WordPress backup plugins: how to choose one and test your restores
WordPress backup plugins: how to choose one and test your restores

WordPress has no built-in backup system. To recover from a bad update, a hack or a host failure, you need a copy of two things: the database (posts, pages, settings, orders, users) and the files (themes, plugins, uploads and configuration). The official documentation is blunt about it: "You need both to be able to fully restore a typical WordPress site."
A backup plugin automates those copies and, ideally, sends them somewhere other than your server. Some plugins run entirely on your host and push archives to cloud storage; others are services that pull the backups to their own infrastructure. Your host may already back up your site, which changes what you need.
The part most people skip is the restore. A backup you have never restored is a hope, not a plan. This guide covers what to back up, what your host may already do, how to evaluate backup plugins, and how to test a restore. It is a neutral guide, not a ranking.
Key Takeaways
- A complete WordPress backup includes both the database and the files; one without the other will not fully restore a site.
- The WordPress documentation suggests keeping 3 to 5 recent backups in different locations, such as the server, cloud storage and a local copy.
- Backups stored only on the same server as the site can be lost with it.
- Plugins differ in where backups run (your server or the vendor's), incremental support, storage destinations and restore options.
- Busy stores and membership sites need more frequent or real-time backups than brochure sites.
- Test a full restore on staging at least once a year, and after any major change to your setup.
What a WordPress backup must include
According to the WordPress backup documentation, there are two parts: the database and the files.
- Database: all content, comments, users, settings, plugin data and, on WooCommerce sites, orders and customers.
- Files: the wp-content folder (themes, plugins, uploads), wp-config.php and any custom files such as .htaccess. WordPress core files can be re-downloaded, but including them makes a restore simpler.
The same page recommends keeping at least three to five recent backups, with copies in different locations, for example one on the host, one in cloud storage and one downloaded locally. It also suggests occasionally making a manual backup on top of automatic ones "to guarantee that the process is working".
Check what your host already does
Many hosts take daily backups. Before buying a plugin, find out:
- How often backups run and how long they are kept.
- Whether they are stored on separate infrastructure from your server.
- Whether you can restore yourself, and whether you can restore only the database or a single folder.
- Whether restores cost extra.
Host backups are useful but often live with the same provider. If the host account is suspended, compromised or closed, you may lose access to both the site and its backups. An independent off-site copy covers that risk. On WordPress.com, real-time backups and one-click restores are included on the Business, Commerce and Enterprise plans.
Types of backup plugins
Plugins that run on your server
These create archives on your host and can send them to cloud storage you control. UpdraftPlus is a widely used example; its free version can schedule backups and send them to Dropbox, Google Drive, Amazon S3 (or compatible), FTP, email and others. They are inexpensive but use your server's resources while running, which can matter on large sites or cheap hosting.
Service-based backups
BlogVault and Jetpack VaultPress Backup copy your site to the vendor's infrastructure. BlogVault's listing says "All backups are stored offsite" and that it backs up incrementally, changing only what changed since the last run. These usually cost more but put less load on your server and make restores possible even when the site is down. We look at where vendor-hosted storage is heading in backup plugins with their own cloud storage.
Migration-first tools
Duplicator and All-in-One WP Migration package an entire site into an archive you can install elsewhere. They are widely used for moving sites and can also act as backups. In Duplicator, scheduled backups and cloud destinations such as Dropbox and Google Drive are Pro features; the free version stores packages locally or in Duplicator's own cloud service.
How to evaluate a backup plugin
- Completeness. It must capture the database and all of wp-content, including custom tables created by plugins.
- Off-site storage. Check which destinations are available on the tier you will pay for, and that backups do not stay only on your server.
- Frequency and incremental backups. Stores and active sites may need hourly or real-time backups. Incremental backups (only changes) reduce server load; in UpdraftPlus they are a Premium feature.
- Retention. How many copies, for how long. A 30-day history lets you recover from a problem you did not notice right away.
- Restore options. One-click restore, partial restore (database only, a single plugin), and restore when the site will not load.
- Security. Encryption at rest, access controls on the storage account and two-factor authentication on the vendor dashboard.
- Maintenance and support. Check "last updated", "tested up to" and forum response times on WordPress.org.
- Lock-in. Check whether you can download a standard archive and restore it without the vendor, should you stop paying.
Well-known backup plugins
Listed in no particular order. Install bands are from WordPress.org and pricing from each vendor's site, as of October 2026. Prices are annual unless noted and often show a first-year discount.
| Plugin | Approach | Active installs (WordPress.org) | Pricing model (vendor site) |
|---|---|---|---|
| UpdraftPlus | Runs on your server; scheduled backups to many cloud destinations | 4+ million | Free; Premium from $70/yr (Personal, 2 sites) to $399/yr (Gold) |
| Jetpack VaultPress Backup | Service-based backups managed by Automattic | 20,000+ (standalone plugin); Jetpack plugin 3+ million | Paid; included in Jetpack Security, $19.95/mo regular (billed yearly) |
| BlogVault | Service-based, incremental, off-site backups with staging and test restore | 80,000+ | Paid per site: Personal $99/yr, Business $299/yr, WooCommerce $499/yr; 7-day free trial |
| Duplicator | Site packages for backup and migration | 1+ million | Free; Pro plans $79 to $599/yr at regular price |
| All-in-One WP Migration | Export and import whole sites as one file | 5+ million | Free on WordPress.org |
| WPvivid | Backup, migration and staging | 900,000+ | Free on WordPress.org |
| BackWPup | Scheduled backups to various destinations | 400,000+ | Free on WordPress.org |
Sources: UpdraftPlus pricing, Jetpack pricing, BlogVault pricing and Duplicator pricing. The older standalone "Jetpack VaultPress" plugin is a separate, legacy listing; VaultPress Backup is now part of Jetpack.
How often should you back up?
Match the schedule to how much work you could afford to lose:
- Brochure sites that change monthly: weekly backups, plus a manual backup before updates.
- Blogs and content sites: daily database backups; files weekly or daily depending on uploads.
- WooCommerce stores and membership sites: real-time or at least hourly database backups, because orders and sign-ups change constantly. Restoring last night's backup on a store can erase today's orders.
Always take a fresh backup before core, theme or plugin updates. Our article on automating backups in a maintenance plan covers scheduling in more detail.
How to test a restore
- Create a staging site or a local copy (many hosts offer one-click staging).
- Restore your most recent backup to it, using the same method you would use in an emergency.
- Check that the home page, a few posts, media files, forms and logins work.
- On stores, check recent orders, products and customer accounts.
- Time the process and note any steps that needed extra access (host panel, SFTP, database credentials).
- Write those steps down and store them somewhere other than the website.
Some services make this easier: BlogVault's FAQ describes a test restore that validates a backup without touching the live site. Whatever tool you use, the point is the same: prove the restore works before you need it. Our website backup and recovery guide covers recovery planning beyond WordPress.
Common backup mistakes
- Keeping backups only on the server. If the server fails or is compromised, the backups go with it.
- Backing up files but not the database, or the reverse. You need both for a full restore.
- Short retention. Malware and data problems are often found weeks later. If you only keep seven days of backups, every copy may already contain the problem.
- Restoring over a live store without a plan. Restoring a database on WooCommerce can remove orders placed since the backup. Export recent orders first, or restore to staging and move only what you need.
- Letting a paid license lapse. Check whether existing backups stay available and whether scheduled jobs stop.
- Nobody knows how to restore. Write down the steps, the logins required and who is responsible, and keep that document outside the website.
Conclusion
Back up both the database and the files, keep several copies in more than one place, and match frequency to how fast your site changes. Choose between server-run plugins and backup services based on site size, budget and how you want to restore. Then test a restore. For a full backup strategy beyond plugins, see our guide to WordPress backups and the WordPress hub. If you want backups, updates and restore tests handled for you, eSEOspace offers website maintenance services.
Frequently asked questions
Does WordPress back itself up?
No. Core has no backup feature. Your host may back up the server, and plugins or services can back up the site.
Are my host's backups enough?
They are a good first layer. Because they usually live with the same provider, an independent off-site copy protects you if the hosting account itself is lost or compromised.
Where should I store backups?
Somewhere other than the web server. The WordPress documentation suggests copies in different locations, such as the host, cloud storage and a local computer.
Can a migration plugin be used for backups?
Yes. Tools such as Duplicator and All-in-One WP Migration create full-site archives. Check whether scheduling and cloud storage are included in the version you use.
How often should I test restores?
At least once a year, and after changing hosts, backup tools or site structure. Stores should test more often because order data makes restores more delicate.
Put this into action with eSEOspace
We help businesses grow with website design that actually performs. Explore the services behind this guide:
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!





