FTP (File Transfer Protocol) and SFTP (SSH File Transfer Protocol) are methods for moving files between your computer and the server that hosts your website. FTP is the older method and sends usernames, passwords and files unencrypted. SFTP does the same job over an encrypted SSH connection, so nothing can be read in transit.
How FTP and SFTP work
You open a client program such as FileZilla, Cyberduck or WinSCP, enter the server address, a username, a password or key, and a port. FTP normally uses port 21; SFTP uses port 22, the same as SSH. Once connected, you see the site’s folders on the server and can upload, download, rename or delete files by dragging them across.
The names cause confusion. SFTP is not “FTP with security added”; it is a separate protocol that belongs to SSH. FTPS, by contrast, is the original FTP wrapped in TLS encryption. Both SFTP and FTPS are encrypted. Plain FTP is not, which means anyone able to watch the traffic on a shared network, such as café or hotel Wi-Fi, could capture the login details.
Most web hosting accounts let you create file-access accounts in the hosting control panel, and many now offer SFTP or SSH as standard. Managed WordPress hosts often provide SFTP only.
Why it matters
File access is powerful. Whoever can upload files to your server can change any page, add malicious code or delete the site. That makes FTP and SFTP accounts a common target, and plain FTP the weakest point, because a password sent in clear text can be intercepted and reused. For a UK business handling enquiries or orders, a compromised server can also be a personal data breach under UK GDPR, which you may need to report to the ICO within 72 hours of becoming aware of it.
From a marketing point of view, you still need file access occasionally: to upload a verification file for Google Search Console, edit a robots.txt file, fix a site locked by a faulty plugin or restore files from a backup. Knowing how to reach the server safely saves hours when something breaks.
Common mistakes
- Using plain FTP because it is the default. If your host supports SFTP, there is no reason to use FTP.
- One shared login for everyone. When a designer, a developer and an agency all use the main hosting password, you cannot tell who changed what or remove one person’s access.
- Old accounts left open. File access created for a supplier years ago and never removed is a door left unlocked.
- Editing live files directly. Changing theme files on the production server with no copy can take the site down in seconds. Work on a staging site and keep a backup.
- Passwords saved in plain text in the FTP client or emailed between suppliers.
How to act on it
Log in to your hosting control panel and list every file-access account. Delete any you do not recognise or no longer need, and give each current supplier their own account limited to the folders they need. Switch to SFTP, or FTPS if SFTP is not offered, and prefer SSH keys to passwords where your host supports them.
Before anyone edits files on the server, confirm a recent website backup exists. When I need server access during a technical SEO project, for example to fix redirects or a robots.txt file, I ask for a separate SFTP account that can be removed when the work is done, rather than the main hosting login.
