If you need to move files to and from your website’s server, you usually have three options: FTP, FTPS and SFTP. They sound almost the same, but there’s a big difference between them. The short answer is: use SFTP, preferably with an SSH key instead of a password, and never use plain FTP. Here we explain why, and how to get started.
What is FTP?
FTP (File Transfer Protocol) is one of the internet’s oldest protocols. The first version is from 1971, and the version used today was described in 1985, long before anyone thought about encryption. FTP uses two separate TCP/IP connections: one for commands, normally on port 21, and a new connection for every file or directory listing transferred. Who opens the data connection depends on whether active or passive mode is used, and that’s why FTP often acts up behind firewalls and routers.
The most serious problem, though, is that everything is sent unencrypted, including the username and password. Anyone who can see the traffic along the way, for example on public Wi-Fi, can read your login details and get full access to the files on your server.
FTPS and SFTP are two different things
The names are confusing because they look alike, but the two secure alternatives have nothing to do with each other. FTPS is plain FTP sent through an encrypted connection with TLS, the same TLS encryption that protects HTTPS. The protocol is the same as before, including the two connections, so the firewall problems are still there, and now the firewall can’t even look into the traffic to help.
SFTP (SSH File Transfer Protocol) is a completely different protocol that runs inside an SSH connection, the same one used to log in to a server via the terminal. Everything goes through one encrypted connection on one port, usually 22, and you can log in with an SSH key instead of a password.
| FTP | FTPS | SFTP | |
|---|---|---|---|
| Encrypted | No | Yes (TLS) | Yes (SSH) |
| Built on | FTP | FTP | SSH |
| Connections | Two or more | Two or more | One |
| Typical port | 21 | 21 or 990 | 22 |
| Key-based login | No | With a client certificate, rarely | Yes |
What you should use
SFTP is almost always the best choice. It’s encrypted, works through firewalls, is supported by every common file transfer program, and allows key-based login. If your hosting only offers FTPS, that’s an acceptable alternative. Plain FTP should be turned off on the server, and if your hosting provider only offers that, it’s a sign you should look for another.
How to get started with SFTP
- Find the SFTP or SSH details in your hosting control panel: host, port and username.
- Create an SSH key on your computer, for example with
ssh-keygen, and add the public part to your hosting. - Open a file transfer program that supports SFTP, such as FileZilla, Cyberduck or WinSCP, or use your code editor.
- Choose the SFTP protocol (not FTP), and enter the host, port and username.
- Accept the server’s fingerprint the first time you connect, after checking that it matches what your hosting provides.
You create the key with one command, and the ed25519 type is the good default today. You don’t need a file program either: SFTP is built into the terminal on macOS, Linux and recent Windows. The port is 22, unless your hosting has chosen another:
ssh-keygen -t ed25519 create a key pair
sftp -P 22 user@server.com connect
ls list files on the server
cd wp-content/uploads change folder on the server
get debug.log download a file to your computer
put image.jpg upload a file to the server
exit quit
The private key stays on your computer and must never be sent to anyone. Only the public part, usually the file ending in .pub, goes to your hosting.
SFTP and WordPress
Many people first meet FTP when WordPress asks for “connection information” to install or update a plugin. That happens because WordPress doesn’t have permission to write directly to its own files on the server, and so tries to do it via FTP instead. The fix isn’t to enter an FTP password, but to get the file permissions set up correctly so WordPress can update itself, or to have updates done somewhere other than WordPress’s own dashboard.
The starting point WordPress itself recommends is 755 on folders and 644 on files, owned by the user the web server runs as. wp-config.php contains the database password and should be stricter, so other users on the server can’t read it. If you see 777 anywhere, it’s a shortcut someone took, and it should be fixed.
For your own development, manual file transfer is rarely the best solution anyway. If you edit files directly on a live server, there’s no history, no testing and no way back if something goes wrong. A better workflow is to keep the code in a version control system like Git, test changes on a staging environment, and then deploy them automatically. SFTP is still useful for fetching log files, uploading a single file or fixing an urgent bug. If you’d rather not deal with any of it, files, updates and deployment can also be handled as part of ongoing maintenance.
Security
File access to the server is the same as full control of your website, so it has to be protected accordingly. Use SSH keys and turn off password login if your hosting allows it. Give each person and each system their own user, restrict them to the folders they need, and delete users when a collaboration ends. And never store login details in a file transfer program on a shared computer.
Frequently asked questions
Is SFTP slower than FTP?
Barely noticeably. The encryption costs a little, but modern computers handle it without problems, and because SFTP only uses one connection, it can even be faster with many small files.
Which port does SFTP use?
Port 22, the same as SSH, because SFTP runs inside an SSH connection. Plain FTP uses port 21, and FTPS either 21 or 990. Some hosting providers move SSH to another port, so check the control panel if the connection doesn’t get through.
Does SFTP require full SSH access?
No. SFTP uses SSH as its transport, but a user can have SFTP access without being able to run commands on the server. Many hosting providers offer exactly that kind of SFTP user, which can only see its own folder.