Poorly set file permissions on shared hosting
A folder or file left too open on a server shared by dozens of other sites can be enough to spread an infection from one site to another, without any password ever being compromised.
What file permissions actually are
Every file and folder on a server has permissions defining who can read, modify or execute it: the file’s owner, a group of users, and everyone else on the server. These permissions are expressed as three digits, such as 644 or 755, each combining read, write and execute rights for those three categories.
On a server dedicated to a single site, an overly open permission is still a risk, but a limited one. On shared hosting, several different customer accounts often share the same physical server. If file permissions are too permissive, a script running under another account on that same server can, depending on the host’s configuration, read or write into a neighbouring site’s files. This is known as "cross-site" or "cross-account" compromise: a neglected site can become the way in to a perfectly up-to-date site hosted right next to it.
The recommended values for WordPress
WordPress’s official documentation recommends folders at 755 (or 750 if the server allows it), files at 644 (or 640), and a special case for wp-config.php: 440 or 400, to stop other users on the server from even reading it, since it holds the database login credentials. No folder should ever be set to 777, including upload folders, which are often left too open to avoid write errors when a file is submitted.
chmod 440 wp-config.php # 644 leaves the file readable by other accounts on the server
The recommended values for PrestaShop
PrestaShop’s official documentation and community guides recommend 644 for files and 755 for folders. Some hosts temporarily require 777 on certain folders during the installation step, so the installer can write without errors. Once installation is finished, permissions should be tightened back up: 775 for folders and 664 for files at minimum, ideally 755 for folders and 644 for files as soon as the host’s configuration allows it.
How to check your own permissions
-
Connect via FTP or SFTP
Most FTP clients show a permissions column next to each file and folder, usually as three digits or a string of letters.
-
Check your host’s file manager
The hosting control panel usually offers a file manager with the same information, without needing an external FTP client.
-
Check configuration files first
wp-config.php on WordPress, or PrestaShop’s database configuration files, should be checked first: they hold the most sensitive information.
-
Ask your host to confirm
A reputable host can confirm whether your account benefits from isolation between customers on the same server, which reduces the risk even where a permission is misconfigured elsewhere.
Related reading
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.