Development

How to Back Up a WordPress Site

What a WordPress backup must include, the four realistic ways to take one, how often, and the restore test almost everybody skips.

A backup is the difference between a bad hour and a rebuild. Most small business WordPress sites either have no backup at all, or have one nobody has ever tested, which in practice is the same thing.

This is what a WordPress backup actually needs to include, the realistic ways to take one, and the step almost everybody skips.

What a WordPress backup has to contain

WordPress keeps your site in two separate places, and a backup of one without the other is not a backup.

PartWhat lives thereWhat happens if you lose it
The databaseYour pages, posts, settings, users, commentsYour content is gone. The design remains, with nothing in it
The filesThemes, plugins, and everything in uploads, meaning your imagesYour design and every photo is gone

When people say they lost their site, it is usually because they had one of these and not the other.

The four realistic options

1. Your host does it

Most decent hosting includes automatic daily backups. This is the least effort and, for most small business sites, genuinely enough.

  • Check it exists. Log in to your hosting control panel and find the backups section.
  • Check how far back it goes. Some keep 30 days, some keep 7, some keep 1. Seven days is thin, because problems often go unnoticed for longer than that.
  • Check where it is stored. A backup on the same server as the site is not much use if the server is the problem.
  • Check you can restore it yourself, or that support will, and how quickly.

2. A backup plugin

Plugins such as UpdraftPlus, BackWPup and Duplicator take scheduled backups and send them somewhere else, typically Google Drive, Dropbox or Amazon S3.

  • Send the backup off site. That is the entire point.
  • Set the schedule to match how often the site changes. A brochure site can be weekly, a shop should be daily.
  • Include both database and files. Some plugins default to database only.
  • Keep several versions. If a problem went unnoticed for a fortnight, a single overwritten backup will have the problem in it.

3. Manual, occasionally

Worth doing before anything risky, such as a major update or a theme change. Export the database from phpMyAdmin, download the wp-content folder over FTP, and keep both together with the date in the filename. It is fiddly, which is why it should be a supplement rather than your only plan.

4. Somebody does it for you

The option most small businesses actually want, because backups are a task that only matters when it has been done consistently for months. It is part of what a website maintenance plan covers, along with the updates that create most of the need for one.

How often should you back up?

Type of siteSensible frequencyKeep for
Brochure site, rarely changesWeekly30 days
Site with a blog or regular updatesDaily30 days
Online shopDaily at minimum, ideally continuous30 to 90 days
Before any major updateAn extra one, manuallyUntil you are confident

The keep-for column matters as much as the frequency. Daily backups that overwrite each other give you one day of protection, not thirty.

The step almost everybody skips

Test the restore.

An untested backup is a belief, not a safety net. We have seen backups that ran faithfully for two years and turned out to contain only the database. We have seen files that could not be opened. We have seen restores that needed a login nobody had.

Test it properly at least once:

  1. Restore to a staging site or a local copy, never over your live site.
  2. Check the pages are there, the images load, and the menus work.
  3. Log in. Confirm the users came across.
  4. Time it. Knowing a restore takes twenty minutes rather than a day changes how you feel about a bad morning.

What a backup will not save you from

Worth being clear, because backups get treated as a cure for everything.

  • A lapsed domain. A perfect backup of a site nobody can reach is no help. See domain name renewal.
  • A problem you did not notice. If a hack sat quietly for six weeks, six weeks of backups contain it.
  • Losing your logins. A backup restores the site, not access to the hosting account.
  • Being offline meanwhile. A backup shortens an outage, it does not prevent one.

That last point is why updates, monitoring and backups belong together rather than being treated as three separate chores.

A five minute check you can do now

  1. Log in to your hosting and find the backups section. Does one exist?
  2. What is the date on the most recent one?
  3. How many older ones are kept?
  4. Is it stored somewhere other than the same server?
  5. Do you know how to restore it, or who would?

Any no, or any not sure, is worth fixing this week. It is the cheapest insurance a website has.

This is one item on our website audit checklist, which covers the rest of what quietly goes wrong on a site nobody is watching. If you would rather it was simply somebody’s job, tell us about your site and we will tell you what it needs.

Charlie Dean

Written by

Charlie Dean

Support & Care

Charlie looks after websites after launch, handling updates, fixes, and the day to day care plans.

More guides by Charlie Dean →

FAQs

You have four realistic options: rely on your hosting company's automatic backups, use a plugin such as UpdraftPlus or BackWPup to send scheduled copies to Google Drive or Dropbox, take manual copies before anything risky, or have someone do it as part of a maintenance plan. Whichever you choose, the backup must include both the database and the files.

Two things. The database holds your pages, posts, settings and users. The files hold your themes, plugins and everything in uploads, which means your images. A backup of one without the other is not a backup, and that is usually why people find they have lost a site they thought was protected.

A brochure site that rarely changes is fine weekly. A site with a blog or regular updates should be daily. An online shop should be daily at minimum. Just as important is how many you keep: aim for 30 days of history, because daily backups that overwrite each other give you one day of protection, not thirty.

For most small business sites, yes, provided you check four things: that it exists, how far back it goes, that it is stored somewhere other than the same server, and that you know how to restore it or who would. A backup sitting on the same server as the site is little use if the server is the problem.

Yes, and it is the step almost everybody skips. An untested backup is a belief rather than a safety net. Restore it once to a staging site or local copy, never over your live site, then check the pages, images, menus and logins all came across, and time how long it took.

A lapsed domain, because a perfect copy of a site nobody can reach does not help. A problem you did not notice, since if a hack sat quietly for six weeks then six weeks of backups contain it. Losing your hosting logins, because a backup restores the site rather than your access. And being offline in the meantime, as a backup shortens an outage rather than preventing one.

Free quote

Want a website that works as hard as you do?

Tell us what you do and we will come back with clear, honest next steps.

Get in touch