Scriptbaker
SCRIPTBAKERAI & Software Engineering
WordPress

Install WordPress Plugins Without FTP Access

Learn how to install WordPress plugins without FTP access. This updated guide explains why WordPress requests FTP credentials, how to fix filesystem permissions and ownership, when to use FS_METHOD, and how to troubleshoot common installation errors safely.

· 5 min read · By Tahir Yasin

Have you ever tried to install or update a WordPress plugin only to be greeted with a “Connection Information” screen asking for FTP credentials?

This commonly happens when WordPress cannot write to the files and directories it needs to modify. The good news is that you do not always need FTP access to install WordPress plugins. In many cases, the issue can be resolved by correcting file ownership and permissions or by configuring WordPress to use its direct filesystem method.

In this guide, you will learn:

  • Why WordPress asks for FTP credentials
  • How WordPress chooses its filesystem method
  • How to enable direct file installation with FS_METHOD
  • How to fix file ownership and permissions on Ubuntu/Linux
  • How to troubleshoot shared hosting environments
  • How to use WordPress Site Health to identify filesystem problems
  • Why setting permissions to 777 is a bad idea
  • What to do when FS_METHOD does not solve the problem

Why Does WordPress Ask for FTP Credentials?

WordPress needs filesystem access when it installs plugins, updates themes, upgrades WordPress core, deletes files, or performs other file operations.

Before performing these operations, WordPress determines which filesystem method it should use. The available methods include:

  • Direct — WordPress writes to the filesystem directly through PHP.
  • SSH2 — WordPress uses SSH when the required PHP extension and credentials are available.
  • FTP PHP Extension — WordPress uses the PHP FTP extension.
  • FTP Sockets — WordPress communicates through FTP sockets.

WordPress generally prefers the Direct method when the server environment allows it. The filesystem method can also be explicitly configured with the FS_METHOD constant.

If WordPress determines that it cannot safely write to the required location, it may ask for FTP or SSH connection information instead.

What Causes the FTP Prompt?

The most common cause is a mismatch between file ownership and the user running PHP/web server processes.

For example, imagine that your WordPress files are owned by:

username

but PHP is running as:

www-data

If the PHP process does not have appropriate write access, WordPress may decide that it cannot use direct filesystem operations and request another filesystem transport.

Permissions can also cause the problem. A directory may be readable but not writable by the user or group that needs to modify it.

WordPress's current documentation emphasizes that permissions depend on the server configuration. There is no single permission setting that is correct for every hosting environment.

First: Check WordPress Site Health

Before changing server permissions or editing wp-config.php, check whether WordPress itself has identified a filesystem problem.

Go to:

WordPress Dashboard → Tools → Site Health → Status

Look for information related to:

  • Filesystem permissions
  • Automatic updates
  • PHP compatibility
  • Background updates
  • Filesystem credentials

WordPress Site Health can specifically detect whether the installation requires FTP credentials for updates and whether core files are writable by the web user or group.

Solution 1: Use the Direct Filesystem Method

If your hosting environment is correctly configured and PHP has permission to modify the required WordPress files, you can tell WordPress to use the direct filesystem method.

Open your wp-config.php file and add the following line:

define( 'FS_METHOD', 'direct' );

Place it before the line that says:

/* That's all, stop editing! Happy publishing. */

Your configuration may look similar to this:

define( 'DB_NAME', 'your_database_name' );define( 'DB_USER', 'your_database_user' );define( 'DB_PASSWORD', 'your_database_password' );define( 'DB_HOST', 'localhost' );define( 'FS_METHOD', 'direct' );/* That's all, stop editing! Happy publishing. */

Save the file and return to your WordPress dashboard.

Then try:

Plugins → Add New Plugin

or attempt the update again.

Important: FS_METHOD does not magically grant WordPress permission to write files. If the underlying ownership or permissions are incorrect, forcing the direct method may not fix the problem and can produce permission errors.

WordPress recommends changing FS_METHOD only when you are experiencing filesystem/update problems. If changing it does not help, remove the constant and investigate the server configuration instead.

Solution 2: Fix File Ownership

On a Linux server, incorrect ownership is one of the most important things to investigate.

First check the ownership of your WordPress directory:

ls -la /path/to/wordpress

You can also inspect the wp-content directory:

ls -ld /path/to/wordpress/wp-content

On a typical Ubuntu server, PHP may run under a user such as:

www-data

However, do not automatically change ownership to www-data. The correct ownership depends on how your server, PHP-FPM, web server, and hosting environment are configured.

For example, a server administrator may intentionally configure PHP to run under the website's own system user. In that case, changing everything to www-data could make the configuration worse.

WordPress's documentation recommends understanding the server's ownership model before changing permissions.

Solution 3: Check Directory and File Permissions

Linux permissions determine who can read, write, and access files and directories.

A common starting point for a standard WordPress installation is:

Directories: 755Files:       644

Some hosting environments may require group-writable permissions such as:

Directories: 775Files:       664

But these values should not be applied blindly. The correct settings depend on your server's ownership and PHP execution model.

Check the Current Permissions

Use:

ls -ld wp-contentls -la wp-content

You may see something similar to:

drwxr-xr-x  5 username username 4096 Oct 1 wp-content

The first part represents the directory permissions, while the next fields show its owner and group.

Ubuntu/Linux Example

If you manage your own Ubuntu server, first identify which user PHP-FPM or your web server is actually running as. For example:

ps aux | grep php-fpmps aux | grep nginxps aux | grep apache2

Do not copy ownership commands from a tutorial without confirming your server configuration first.

For a server where www-data is intentionally configured as the appropriate owner, an administrator might use:

sudo chown -R www-data:www-data /path/to/wordpress

However, this is only an example. On many hosting setups, WordPress files should remain owned by the website's system user instead.

Do Not Use 777 to Fix WordPress Permissions

One of the most common suggestions for WordPress permission problems is:

chmod -R 777 wp-content

Do not use this as a normal solution.

Permission 777 gives the owner, group, and everyone else read, write, and execute permissions. Making a directory world-writable can significantly increase the security risk of a compromised process or account.

WordPress's current documentation explicitly warns against using 777 and recommends finding a secure ownership and permission configuration instead.

Instead of making everything writable, determine:

  1. Who owns the WordPress files?
  2. Which user runs PHP?
  3. Which group owns the files?
  4. Does that user or group have the required write access?
  5. Is the hosting environment using a special PHP execution model?

What Permissions Should WordPress Files Have?

There is no universal permission value for every WordPress installation, but the WordPress documentation gives commonly used secure values such as:

Item Common Permission Purpose
Directories 755 Owner can write; others can access the directory.
Files 644 Owner can write; others can read.
More restrictive directories 750 Useful in appropriate server configurations.
More restrictive files 640 Useful when the server/user model supports it.
wp-config.php 440 or 400 in appropriate configurations Provides additional protection for database credentials.

These are starting points rather than rules that should be applied to every server. WordPress specifically notes that permission requirements vary between hosting environments.

Shared Hosting: Why the Solution Can Be Different

Shared hosting environments often use different PHP execution models from a self-managed VPS or dedicated server.

For example, some hosting configurations run PHP under the same account that owns the WordPress files. In that situation, standard permissions such as 755 for directories and 644 for files may allow WordPress to install plugins without FTP credentials.

Other environments use separate web-server and account users. In those cases, group permissions or the hosting provider's configuration may be required.

This is why simply changing permissions without understanding the hosting environment can create new problems.

Solution 4: Ask Your Hosting Provider to Fix the Ownership

If you only have WordPress administrator access and no FTP, SSH, cPanel File Manager, or other server-level access, you may not be able to fix the underlying filesystem configuration yourself.

In that situation, contact your hosting provider and explain:

“WordPress is prompting for FTP credentials when installing or updating plugins. Please check the ownership and write permissions of my WordPress installation and configure the server so WordPress can use the appropriate filesystem method.”

This is often safer than attempting random permission changes from the WordPress dashboard.

Solution 5: Check Whether a Security Plugin or Hosting Rule Is Blocking Writes

Filesystem problems are not always caused by basic Linux permissions.

Other factors can include:

  • Hosting security policies
  • PHP-FPM configuration
  • SELinux policies
  • Read-only filesystem mounts
  • Incorrect ownership
  • Disk quota or storage limits
  • Security plugins or server-level security rules
  • Incorrect WordPress path configuration
  • Containerized or unusual hosting environments
  • Symlink-based WordPress installations

WordPress's server documentation recommends checking the hosting environment before changing server configuration, particularly on managed hosting.

What If FS_METHOD = direct Does Not Work?

If you added:

define( 'FS_METHOD', 'direct' );

and WordPress still cannot install a plugin, do not immediately try 777.

Instead, work through this checklist:

  1. Check the wp-content directory ownership.
  2. Check whether PHP can write to wp-content.
  3. Check the permissions of the relevant directories.
  4. Check available disk space and hosting quotas.
  5. Check WordPress Site Health.
  6. Check whether SELinux or another security policy is blocking access.
  7. Check your hosting provider's filesystem restrictions.
  8. Remove FS_METHOD if forcing it does not solve the problem.

WordPress REST API and Filesystem Access

Modern WordPress also uses filesystem access for certain administrative and REST API operations involving plugins and themes.

For plugin management, WordPress supports the Direct filesystem transport and can also work with SSH/FTP when valid credentials are available.

This makes correct server-side filesystem configuration important not only for the traditional WordPress dashboard but also for some modern WordPress management workflows.

Using the WordPress Filesystem API

If you are a developer creating a plugin or theme that needs to modify files, you should generally use the WordPress Filesystem API rather than assuming that PHP can directly write to files.

WordPress provides filesystem classes for different transports, including the direct filesystem implementation.

This is particularly important for plugins that need to write configuration files, create directories, modify assets, or perform other filesystem operations across different hosting environments.

Can You Install a Plugin Without FTP From the WordPress Dashboard?

Yes. If your server allows WordPress to use the Direct filesystem method and the necessary files are writable, you can install plugins directly from:

Dashboard → Plugins → Add New Plugin

You can also upload a plugin ZIP file from the WordPress dashboard:

Plugins → Add New Plugin → Upload Plugin

However, uploading a ZIP through the dashboard still requires WordPress to have sufficient filesystem access to extract and install the plugin.

What If You Have WordPress Admin Access but No FTP or SSH?

This is a common situation for developers, marketers, content managers, and site administrators who have been given dashboard access but not server access.

Your options are:

  • Ask the hosting provider to correct filesystem ownership.
  • Ask the server administrator to verify PHP write permissions.
  • Use a hosting control panel's File Manager if available.
  • Use the WordPress dashboard if the server is already correctly configured.
  • Ask someone with server access to make the required configuration change.

Do not install an untrusted “FTP bypass” plugin simply to avoid the credentials prompt. A plugin that can write arbitrary files can create a serious security risk if it is poorly designed or malicious.

Important Security Checklist

Before changing your WordPress filesystem configuration:

  • Back up your website.
  • Back up wp-config.php before editing it.
  • Do not use 777 as a permanent fix.
  • Do not change ownership without understanding your PHP/web-server user model.
  • Use the least-permissive permissions that work.
  • Remove unnecessary filesystem overrides.
  • Test plugin installation after making changes.
  • Check Site Health after the configuration change.

Incorrect server configuration can take a WordPress website offline, so server-level changes should be made carefully and preferably tested on staging first.

Quick Fix Summary

Problem What to Check
WordPress asks for FTP Check file ownership and filesystem method.
FS_METHOD is not set Use define( 'FS_METHOD', 'direct' ); only when appropriate.
Direct method fails Check PHP write access and ownership.
Permission denied Review directory/file permissions.
Shared hosting Check the hosting provider's PHP and ownership configuration.
Nothing works Ask the host/server administrator to check filesystem access.

Frequently Asked Questions

1. Can I install WordPress plugins without FTP access?

Yes. If WordPress can write to the required directories using the Direct filesystem method, you can install and update plugins directly from the WordPress dashboard without entering FTP credentials.

2. Why is WordPress asking for FTP credentials?

Usually because WordPress cannot use the Direct filesystem method with the current server ownership or permissions. WordPress then looks for another supported filesystem transport, such as FTP or SSH.

3. Does FS_METHOD direct remove the need for FTP?

It can, provided the server configuration allows PHP to write to the required WordPress files. The constant does not override operating-system permissions or server security policies.

4. Where should I add FS_METHOD direct?

Add it to wp-config.php, before the “That's all, stop editing!” comment:

define( 'FS_METHOD', 'direct' );

5. Is FS_METHOD direct safe?

It is not inherently unsafe, but it should be used only when the server's filesystem permissions and ownership are correctly configured. WordPress recommends changing the constant only when necessary for update problems.

6. Should I set wp-content to 777?

No. A world-writable directory can introduce unnecessary security risk. Correct the ownership and permissions instead. WordPress specifically warns against using 777 as a normal permissions solution.

7. What are the normal WordPress file permissions?

A common starting point is 755 for directories and 644 for files, but the correct configuration depends on the hosting environment and ownership model.

8. Why does WordPress still ask for FTP after I set FS_METHOD to direct?

The underlying filesystem may still be unwritable. Check ownership, permissions, PHP execution users, disk space, security policies, and hosting restrictions.

9. Can I fix this with only WordPress admin access?

Sometimes. If the server is already correctly configured, adding the appropriate FS_METHOD setting may help. However, if the problem is caused by Linux ownership or server permissions, you will normally need hosting, File Manager, SSH, or administrator access.

10. Does this problem affect WordPress core updates too?

Yes. Filesystem access is used for more than plugin installation. WordPress also needs appropriate filesystem access for core updates, theme updates, plugin updates, and other file-management operations.

11. Should I leave FS_METHOD direct permanently?

If your hosting environment is designed to use the Direct method and it works correctly, it may be appropriate. However, WordPress recommends avoiding unnecessary filesystem overrides. If the setting was added only to troubleshoot a temporary problem, consider removing it after the underlying configuration is corrected.

12. Who should I contact if I don't have server access?

Contact your hosting provider or server administrator. Ask them to check WordPress file ownership, PHP's effective user, filesystem permissions, and whether the server allows WordPress to use the Direct filesystem method.

Final Thoughts

The FTP credentials prompt is usually not a WordPress plugin problem. It is often a sign that WordPress cannot safely access the filesystem using the method it wants to use.

The best solution is not to make everything writable. Instead, identify why WordPress cannot write to the required location and correct the server configuration.

For many properly configured servers, the solution is straightforward:

  1. Check Site Health.
  2. Verify file ownership.
  3. Verify directory and file permissions.
  4. Confirm which user runs PHP.
  5. Use FS_METHOD only when appropriate.
  6. Never use 777 as a shortcut.
  7. Contact your hosting provider when server-level access is required.

Once WordPress has the correct filesystem access, you should be able to install and update plugins directly from the dashboard without repeatedly entering FTP credentials.

Last updated:

Work with Scriptbaker

Let's talk about your project

Whether you're extending an existing platform, modernising legacy code, or planning something new, our engineers can help. Tell us what you're working on and we'll explore a practical technical solution together.