General advice on installing updates?

I hadn’t thought of that, and it made me wonder whether even my Omeka permissions (on Reclaim) were safe. They all seem to be 755 (directories) or 644 (files), which I take it is OK. But I’m confused about permissions in general, and after reading your explanation here I bet many other people get it wrong too.

I mentioned Piwigo as being very easy to update, and many of the files in my installation are 755. Sounds like you’re suggesting that (a) those facts are related and (b) that’s bad. CMS Made Simple (the one that updates via a PHAR file) is on the same server, and all files seem to be 644.