Ravindra BagaleCourses & study guides Track your progress

Guides

How to Install WordPress Themes and Plugins Without FTP (Amazon Linux 2023)

WordPress asks for FTP details when PHP cannot write to its own files, because the files belong to a different user than the one PHP-FPM runs as. On Amazon Linux 2023, PHP-FPM runs as apache by default (check /etc/php-fpm.d/www.conf), so run sudo chown -R apache:apache /var/www/wordpress, set folders to 755 and files to 644, and restart PHP-FPM; themes and plugins then install directly from the dashboard. define('FS_METHOD','direct'); and WP-CLI are optional helpers. Never use chmod 777.

Come on, friends! WordPress is installed, now you want to add a theme – you click Install Now and WordPress asks "FTP hostname, FTP username, password". Here many students start installing vsftpd or run chmod 777. Both are wrong. What is the problem? The owner of the files is wrong. Today we fix that – without FTP, the safe way.

Quick answer

On Amazon Linux 2023 with WordPress in /var/www/wordpress:

grep -E '^(user|group)' /etc/php-fpm.d/www.conf       # user = apache, group = apache (default)
sudo chown -R apache:apache /var/www/wordpress
sudo find /var/www/wordpress -type d -exec chmod 755 {} \;
sudo find /var/www/wordpress -type f -exec chmod 644 {} \;
sudo chmod 640 /var/www/wordpress/wp-config.php
sudo service php-fpm restart

Then Plugins → Add New → Install Now works without asking for FTP.

What do I need before fixing this?

Why does WordPress ask for FTP details?

Why WordPress asks for FTP and how the right owner fixes it You click Install Now in wp-admin. PHP-FPM runs as the user apache and tries to write into wp-content, which belongs to ec2-user, so WordPress shows the FTP Connection Information form. After sudo chown -R apache:apache, the files belong to apache with folders 755 and files 644, and the plugin installs directly without FTP. wp-admin Install Now Connection InformationFTP hostname: ____FTP password: ____ Plugin installed ✓no FTP needed EC2 (Amazon Linux 2023) PHP-FPMuser apache wp-content/ owner: ec2-user owner: apache folders 755files 644 $ sudo chown -R apache:apache ... never chmod 777 write?write?

You click Install in the WordPress dashboard. PHP-FPM (user apache) tries to write into wp-content. When the files belong to that same user, the plugin installs directly; when they belong to someone else, WordPress asks for FTP details.

Before installing anything, WordPress creates a small test file in wp-content and compares its owner with the owner of WordPress's own files. If they match, it uses the direct method and writes the plugin itself. If they do not match — for example the files were copied as ec2-user or root while PHP-FPM runs as apache — WordPress assumes it may not write there and falls back to FTP or SSH, which is why the "Connection Information" form appears.

How do I install themes and plugins without FTP?

Step 1 — Find the user PHP-FPM runs as

grep -E '^(user|group)' /etc/php-fpm.d/www.conf
ps -o user= -C php-fpm | sort | uniq -c

On Amazon Linux 2023 you normally see user = apache and group = apache — also when Nginx is the web server, because the Nginx PHP config on Amazon Linux 2023 only connects to this PHP-FPM pool through its socket. The master process shows as root; the workers that run WordPress show as apache. If your file says another user, use that name in the next steps.

Step 2 — Give the WordPress files to that user

ls -l /var/www/wordpress | head -5                  # who owns the files now?
sudo chown -R apache:apache /var/www/wordpress
ls -ld /var/www/wordpress/wp-content                # owner and group should now be apache

Ravindra Bagale's Tip

Because the theme won't install, many students run chmod -R 777 – it works, but now any user on the server, or one hacked plugin, can change your whole site. Never do this. The problem is not the permissions, it is the owner. Make the PHP-FPM user the owner (apache), folders 755, files 644. 777 means leaving every door of the house open. Keep this in mind!

Step 3 — Set safe permissions (755 / 644)

sudo find /var/www/wordpress -type d -exec chmod 755 {} \;
sudo find /var/www/wordpress -type f -exec chmod 644 {} \;
sudo chmod 640 /var/www/wordpress/wp-config.php     # database password: owner and group only

755 folders and 644 files let the owner (apache) write, and everybody else only read. That is all WordPress needs.

Step 4 — Restart PHP-FPM and install from the dashboard

sudo service php-fpm restart

Log in to /wp-admin → Appearance → Themes → Add New Theme, or Plugins → Add New Plugin → Install Now → Activate. No FTP form this time. 🎉 Uploading a .zip theme (Upload Theme) and WordPress core updates also work now.

Step 5 — Optional: FS_METHOD direct

If the form still appears after fixing the owner (for example with an unusual setup), you can tell WordPress to always write directly. Open wp-config.php:

sudo nano /var/www/wordpress/wp-config.php

Add this line above /* That's all, stop editing! Happy publishing. */:

define('FS_METHOD', 'direct');

Save (Ctrl+O, Enter) and exit (Ctrl+X). FS_METHOD only changes how WordPress writes. If PHP-FPM still cannot write to the folders, installs fail with "Could not create directory" — so the ownership fix in Step 2 is always the real solution.

Step 6 — Optional: WP-CLI, without the dashboard

WP-CLI installs themes and plugins from the terminal. Install it once:

curl -O https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar
php wp-cli.phar --info
chmod +x wp-cli.phar
sudo mv wp-cli.phar /usr/local/bin/wp

Run it as the PHP-FPM user, so the new files get the right owner (with the full path, because sudo does not search /usr/local/bin on Amazon Linux 2023):

sudo -u apache /usr/local/bin/wp plugin install classic-editor --activate --path=/var/www/wordpress
sudo -u apache /usr/local/bin/wp theme install astra --activate --path=/var/www/wordpress
sudo -u apache /usr/local/bin/wp plugin list --path=/var/www/wordpress

A warning about the WP-CLI cache folder is harmless. Do not run wp as root or with plain sudo: the files would belong to root and the FTP form would come back.

Ravindra Bagale's Tip

Pay attention: after fixing the owner, if you add new files with sudo cp or sudo unzip, they belong to root – and the FTP form comes back. When you have finished adding files, run sudo chown -R apache:apache /var/www/wordpress once more. Got it? One owner, permissions 755/644 – that's it.

Why not install an FTP server (vsftpd)?

Plain FTP sends the username and password unencrypted, needs port 21 plus a range of passive ports open in the security group, and adds one more service to patch. With the right owner WordPress needs no FTP at all. When you really need to copy files, upload them to your home folder with SFTP (it runs over SSH on port 22, which is already open for My IP) or scp, copy them into place with sudo cp, and run the chown again.

How do I fix common errors when installing plugins?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
"Connection Information" form asks for FTP Files not owned by the PHP-FPM user Step 1 and Step 2; restart PHP-FPM
Could not create directory Owner fixed on part of the tree only, or FS_METHOD without the owner fix sudo chown -​R apache:​apache /​var/​www/​wordpress
Installation failed: Download failed The instance cannot reach the internet (outbound rules, no route) Test curl -​I https://​wordpress.​org on the server
The uploaded file exceeds the upload_​max_​filesize PHP upload limit too low for the theme .zip Raise upload_​max_​filesize and post_max_size in /etc/php.ini, restart PHP-FPM
FTP form comes back after a while New files copied with sudo cp (owned by root), or wp run as root Run the chown again; use sudo -u apache for WP-CLI
wp: command not found with sudo /usr/local/bin not in sudo's path Use /​usr/​local/​bin/​wp

Learn it properly

This guide is the short path. These free lessons explain the Linux and WordPress background:

Samajla ka? Got it? WordPress asks for FTP because the owner is wrong. Find the PHP-FPM user, run chown, 755/644, and restart PHP-FPM – that's it. Never 777, and no FTP server either. Now install themes and plugins without fear.

Frequently asked questions

Why does WordPress ask for FTP details when I install a plugin?

WordPress first tests whether PHP can write to wp-content as the owner of the files. If the files belong to another user (for example ec2-user or root), it falls back to FTP and asks for connection details.

Which user does PHP-FPM run as on Amazon Linux 2023?

By default apache, with Apache and with Nginx. Check with grep -E '^(user|group)' /etc/php-fpm.d/www.conf and ps -o user= -C php-fpm.

Is chmod 777 a good fix?

No. 777 lets every user and process on the server change your files, so one hacked plugin can rewrite the whole site. Use the right owner with 755 folders and 644 files.

What does define('FS_METHOD','direct') do?

It tells WordPress to write files directly with PHP instead of testing ownership. It works only when PHP-FPM can really write to the folders, so fix the ownership first.

How do I install a plugin with WP-CLI?

Run WP-CLI as the PHP-FPM user so the new files get the right owner, for example sudo -u apache /usr/local/bin/wp plugin install classic-editor --activate --path=/var/www/wordpress.

Should I install vsftpd for WordPress updates?

No. Plain FTP sends the password unencrypted and needs port 21 plus passive ports open. Correct ownership, WP-CLI or SFTP on port 22 are safer.