↑ ↓ select, Enter open, Esc close

Permissions and ownership

Set file permissions and ownership correctly without opening up too much. With typical values for web directories, WordPress installations and Plesk subscriptions.

15 one-liners: 8 harmless, 7 caution, 0 destructive

All Permissions and ownership one-liners

Check permissions along a path

$namei -l /var/www/vhosts/example.com/httpdocs/index.php
harmless

Copy permissions and owner from a reference file

#chmod --reference=/var/www/vhosts/example.com/httpdocs/index.php /var/www/vhosts/example.com/httpdocs/wp-config.php && chown --reference=/var/www/vhosts/example.com/httpdocs/index.php /var/www/vhosts/example.com/httpdocs/wp-config.php
caution

Find files with the SUID or SGID bit

#find / -xdev \( -perm -4000 -o -perm -2000 \) -type f -exec ls -l {} + 2>/dev/null
harmless

Find files with the wrong owner in a webspace

#find /var/www/vhosts/example.com/httpdocs ! -user webuser -ls
harmless

Find files without a valid owner

#find /var/www -xdev \( -nouser -o -nogroup \) -ls 2>/dev/null
harmless

Find world-writable files and directories

$find /var/www/vhosts -xdev -perm -0002 ! -type l -ls 2>/dev/null
harmless

WordPress runs. Does it rank?

Check the Core Web Vitals of your WordPress site

Plugins updated, cache flushed, permissions fixed. GENLOC.SEO shows how Google sees the site: PageSpeed, on-page checks and prioritized recommendations. Free.

by GENLOC.NETWORK, the team behind myline.de

Grant a user write access with ACLs

#setfacl -R -m u:deploy:rwX,d:u:deploy:rwX /var/www/vhosts/example.com/httpdocs
caution

Remove write permission for others recursively

$chmod -R o-w /var/www/vhosts/example.com/httpdocs
caution

Reset file ownership in a Plesk webspace to the subscription user

#find /var/www/vhosts/example.com/httpdocs -mindepth 1 -exec chown -h webuser:psacln {} +
caution

Secure the permissions of wp-config.php

$chmod 600 /var/www/vhosts/example.com/httpdocs/wp-config.php
caution

Set all directories to 755 recursively

$find /var/www/vhosts/example.com/httpdocs -type d -exec chmod 755 {} +
caution

Set all files to 644 recursively

$find /var/www/vhosts/example.com/httpdocs -type f -exec chmod 644 {} +
caution

Show permissions and owner in octal notation

$stat -c '%a %U:%G %n' /var/www/vhosts/example.com/httpdocs/* /var/www/vhosts/example.com/httpdocs/.[!.]*
harmless

Show the ACL permissions of a file

$getfacl /var/www/vhosts/example.com/httpdocs
harmless

Show the current umask

$umask && umask -S
harmless

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.