An SEO company asks for FTP because several of the highest-impact technical fixes live in files your CMS dashboard never shows you: robots.txt.htaccess, raw server logs, theme templates, and the junk left behind by a previous developer. A WordPress login covers maybe 70% of the work on a typical site. The remaining 30% is file-level, and that is where rankings often get stuck.

Below is a plain breakdown of what an agency actually does with that access, when the request is unnecessary, and how to hand over credentials without handing over your whole business.

What FTP Does on a Web Server

FTP (File Transfer Protocol) is a standard for moving files between a local computer and a remote server. It has been around since RFC 959 was published in 1985, which tells you something about both its durability and its age. Connecting with an FTP client shows the server’s directory tree the way a file explorer shows folders on your laptop.

That view matters because a content management system deliberately hides most of it. Your dashboard lets you publish a page; it rarely lets you read the error log, edit a redirect rule, or delete a 400MB backup file sitting in the public root where anyone can download it.

Five Jobs That Genuinely Require File-Level Access

When an agency says it needs FTP access, the work usually falls into one of these buckets:

  • robots.txt edits. A single misplaced Disallow line can de-index an entire section. Google’s own robots.txt documentation notes the file must sit at the root of the host, and on many setups that means editing it on the server rather than through a plugin.
  • .htaccess and redirect rules. Server-level 301s are faster and more reliable than plugin-based redirects, especially during a migration involving a few thousand URLs.
  • Raw server log retrieval. Logs show exactly which URLs Googlebot requested, how often, and what status codes it got back. That data cannot be reconstructed from analytics, which is why log file analysis is still a specialist task.
  • Template and theme edits. Heading hierarchy, canonical tags, schema markup, lazy-loading behavior and image sizing often live in PHP template files, not in any settings panel.
  • Cleanup of orphaned files. Old staging folders, duplicate sitemaps, exposed database dumps and leftover test directories get indexed more often than people expect.

None of that is exotic. It is routine maintenance that most site owners never see because nobody shows them the file tree.

When an SEO Company Does Not Need FTP

Plenty of agencies ask for server credentials out of habit. If the scope of work is content production, keyword research, local listings, link acquisition or reporting, a CMS editor account is enough. Be skeptical of a blanket request before anyone has looked at your setup.

Reasonable alternatives that cover a lot of ground:

  • A WordPress Administrator or Editor role for on-page work, metadata and internal linking.
  • Google Search Console and Google Analytics access for diagnostics and verification.
  • Google Tag Manager for tracking scripts, including conversion tags used by paid advertising campaigns that need to fire alongside organic tracking.
  • A staging environment where template changes get tested before anything touches the live site.

A good agency will tell you which of these it actually needs and will accept read-only access for the diagnostic phase. If the answer to “what specifically will you change” is vague, that is worth pausing on.

Use SFTP, Not Plain FTP

Classic FTP sends your username and password as plain text across the network. On a shared coffee shop connection, that is a genuine exposure. Nearly every host supports SFTP (SSH File Transfer Protocol) on port 22 or FTPS (FTP over TLS), both of which encrypt the session.

Ask your hosting provider which one is enabled before creating an account for anyone. Most managed platforms default to SFTP now, and some, including many managed WordPress hosting environments, replace FTP entirely with SSH keys or a web-based file manager with activity logging.

How to Grant Access Without Losing Control

You are not obligated to share the master credential your developer uses. Create a separate account scoped to the job:

  1. Make a new FTP or SFTP user rather than sharing an existing login, so activity is attributable to one person.
  2. Restrict the home directory to the site folder (public_html or similar) so the account cannot reach other domains on the same server.
  3. Take a full backup first, including the database, and confirm you can restore it. Any host worth paying keeps daily snapshots for 14 to 30 days.
  4. Send credentials through a secure channel such as a password manager share link or a one-time secret tool, never in a plain email thread.
  5. Set a review date. Thirty to ninety days is typical for an active technical engagement; disable the account when the project ends.

Ask the agency to document every file it modifies. A short change log with dates and filenames costs them ten minutes and saves hours of guesswork if something breaks six weeks later.

What Delays Look Like When Access Is Withheld

Refusing server access does not stop the work, it just routes it through someone else. In practice that means the agency writes a ticket, your developer schedules it, and a change that takes four minutes directly takes five to ten business days round trip. Across a technical audit with 25 to 40 recommended fixes, that gap can stretch a two-week implementation into an entire quarter.

The cost compounds during migrations. If redirects go live late, you can watch organic sessions fall 30% or more while the old URLs serve 404s and Google reprocesses the site. Our team has rebuilt rankings after botched launches often enough to know that access friction is usually the root cause, not strategy.

Questions to Ask Before You Hand Over Credentials

A short vetting conversation separates a careful partner from a careless one. Worth asking:

  • Which specific files do you expect to edit, and why?
  • Do you work on staging first, or directly on production?
  • Who on your team will have the credentials, and how are they stored?
  • What is your rollback plan if a change breaks the site?
  • Will you provide a written change log?

Any agency doing this professionally answers those in a sentence or two each. When we onboard a client through our SEO team in Summerville, SC, access requests are itemized in the proposal so nobody is guessing what a login is for.

Frequently Asked Questions

What Is the Main Purpose of FTP?

FTP exists to move files in both directions between a local computer and a remote server, using a control connection on port 21 and a separate data connection for the transfer itself. For a website, that means uploading templates, plugins and images, downloading logs and backups, and editing configuration files that no dashboard exposes.

What Are the Disadvantages of Using FTP?

The biggest drawback is that standard FTP transmits usernames, passwords and file contents unencrypted, so anyone monitoring the connection can read them. It also uses two separate ports, which complicates firewalls, offers no built-in integrity checking, and gives a broad account more reach than most tasks require. SFTP solves most of this by running the whole session over SSH.

Why Use FTP Instead of HTTP?

FTP is built for two-way transfers and bulk operations, while HTTP is primarily designed to retrieve a resource and render it. With an FTP client you can browse directories, upload hundreds of files in one queue, resume interrupted transfers, and change file permissions, none of which standard HTTP handles natively.

Is FTP Faster Than SMB?

Over the open internet or any high-latency link, FTP is typically faster because SMB is a chatty protocol that requires many round trips per file. On a local network with low latency, SMB performs comparably and is often more convenient since shares mount like a local drive. For transferring to a web host, FTP or SFTP is the practical choice.

Should I Give My SEO Agency Admin Access Too?

Give CMS admin access only if the scope includes plugin management, redirects or template changes; otherwise an Editor role covers content work with less risk. Pair it with the naming and structural decisions covered in our guide to naming a company for SEO, since early structural choices shape what needs editing later.

Talk to SEO Locale About Your Technical Setup

If you are not sure what access your site actually requires, we will review your hosting and CMS first and tell you exactly which credentials matter. Contact SEO Locale for a technical review and a clear list of what we would change and why.

Share Article

Nick Quirk

Nick Quirk is the COO & CTO of SEO Locale. With years of experience helping businesses grow online, he brings expert insights to every post. Learn more on his profile page.

Google Partner Semrush certified agency partner badge Top Web Development Company

Montgomeryville Office

601 Bethlehem Pike Bldg A
Montgomeryville, PA 18936

Philadelphia Office

250 N Christopher Columbus Blvd #1119
Philadelphia, PA 19106

seo locale

We're your premier digital marketing agency in Philadelphia. We've been providing results both locally and nationally to all of our clients. Honored to win the best of Philadelphia for web design 2020. We have three offices located in Montgomeryville, Jenkintown & Philly. Our success is your success.

Copyright © 2026. SEO Locale, LLC, All rights reserved. Unless otherwise noted, SEO Locale, the SEO Locale logo and all other trademarks are the property of SEO Locale, LLC.. Philadelphia Digital Marketing Company.