Sunday, July 26, 2026
HomeEveryday WordPressWordPress file manager in MyKinsta (no FTP client needed)

WordPress file manager in MyKinsta (no FTP client needed)


It is 11 p.m., something just broke on a client site, you need to rename a plugin folder to deactivate it, but wp-admin is down. So you open FileZilla, realize you never saved the SFTP credentials, dig around for the server details, configure a new connection, wait for the directory tree to load, and finally rename a single folder.

Five minutes of setup for a five-second task. It is a workflow that has not changed much in 20 years, and it has always had more friction than it needs.

With the MyKinsta file manager, you can now browse, edit, upload, move, copy, delete, and manage your WordPress files directly inside your hosting dashboard, no FTP client required.

This article walks you through everything the file manager can do and covers the real-world scenarios where it saves you the most time.

Why file access without FTP matters

FTP and SFTP are not going away. For heavy-duty tasks like bulk migrations, automated deployments, or syncing thousands of files, a dedicated client is still the right tool. But for most everyday tasks that come up while running a WordPress site, the setup overhead is disproportionate to the job.

There is also a security reason to avoid the most popular alternative. When people want quick file access without a client, the usual answer is a file manager plugin installed inside WordPress. It is convenient, but the security record is bad. WP File Manager, one of the most widely used options, had a zero-day vulnerability in 2020 that carried a CVSS score of 10.0, the maximum possible severity rating.

700,000 WordPress users affected by file manager plugin vulnerability.

It allowed unauthenticated attackers to upload PHP webshells directly to the server with no login required, and it was being actively exploited in the wild on the same day it was disclosed. Over 700,000 sites were running the affected versions, according to Wordfence, which reported the issue.

The core issue is not bad code in one plugin, but the category. Any plugin that needs to read, write, and delete files across your entire WordPress installation is doing something powerful, and powerful things inside WordPress inherit all of WordPress’s attack surface. If an attacker finds a way past the authentication layer, the file manager is exactly what they want to find waiting for them.

A hosting-level file manager sidesteps this entirely. It lives outside WordPress, is protected by your Kinsta account credentials, and adds nothing to the site’s attack surface.



Source link

RELATED ARTICLES
Continue to the category

LEAVE A REPLY

Please enter your comment!
Please enter your name here


Most Popular

Recent Comments