Best thing to do is check the WP docs themselves for correct file/folder permissions and how to change them, if needed:
Typically, all files should be owned by your user (ftp) account on
your web server, and should be writable by that account. On shared
hosts, files should never be owned by the web server process itself
(sometimes this is www, or apache, or nobody user).
Is “tape” a local user name? Or FTP name?
Depending on what kind of system you’re using – a local install of apache, php and mysql – or a stack like Bitnami, XAMPP or MAMP, there may be slightly different owners and groups for folders and users.
Related Posts:
- What Are Security Best Practices for WordPress Plugins and Themes? [closed]
- Are WordPress Plugins essential?
- Prompted for FTP details even with FS_DIRECT set to true
- What are the common security flaws I need to look for? [closed]
- How Can I Securely Implement a Password-less Login Feature?
- How to prevent a post from being deleted?
- Is there a way (plugin?) to restrict a user to being able to edit just one page?
- Security and .htaccess
- Are there procedures to prevent malicious plugin updates?
- How to stop wordpress from changing default .htaccess permissions to 444
- Secure WordPress paid plugin
- How to make media upload private? [duplicate]
- Does WordPress contain “default” anti-SQL injection code that responds with a 404 error?
- What does a security risk in a plugin look like?
- WordPress Capabilities: edit_user vs edit_users
- How to check plugins for malicious code?
- How to properly secure my WordPress installation?
- Where should my plugin POST to?
- How does WordPress update plugins, without running into permissions issues?
- Security error WP 4.0 + WP phpBB Bridge [closed]
- Plugins won’t auto-update on IIS
- Why am I sometimes getting a 404 error when I try to update a page with Elementor?
- Is it possible to block subscriber users to changing its password?
- Why users disable the WordPress update?
- Will WordPress username displayed somewhere in the site?
- WordPress roles – Protect administrator role
- 403 Forbidden – You don’t have permission to access /wp-admin/admin-ajax.php on this server
- Is revealing just the AUTH_KEY a security issue?
- Questions about brute force attacks on the admin username, coming from amazon IP addresses
- Could not create directory
- Why Better WP security plugin returns 418 I’m a Teapot “error”?
- How to expire all wordpress user passwords instantly?
- Weird problems after recovery from security breach
- Correct wp-content ownership and permissions
- Security checking in meta_box save is reluctant?
- Advanced Custom Fields/User Role Editor – how to hide ACF for certain users?
- Should you escape hardcoded URLs?
- How create a role with admin capability less 1 or 2?
- Are these wp-content permissions safe?
- How To Clean The Malware Infected & Hacked WordPress Websites? [duplicate]
- How to delete Passwrd Protected posts cookies when a user logged out from the site
- Prevent WordPress installing plugins and themes via Admin
- Upgraded to latest version – 3.0.3 and Now I get a “sufficient permissions to access this page” error
- Headers Content-Security-Policy CSP Major Issue
- How to block plugin activations with no known user or coming from unknown IP address range?
- Check for security updates
- Standard Fail2Ban vs. WP Fail2ban vs. WP Fail2Ban Redux
- Linux Permissions and Ownership for WordPress
- Malicious File Upload [closed]
- Updating plugins asks for FTP information, why? (this is a new one)
- Malware installation during plugin update?
- Add menu page issues (permissions & position)
- I should enable automatic updates?
- Can some vulnerabilities in plugins be exploited even when the plugin is inactive?
- Advanced Custom Fields – Disable Users to Edit Custom Fields
- Is there any way to make myself an admin?
- Why is the ‘Gutenberg’ Plugin generating an ‘Inconsistent File Permissions’ error when other Plugins, with the same permissions, do not?
- How to protect WordPress from security scanner [closed]
- Too many login attempts
- Website show Google Ads when we have no Google Ads linked to our website
- Vulnerability Concern From the Plugin or From Not Updating the Plugin?
- Why is my WordPress Plugin page requesting my FTP Login Credentials?
- Chrome Dev Tools console says every page in my blog has link to [closed]
- Webservice credential storage [duplicate]
- Regarding plugin security
- How do I determine if the user who registered is not spam?
- Is this plugin safe to run?
- How to write to the plugin’s directory?
- Is the Block Bad Queries Plugin Still Relevant?
- 404 errors when updating options in admin dashboard
- How can I disable new plugin and theme install, but allow updates?
- Help to Create a Simple Plugin to make a post
- Validating ajax search
- WordPress disable direct access of files in WordPress installation path
- Asking help regarding potential malware
- Bing/msn bots is heavily requesting random of my website
- Can’t add or delete plugins – but I’m an admin [closed]
- Database error when user logs in
- WordPress FTP/media directory permissions problem?
- SSH vs WordPress
- Being hacked. Is there a list of WordPress security holes I can check against?
- wp_verify_nonce fails always
- Images not showing on homepage after migration [duplicate]
- Write mysql credentials in plugin
- page creator to leave comments ONLY
- Editor have not permissions for a plugin
- SWF in wordpress post
- WordPress Permission Problems on Ubuntu 12.04 with LAMP stack
- Unwanted Links and Spam WordPress Pages and Posts
- Making plugin to use different table prefix cause permission problem
- File permissions for wp-minify plugin
- What is the recommended way to be notified of security updates to my plugins? [closed]
- My WP site and password was hacked, what to do? [closed]
- How to resolve these findings from security audit
- Two sites one PC
- How I can hide my wp folders from Inspect Element (Developer Tools)
- How to Find WordPress site has backdoor login Codes
- How to rename files during upload to a random string?
- Gravity Forms and Gravity View Permissions
- Stop the user if login from the cookies