What Folder Permissions Should Joomla Directories Use?

Use 755 as the common directory baseline

Joomla documentation lists 755 as a recommended default for directories on typical Unix/Linux hosting. The owner can read, write, and traverse the directory, while group and other users can read and traverse it. This permits normal web access without making the directory writable by everyone.

Understand why directories need execute permission

On directories, execute permission means traverse access rather than permission to run the directory. PHP and the web server need traverse permission on each parent directory leading to a file. A directory can therefore appear readable yet still block Joomla if the process cannot traverse part of the path.

Writable Joomla folders still should not default to 777

Cache, logs, temporary files, media uploads, and extension installation can require PHP write access, but Joomla security guidance warns against 0777. If a required directory is not writable at 755, investigate its owner, group, ACLs, or the server's PHP execution model instead of opening it to every user.

Check ownership before changing the mode

A 755 directory is writable only by its owner under the normal Unix interpretation. If Joomla runs PHP as the site account, that may be exactly what you want. If PHP runs under another user, the host may use groups, ACLs, or another mechanism. Match the hosting architecture rather than guessing.

Use Joomla's folder status as a diagnostic clue

Joomla System Information includes a Folder Permissions view that reports whether important directories are writable from Joomla's perspective. If a required folder reports unwritable, compare its filesystem path, ownership, and permissions with a working folder before applying broad recursive changes.

Be careful with recursive permission changes

Recursively setting every directory and file to the same numeric mode is usually wrong because directories and files use execute bits differently. If you must repair a tree, distinguish directories from files and preserve any host- or application-specific exceptions. Take a backup before large filesystem changes.

Verify functionality and security together

After correcting a folder, test the operation that needs it—such as cache writes, uploads, extension installation, or logs—and then confirm you did not grant unnecessary write access. A successful operation is only half the goal; the resulting directory should also follow the host's secure ownership model.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket