li>New scpc_risk_cache_ttl filter to tune how long the risk diagnosis is cached.<\/li>\n<li>Shortened the directory description to fit WordPress.org limits.<\/li>\n<\/ul>\n\n<h4>2.3.8<\/h4>\n\n<ul>\n<li>New: instant diagnosis - the screen now opens with a clear \"X items are writable by everyone\" warning when risky permissions exist on your site.<\/li>\n<li>Dismissing the support box now sticks across browsers and devices (stored per user on the server).<\/li>\n<li>Housekeeping: refreshed screenshots and link attribution.<\/li>\n<\/ul>\n\n<h4>2.3.7<\/h4>\n\n<ul>\n<li>Preset chips (755, 644 ...) now show a plain-language tooltip explaining what each value does.<\/li>\n<li>More breathing room between the support box and the permissions section.<\/li>\n<\/ul>\n\n<h4>2.3.6<\/h4>\n\n<ul>\n<li>Tidied up the permissions screen: each matrix is now a self-contained card with its own header, the value + presets sit on one row, and both columns line up cleanly.<\/li>\n<\/ul>\n\n<h4>2.3.5<\/h4>\n\n<ul>\n<li>Balanced the two-column layout: the file tree now matches the height of the settings column, removing the empty space.<\/li>\n<\/ul>\n\n<h4>2.3.4<\/h4>\n\n<ul>\n<li>Moved the support box directly under the intro notice; the info icon is now blue and better aligned.<\/li>\n<\/ul>\n\n<h4>2.3.3<\/h4>\n\n<ul>\n<li>Footer links no longer underline on hover; tidied up the \"safe defaults\" notice.<\/li>\n<\/ul>\n\n<h4>2.3.2<\/h4>\n\n<ul>\n<li>Unified the footer across the SiteCare plugin family; the SiteCare link now points to app.sitecare.cz.<\/li>\n<\/ul>\n\n<h4>2.3.1<\/h4>\n\n<ul>\n<li>Added a subtle link to SiteCare for people who manage several sites and want them all handled from one dashboard.<\/li>\n<\/ul>\n\n<h4>2.3.0<\/h4>\n\n<ul>\n<li>New: <strong>beginner-friendly checkbox editor<\/strong> for owner \/ group \/ world (read \/ write \/ execute). No octal knowledge needed - the number is filled in and kept in sync automatically.<\/li>\n<li>New: <strong>live plain-language explanation<\/strong> of what each permission choice actually means, so you always know what you are about to apply.<\/li>\n<li>New: <strong>safety guardrails<\/strong>. Dangerous values (world-writable like 777\/666, unreadable 000, non-traversable folders, setuid\/setgid) are now hard-blocked in the browser and re-checked on the server - they can never be applied.<\/li>\n<li>Improved: clearer, decluttered interface with contextual \"i\" info tooltips, a primary \"Apply safe permissions\" action and a cleaner responsive layout.<\/li>\n<li>Changed: removed the one-click Undo. With dangerous values now impossible to apply and permissions safely re-runnable, it was no longer needed.<\/li>\n<\/ul>\n\n<h4>2.2.0<\/h4>\n\n<ul>\n<li>Renamed to SiteCare \u2013 File Permissions Manager, part of the SiteCare plugin family<\/li>\n<\/ul>\n\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>New: confirmation step before changing permissions, showing exactly how many files and folders will be affected.<\/li>\n<li>New: interface now follows your chosen WordPress admin colour scheme.<\/li>\n<li>New: file tree is fully keyboard accessible.<\/li>\n<li>Improved: errors are shown inline instead of browser pop-ups.<\/li>\n<li>Improved: refreshed icons and a friendly way to support the plugin (review, translate, donate).<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>New two-column interface with a live file tree and real progress bar.<\/li>\n<li>Advanced overrides for .htaccess, wp-config.php, .user.ini and php.ini (recommended \/ global \/ custom).<\/li>\n<li>Batched, timeout-safe processing.<\/li>\n<li>Full internationalization with translations for major languages; no external resources loaded.<\/li>\n<li>Security hardening: nonces, capability checks, path-traversal protection, symlink skipping.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Wrong permissions expose your site or quietly break it. Fix them across your whole WordPress install in one safe click - no FTP or SSH.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/336614","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=336614"}],"author":[{"embeddable":true,"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/fstab"}],"wp:attachment":[{"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=336614"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=336614"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=336614"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=336614"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=336614"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/mri.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=336614"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}