FTP sends passwords and files in clear text and needs extra ports for data. SSH already does its job with your keys and ~/.ssh/config aliases, so a web server needs no FTP daemon.
| Tool | Encrypted | Best at | Watch out for |
|---|---|---|---|
| FTP | No | Nothing today | Clear-text passwords |
| FTPS | TLS | Old hosting panels | Certificates, extra ports |
| scp | SSH | One file or a few | Recopies whole files |
| sftp | SSH | Scripted file work | No delta transfers |
| rsync 13,872 | SSH | Deploys and backups | A misplaced --delete |
Since OpenSSH 9.0 23,707 , scp speaks the SFTP protocol underneath (scp -v logs command sftp), and scp -O restores the legacy protocol for very old servers. sftp -b file runs a batch of put, ls and rm commands unattended. rsync sends only what changed. -a preserves permissions and times, -z compresses, -i itemizes each change, and --delete removes server files gone locally, so preview with --dry-run first.
rsync -azi --delete --exclude-from=site/.rsync-exclude --dry-run site/ web1:site/
rsync -az --delete --exclude-from=site/.rsync-exclude site/ web1:site/
echo 'body{margin:0;font-family:sans-serif}' > site/public/css/app.css
rsync -azi --delete --exclude-from=site/.rsync-exclude --stats site/ web1:site/ \
| grep -E '^<|speedup'created directory site cd+++++++++ ./ <f+++++++++ .rsync-exclude cd+++++++++ public/ <f+++++++++ public/hero.jpg ... <f.st...... public/css/app.css total size is 200,083 speedup is 482.13
The exclude file lists .git/, .env and storage/logs/, so secrets and logs never leave your machine. Mind the trailing slash: site/ copies the directory's contents, while site would create site/site on the server. On Windows, WinSCP 14,725 and FileZilla 4,598 speak SFTP with the same keys.