Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
To upload files to a WordPress site from your computer, use an FTP client to connect to the hosting server, find the directory containing wp-admin, wp-content, and wp-includes, then copy files into the required subfolder. Choose SFTP whenever your host offers it: plain FTP sends credentials and data without encryption. This guide covers the complete beginner workflow, including plugins, themes, media, verification files, recovery, and common errors.
FTP, SFTP and the WordPress file system
FTP means File Transfer Protocol. An FTP client is the desktop application that copies files between your local site (your computer) and the remote site (your hosting server).
SFTP means SSH File Transfer Protocol. It is a separate SSH-based protocol, not simply FTP with an extra letter. FTPS is FTP protected with TLS/SSL. WordPress recommends SFTP instead of unencrypted FTP whenever the host supports it (WordPress FTP documentation).
These protocols provide access to files, not to the WordPress database. Copying files alone does not move posts, pages, users, menus, or plugin settings; a complete migration requires a database backup as well (WordPress backup lesson).
#1 Best Overall
- USB-C 2-in-1 storage OTG: The Lexar JumpDrive Dual Drive D40E features USB Type-A and Type-C connectors in a slim, portable form factor for easy device compatibility
- Transfer speeds up to 100MB/s: Based on internal testing, performance may vary depending upon the host device, interface, and usage conditions. 1MB=1,000,000 bytes
- Plug and Play: Widely compatible with USB Type-C smartphones, tablets, laptops, Macs, and traditional Type-A devices, no software installation required. The 360° swivel design allows for easy switching between connectors without the hassle of losing a cap
- Durable & Compact: The Lexar D40E USB memory stick features a metal enclosure, withstands temperatures from 0° to 50° C (32°F to 122°F), and is lightweight at 26g with dimensions of 70.4 x 16.9 x 11.7mm
- Security & Warranty: Securely protects files using an advanced security software solution with 256-bit AES encryption. Backed by a Lexar 3-year limited warranty
When FTP or SFTP is useful
- Uploading a large folder or many files.
- Manually installing a plugin or theme.
- Replacing damaged WordPress files.
- Adding a PHP, CSS, JavaScript, font, or verification file where documentation requires it.
- Downloading files for a backup.
- Recovering when a plugin or theme has broken the dashboard.
- Resuming an interrupted transfer.
For routine work, FTP is often unnecessary. Use Plugins → Add New, Appearance → Themes, or Media → Add New when those dashboard tools meet your needs. A hosting File Manager can also be quicker for a single upload or ZIP extraction.
What you need before connecting
- A self-hosted WordPress site or a platform that provides file access.
- The host name, SFTP/FTP username, password or SSH private key, and port supplied by your host.
- A desktop client such as FileZilla Client or Cyberduck.
- The local file or extracted folder you intend to upload.
- A recent backup of both site files and the database.
Find connection details in your hosting welcome email, control panel’s SFTP/SSH or FTP accounts area, support documentation, or by asking support. Do not assume your WordPress administrator username and password are the same as your hosting login.
WordPress.com has platform-specific access rules. Its instructions tell users to select SFTP in FileZilla (WordPress.com SFTP client guide), and managed files may not be editable like files on ordinary self-hosted hosting.
Recommended Free Tools
Choose a transfer tool
| Tool | Best for | Important notes |
|---|---|---|
| FileZilla Client | Most beginners on Windows, macOS, or Linux | Free; supports FTP, FTPS, and SFTP; download from the official site. |
| Cyberduck | Windows and macOS users who prefer a simpler browser-style interface | Supports SFTP, secured FTP, and cloud services; use the official download page. Version listings and store pricing can change. |
| Hosting File Manager | One-off uploads, renaming, deletion, or server-side ZIP extraction | No installation, but browser limits and timeouts can make large batches inconvenient. |
FileZilla Pro is not required for ordinary WordPress transfers. It adds cloud-storage integrations and related professional features; consider it only if you need those connections (FileZilla Pro protocols). Do not pay for a client when the free Client or Cyberduck solves the task.
Rank #2
- High-speed USB 3.0 performance of up to 150MB/s(1) [(1) Write to drive up to 15x faster than standard USB 2.0 drives (4MB/s); varies by drive capacity. Up to 150MB/s read speed. USB 3.0 port required. Based on internal testing; performance may be lower depending on host device, usage conditions, and other factors; 1MB=1,000,000 bytes]
- Transfer a full-length movie in less than 30 seconds(2) [(2) Based on 1.2GB MPEG-4 video transfer with USB 3.0 host device. Results may vary based on host device, file attributes and other factors]
- Transfer to drive up to 15 times faster than standard USB 2.0 drives(1)
- Sleek, durable metal casing
- Easy-to-use password protection for your private files(3) [(3)Password protection uses 128-bit AES encryption and is supported by Windows 7, Windows 8, Windows 10, and Mac OS X v10.9 plus; Software download required for Mac, visit the SanDisk SecureAccess support page]
Connect with SFTP in FileZilla
- Install FileZilla Client from filezilla-project.org.
- Open File → Site Manager, create a new site, and enter the values supplied by your host.
- Set Protocol to
SFTP - SSH File Transfer Protocol. - Enter the host address and the host-supplied port. Do not assume port 22 is universal.
- Choose the logon type required by the host (password, interactive, or key file), then enter the hosting username and password or select the authorized private key.
- Click Connect. On the first connection, review the server fingerprint. Compare it with a fingerprint published by your host and accept only when the server identity is reasonably verified; ask support if unsure.
If the host supplied FTPS rather than SFTP, select the exact FTPS protocol and settings it specifies. Choosing ordinary FTP for SFTP credentials commonly causes connection or authentication failures.
Understand the FileZilla window
- Local site: folders on your computer.
- Remote site: folders on the server.
- Filename panes: files available locally and files already on the server.
- Transfer queue: pending, successful, and failed transfers.
- Status area: connection messages and errors.
- Site Manager and bookmarks: saved connection profiles.
Select a local file or folder and drag it into the correct remote folder. Wait for the queue to finish before closing the application.
Find the WordPress installation directory
Do not assume the directory is named public_html. Hosts may use www, htdocs, httpdocs, or a domain-specific path such as domains/example.com/public_html/.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →The reliable test is to open a directory containing most or all of these:
Rank #3
- What You Get - 2 pack 64GB genuine USB 2.0 flash drives, 12-month warranty and lifetime friendly customer service
- Great for All Ages and Purposes – the thumb drives are suitable for storing digital data for school, business or daily usage. Apply to data storage of music, photos, movies and other files
- Easy to Use - Plug and play USB memory stick, no need to install any software. Support Windows 7 / 8 / 10 / Vista / XP / Unix / 2000 / ME / NT Linux and Mac OS, compatible with USB 2.0 and 1.1 ports
- Convenient Design - 360°metal swivel cap with matt surface and ring designed zip drive can protect USB connector, avoid to leave your fingerprint and easily attach to your key chain to avoid from losing and for easy carrying
- Brand Yourself - Brand the flash drive with your company's name and provide company's overview, policies, etc. to the newly joined employees or your customers
wp-admin/
wp-content/
wp-includes/
index.php
wp-config.php
That is the WordPress root. Uploading into a parent directory or another domain’s folder can produce a successful transfer while leaving the intended website unchanged.
Where WordPress files belong
Plugins
Extract the plugin ZIP on your computer and upload the resulting folder to wp-content/plugins/:
wp-content/plugins/example-plugin/
Do not normally leave the ZIP in plugins. When the transfer completes, open Dashboard → Plugins and activate it. WordPress documents this manual procedure at Manage Plugins.
Free tools Windows power users keep installed
One-click scans. No signup required.
Themes
Upload the extracted theme folder directly into wp-content/themes/:
Rank #4
- GOOD VALUE PACKAGE - 1 Pack 32GB Memory Stick USB 2.0 Flash Drives with great cost performance and high quality.
- BIG CAPACITY - The available capacity: 29.10GB-29.8GB, You can save the data of movies, music, photos, designs, programs, manuals, handouts in a high speed.Good performance in digital data storing, transferring and sharing with families, friends, workmates, clients and machines.
- EASY TO USE & PLUG AND WORK - Support windows 7 / 8 / 10 / Vista / XP / 2000 / ME / NT Linux and Mac OS, Compatible with USB2.0 and below.
- TWISTTURN DESIGN & EASY CARRY - The metal clip rotates 360° round the ABS plastic body which with rubber oil skin feeling finish. The capless design can avoid lossing of cap, and providing efficient protection to the USB port.
- WARRANTY & SUPPORT - SIMMAX logo is laser printed on the USB connector surface, our products are of good quality and we promise that any problem about the product within one year since you buy.
wp-content/themes/example-theme/
Activate it from Dashboard → Appearance → Themes. Keep a child-theme or staging workflow in mind before changing a production theme.
Media
Ordinary images and documents should normally be added through Media → Add New. WordPress commonly stores uploads under wp-content/uploads/, often in year/month folders such as wp-content/uploads/2026/08/, but multisite, plugins, hosts, and managed platforms can change this.
Copying an image into that directory does not automatically create a Media Library attachment. The file may have a URL while remaining unregistered in WordPress; it may need an import or synchronization process (WordPress.com file and permission guidance).
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Verification and custom files
Put a verification file in the site root only when the verifying service instructs you to. Custom CSS, JavaScript, fonts, and PHP belong in the specifically documented child-theme, custom-plugin, or assets directory. Never invent a destination because its name seems logical.
Best Value
- 【16GB Flash Drive】USB flash drives with 16GB capacity, meet your needs of daily use on work, school, home and travelling for photos, music, videos, files storage and transfer. IMEASON thumb drives can be used to store different files, easy to data backup.
- 【Metal Swivel Cap Design】USB thumb drive is metal swivel cover provides extra protection for the usb thumbdrive connector, no usb drive cap to lose; keychain design makes it easier to carry without worrying lose it.
- 【Wide Compatibility】USB drive supports Windows 7/8/10/11 / Vista / XP / Unix / 2000 / ME / NT Linux and Mac OS, also Supports USB 2.0 and 1.1 ports. USB Stick support TV, desktop, notebook computer, car, audio and other device. The USB Memory Stick is your great data storage and transfer companion with traveling and working.
- 【Easy to use】usb memory stick is plug and play without any software installation. Just simply plug the Flashdrive into the port of your USB-compatible devices such as computer, laptop to start data storage or transmission.
- 【What You Get】16 GB USB Flash Drive Thumb Drive, The default format of the usb storage flash drive is FAT32.
High-risk files
Back up before touching wp-config.php, .htaccess, or WordPress core files. Download the original before replacing it, and remember that hidden files may be hidden by default in a client. WordPress identifies these as important backup targets (file backup guidance).
Complete upload procedure
- Back up first. Preserve relevant files and confirm that a database backup exists; files alone are not a complete WordPress backup.
- Prepare the local copy. Obtain plugins and themes from a trusted official source, scan untrusted files, and extract ZIP archives unless documentation says otherwise.
- Connect over SFTP. Use the host’s protocol, address, port, and credentials.
- Confirm the root. Look for
wp-admin,wp-content, andwp-includes. - Open the destination. Use
wp-content/plugins/,wp-content/themes/, or the documented location for another file. - Drag the item across. Copy from the local pane to the remote pane.
- Wait for completion. Review the queue’s failed-transfer list and retry failures.
- Check nesting. A plugin should usually look like
plugins/plugin-name/plugin.php, notplugins/plugin-name/plugin-name/plugin.php. - Test. Activate only after the complete folder is present, then check the dashboard, relevant pages, browser URL, and logs.
- Disconnect securely. Close the session and remove saved credentials on shared computers.
How to verify the upload
- The expected remote folder and filename are visible.
- Remote size and filename match the local copy.
- The queue reports success, with no failed items.
- The plugin or theme appears in its WordPress administration screen.
- A file intended to be public opens at its correct URL.
- The changed page works without a PHP fatal error, and logs show no new related error.
A successful transfer proves only that bytes reached the server. Wrong location, permissions, incompatible code, caching, or malformed files can still prevent the feature from working.
Troubleshooting common failures
| Symptom | Checks and safe response |
|---|---|
| Could not connect | Verify SFTP versus FTP, host, port, account status, firewall/VPN restrictions, and any host IP allowlist. Confirm values with the host before changing random settings. |
| Authentication failed | Check hosting credentials, logon type, SSH-key authorization, and whether the account is enabled. WordPress dashboard credentials may be unrelated. |
| Permission denied | Confirm the directory and account ownership, then ask the host for expected permissions. Never treat 777 as a normal fix; excessive permissions can enable malicious uploads (WordPress permissions guidance). |
| Plugin is not visible | Ensure the extracted folder is directly inside wp-content/plugins/, contains its expected main file, and transferred completely. Check compatibility with the WordPress and PHP versions. |
| Theme is missing | Place the extracted folder directly inside wp-content/themes/; do not upload only a ZIP or create an extra nested folder. |
| URL returns 404 | Check the domain’s directory, exact capitalization, public URL, rewrite/server rules, and whether the file is intended to be public. |
| Image is absent from Media Library | Direct file copying and attachment registration are separate. Import or synchronize the file if the platform requires it. |
| Site shows a critical error | Preserve a copy, connect through SFTP or File Manager, rename the new plugin folder to something such as plugin-folder-disabled/, and reload. For a theme, rename it only if an alternative theme is available. Review PHP logs and restore the original or backup. |
| Transfer is incomplete | Retry failed queue items, compare local and remote contents, upload smaller batches, or use a host File Manager to extract a ZIP. Do not activate incomplete code. |
Security rules for file transfers
- Prefer SFTP; use FTPS when that is the host’s supported encrypted option; avoid plain FTP.
- Download clients from their official sites, including FileZilla or Cyberduck.
- Use separate, limited SFTP accounts where the host supports them, and never share passwords or private keys.
- Do not loosen permissions casually or use
chmod -R 777. WordPress warns that overly permissive permissions can allow attackers to upload or modify malicious code (hardening guidance). - Back up before overwriting production files, and keep an original copy for rollback.
- Remove unused accounts and saved credentials, especially on shared computers.
Alternatives and the WordPress.com distinction
Use the dashboard uploader for normal plugins, themes, and media. Use a hosting File Manager for a one-off operation or server-side ZIP extraction. Developers may use SSH and WP-CLI, but those tools require command-line knowledge and host access. For repeated changes, a staging site and deployment workflow is safer than editing production files directly.
On self-hosted WordPress.org sites, the hosting provider controls SFTP access, directories, permissions, backups, and restrictions. WordPress.com access and managed components are platform-specific; changing managed files or permissions can affect included updates and support. Follow that platform’s documentation before modifying them.
Quick Recap
Final checklist
- SFTP or the host’s encrypted alternative is selected.
- Host, port, username, and key/password came from the hosting provider.
- The directory contains
wp-admin,wp-content, andwp-includes. - The extracted folder is in the documented destination without accidental nesting.
- The transfer queue has no failures.
- A backup and rollback copy are available.
- The dashboard, public URL, and relevant site function have been tested.
- The connection is closed and temporary credentials are secured.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

