FTP TUTORIALS & GUIDES

How to Use FTP to Manage Your WordPress Site - A Beginner’s Guide

Learn how to manage WordPress files securely using FTP or SFTP, including uploading themes and plugins, editing configuration files, fixing errors, managing permissions and restoring access when the WordPress dashboard is unavailable.

Updated: June 20, 2026
By: RSH Web Editorial Staff

Hosting from $2.99/mo
  See Plans    Contact Us

Menu

How to Use FTP to Manage Your WordPress Site

Learn how to manage WordPress files with FTP or SFTP: upload themes and plugins, edit configuration files, fix errors when the dashboard is down, set permissions, and restore access.

Manage a WordPress site with FTP or SFTP

WordPress

The dashboard covers most day-to-day work. FTP or SFTP is for when you need the files themselves: a plugin that locks you out, a theme that whitescreens the site, or a copy of wp-config.php. Prefer SFTP. Using SFTP with cPanel

Connect

  1. Create or use an FTP account pointed at the WordPress root (often public_html). Create an FTP Account
  2. Open FileZilla, WinSCP, or another client. Choose a client
  3. Host, complete username, password or SSH key, port 21 or 22.
  4. You should see wp-admin, wp-content, and wp-includes.

Common tasks

Install a plugin or theme by hand
  1. Download the zip from wordpress.org or another source you trust. Unzip locally.
  2. Upload the plugin folder to wp-content/plugins, or the theme folder to wp-content/themes.
  3. Activate it in the dashboard if the site still loads.
Disable a broken plugin or theme

Rename the plugin folder (add -off) or rename the active theme folder so WordPress falls back to a default theme. Then log in and remove or replace the broken item.

Copy files for a backup

Download the WordPress tree, including wp-content/uploads and wp-config.php. That is files only. Export the database separately. Website backups

wp-config.php holds database credentials. Do not upload it to a public folder or paste it into a ticket in full.

Permissions

ItemTypical mode
Directories755
Files644
wp-config.phpOften 600 or 640 on a locked-down host

Security

Use SFTP or FTPS, not plain FTP. FTP vs SFTP vs FTPS
Do not give a vendor the primary cPanel login. Create a jailed FTP account. FTP user accounts
Delete extra accounts when the job is done.

Frequently Asked Questions

Do I still need FTP if I have the WordPress dashboard?

Yes for emergencies. The dashboard cannot help if a plugin causes a white screen or you are locked out. FTP or SFTP still reaches wp-content so you can rename a plugin, replace a theme, or upload a backup. Day-to-day posts can stay in wp-admin. Client options are in choosing an FTP client.

Where do I upload a plugin or theme with FTP?

Unzip the package on your computer first. Upload the plugin folder into wp-content/plugins, or the theme folder into wp-content/themes. Do not dump a nested extra folder or a zip file unless you will extract it on the server. Then activate it in the dashboard. Account setup is in creating an FTP account in cPanel.

How do I disable a broken plugin with FTP?

Connect, open wp-content/plugins, and rename the plugin folder, for example by adding -off. WordPress will stop loading it, which often restores wp-admin. Delete or replace the plugin after you can log in. The same rename trick works on a broken theme folder in wp-content/themes. Recovery context is in manual website recovery with FTP.

Does an FTP backup include the WordPress database?

No. FTP copies core files, themes, plugins, uploads, and wp-config.php. Posts and settings stay in MySQL. Export the database in cPanel and store that dump with the file copy. A files-only archive cannot rebuild the site. Backup scheduling is in automating website backups with FTP.

Should I use SFTP for WordPress files?

Yes when SSH is enabled, because wp-config.php holds database credentials. Extra FTP accounts still use FTPS unless they have SSH. Avoid plain FTP for WordPress work. See FTP vs SFTP vs FTPS and using SFTP with cPanel.

Which folder is the WordPress root?

It is the folder that contains wp-config.php and wp-content, often public_html or a subdirectory such as public_html/blog. An extra FTP user may already start inside that root. Do not upload a second WordPress copy into a random subfolder unless you want a second site. Path checks are in uploading files with FTP.

What permissions should WordPress files use?

Use 644 for most files and 755 for directories unless your host documents another standard. wp-config.php should stay tightly controlled and never world-writable. Wrong chmod can cause install or upload errors after an otherwise good transfer. Account and quota notes are in FTP user accounts explained.

Can several people share one WordPress FTP login?

They can, but they should not. Give each person or vendor a jailed extra account and revoke it when the work ends. Do not put the primary cPanel password in a group chat. More articles are on the blog index and in managing multiple FTP accounts.

Tweet  Share  Pin  Email

Add Comment

* Required information
Drag & drop images (max 3)

Comments

No comments yet. Be the first!

From the minds of our master copywriters

RSH Web Services is a leading web hosting provider with the most reliable, secure and fast service at affordable prices. We serve small businesses, large businesses and everything in-between. Our goal is to bring you the best value for your money with all of our website packages