Websites and Tech

FTP and SFTP

Also called FTP, SFTP, file transfer protocol

Ways of transferring files between a computer and a web server: FTP sends everything unencrypted, while SFTP runs over an encrypted SSH connection.

Quick facts: FTP and SFTP

Category
Websites and Tech
Also called
FTP, SFTP, file transfer protocol
Level
Intermediate
Affects
Website security, access control, data breach risk, ability to fix site problems
Where to see it
FileZilla, Cyberduck, WinSCP, hosting control panel, SSH keys
In this article4
  1. How FTP and SFTP work
  2. Why it matters
  3. Common mistakes
  4. How to act on it

FTP (File Transfer Protocol) and SFTP (SSH File Transfer Protocol) are methods for moving files between your computer and the server that hosts your website. FTP is the older method and sends usernames, passwords and files unencrypted. SFTP does the same job over an encrypted SSH connection, so nothing can be read in transit.

How FTP and SFTP work

You open a client program such as FileZilla, Cyberduck or WinSCP, enter the server address, a username, a password or key, and a port. FTP normally uses port 21; SFTP uses port 22, the same as SSH. Once connected, you see the site’s folders on the server and can upload, download, rename or delete files by dragging them across.

The names cause confusion. SFTP is not “FTP with security added”; it is a separate protocol that belongs to SSH. FTPS, by contrast, is the original FTP wrapped in TLS encryption. Both SFTP and FTPS are encrypted. Plain FTP is not, which means anyone able to watch the traffic on a shared network, such as café or hotel Wi-Fi, could capture the login details.

Most web hosting accounts let you create file-access accounts in the hosting control panel, and many now offer SFTP or SSH as standard. Managed WordPress hosts often provide SFTP only.

Why it matters

File access is powerful. Whoever can upload files to your server can change any page, add malicious code or delete the site. That makes FTP and SFTP accounts a common target, and plain FTP the weakest point, because a password sent in clear text can be intercepted and reused. For a UK business handling enquiries or orders, a compromised server can also be a personal data breach under UK GDPR, which you may need to report to the ICO within 72 hours of becoming aware of it.

From a marketing point of view, you still need file access occasionally: to upload a verification file for Google Search Console, edit a robots.txt file, fix a site locked by a faulty plugin or restore files from a backup. Knowing how to reach the server safely saves hours when something breaks.

Common mistakes

  • Using plain FTP because it is the default. If your host supports SFTP, there is no reason to use FTP.
  • One shared login for everyone. When a designer, a developer and an agency all use the main hosting password, you cannot tell who changed what or remove one person’s access.
  • Old accounts left open. File access created for a supplier years ago and never removed is a door left unlocked.
  • Editing live files directly. Changing theme files on the production server with no copy can take the site down in seconds. Work on a staging site and keep a backup.
  • Passwords saved in plain text in the FTP client or emailed between suppliers.

How to act on it

Log in to your hosting control panel and list every file-access account. Delete any you do not recognise or no longer need, and give each current supplier their own account limited to the folders they need. Switch to SFTP, or FTPS if SFTP is not offered, and prefer SSH keys to passwords where your host supports them.

Before anyone edits files on the server, confirm a recent website backup exists. When I need server access during a technical SEO project, for example to fix redirects or a robots.txt file, I ask for a separate SFTP account that can be removed when the work is done, rather than the main hosting login.

Do and do not

Do

  • Use SFTP or FTPS instead of plain FTP
  • Give each supplier a separate, limited account
  • Remove file-access accounts when work ends

Do not

  • Share the main hosting login
  • Edit live theme files without a backup
  • Send passwords by email

Questions people ask about this

Is SFTP the same as FTPS?

No. SFTP is part of SSH and runs on port 22. FTPS is traditional FTP with TLS encryption added, usually on port 21 or 990. Both encrypt your login and files, so either is far safer than plain FTP; which one you use depends on what your host supports.

Do I need FTP access if I use WordPress?

Not for everyday editing, which happens in the dashboard. File access becomes useful when something goes wrong, such as a plugin error that locks you out, or for tasks like uploading a verification file. Make sure you know how to get SFTP access before you need it in a hurry.

Should I give my web developer my FTP password?

It is better to create a separate account for them in your hosting control panel, limited to the folders they need. That way you can remove their access when the work ends without changing your own login, and you can see whose account made a change.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.