WordPress Backups: What to Back Up, How Often and How to Restore
WordPress Backups: What to Back Up, How Often and How to Restore

A WordPress backup is only useful if it contains everything needed to rebuild the site, is stored somewhere the problem cannot reach, and has actually been restored at least once. Many site owners discover the gaps in their backups on the worst possible day: after a hack, a failed update or a hosting account that disappears.
The short answer: back up both the WordPress files and the database, automatically, on a schedule that matches how often your site changes. Keep several recent copies in more than one location, including at least one off your web server. Then test a restore before you need one.
The official WordPress documentation gives a practical baseline. It suggests weekly backups for smaller sites with few posts and daily backups for high-activity sites, and it recommends keeping at least 3 to 5 recent backups stored in different places, for example one on the server, one in cloud storage and one on a local computer.
This guide explains what to include, how often to run backups, where to keep them, how host and plugin backups compare, and how to test a restore.
Key Takeaways
- A complete backup has two parts: the WordPress files (including wp-content and wp-config.php) and the database.
- Match frequency to change: weekly can work for a brochure site, while stores and membership sites usually need daily or more frequent database backups.
- Keep several versions in at least two locations, and make sure one copy is off the web server and outside the hosting account.
- Host backups and plugin backups solve different problems; many businesses use both.
- A backup you have never restored is a guess: schedule a test restore to a staging site.
What a WordPress backup must include
The WordPress backup documentation splits a site into two parts.
The files
These are everything in your WordPress directory on the server:
- wp-content: your themes, plugins and the uploads folder (images, PDFs, media). This is the irreplaceable part. Uploads in particular cannot be downloaded again from anywhere.
- wp-config.php: database credentials, security keys and custom constants.
- .htaccess (on Apache servers) and any other server configuration files in the web root.
- WordPress core files: these can be downloaded fresh from WordPress.org, but including them makes a full restore simpler.
The database
The database (usually MySQL or MariaDB) holds posts, pages, users, comments, settings, menus, widget settings, and for WooCommerce, products, orders and customers. A file-only backup gives you a site with no content. A database-only backup gives you content with no images, theme or plugins. You need both, taken close together in time so they match.
What a backup does not cover
- Email accounts hosted with your web host are usually separate.
- DNS records live with your registrar or DNS provider. Keep a written or exported copy.
- Off-site services such as payment processors, CDN settings, form services and email marketing lists.
- Licenses for premium plugins and themes. Keep a list of what you own and where to download it.
How often should you back up?
The right frequency depends on how much data you can afford to lose. Ask: if the site broke right now, what is the oldest backup I could accept?
| Type of site | How often content changes | A sensible starting schedule |
|---|---|---|
| Brochure or small business site | A few edits a month | Weekly full backup, plus a manual backup before updates |
| Active blog or publisher | Several posts a week, comments | Daily database, weekly or daily files |
| WooCommerce store | Orders around the clock | Daily at minimum; real-time or hourly database backups if orders are frequent |
| Membership, LMS or booking site | User data changes constantly | Daily at minimum; real-time options worth considering |
Two rules apply to every site. First, take a manual backup before every update, theme change, migration or major edit. Second, the database usually changes more often than the files, so many tools let you back it up more frequently.
For stores, think carefully about restoring. Restoring yesterday's database overwrites today's orders. Real-time or incremental backup services exist partly to reduce this gap. Our guide to automating website backups goes deeper on scheduling.
Where to store backups
A backup stored only in the same hosting account as the site shares the site's risks. If the account is hacked, suspended, deleted or the server fails, the backup can go with it. The official documentation recommends copies in different locations, and a common rule of thumb is to keep:
- Several versions, not just the latest. Malware or a bad change may go unnoticed for days, so the most recent backup can already be infected or broken.
- At least one copy off the server, in cloud storage such as Amazon S3, Google Drive, Dropbox or a backup service's own storage.
- Separate credentials, so someone who gets into your WordPress admin cannot also delete your backups.
Also consider privacy. Backups contain user accounts, email addresses and, on stores, order details. Store them in private, access-controlled locations, and delete old copies on a schedule.
Host backups vs plugin backups vs backup services
Host backups
Many hosts take automatic daily backups, especially managed WordPress hosts. They are convenient and run at the server level, so they still work if WordPress itself is broken. The drawbacks: retention may be short, the backup is often stored with the same company, and downloading a copy can be awkward or, on some plans, cost extra. Read your host's terms for how long backups are kept and whether you can restore a single file or only the whole site. Our guide to managed WordPress hosting covers what is typically included.
On WordPress.com, real-time backups and one-click restores are listed on the Business, Commerce and Enterprise plans as of October 2026; automated backups are not part of the lower paid plans.
Backup plugins
Plugins run inside WordPress and send backups to storage you choose. They are portable between hosts and often double as migration tools. The drawbacks: they use your server's resources while running, they can time out on large sites with cheap hosting, and if the site is completely broken you may need to restore manually.
Backup services
Some products, such as Jetpack VaultPress Backup and BlogVault, process backups on their own infrastructure and store them off your server. They usually cost more but reduce load and simplify restores.
Common WordPress backup tools
This is a neutral overview, not a ranking. Install counts are bands from WordPress.org and prices are from each vendor's site, both as of October 2026. Check the vendor page before buying, since prices change.
| Tool | What it is | Active installs (WordPress.org) | Pricing model |
|---|---|---|---|
| UpdraftPlus | Scheduled backups to remote storage, with restore and migration | 4+ million | Free plugin; Premium from $70/yr (2 sites) |
| All-in-One WP Migration and Backup | Export and import of full sites, widely used for migrations | 5+ million | Free plugin with paid extensions |
| Duplicator | Packages a site into an archive for backup or migration | 1+ million | Free plugin with a paid Pro version |
| Jetpack VaultPress Backup | Off-site backups processed by Automattic, part of Jetpack | Jetpack plugin: 3+ million | Included in Jetpack Security ($19.95/mo regular, billed yearly) and Complete |
| BlogVault | Off-site incremental backups with staging and restore | 80,000+ | Per site per year, from $99 (Personal) |
| WP STAGING | Backups, restore and staging copies | 100,000+ | Free plugin with a paid Pro version |
When comparing tools, check: where backups are stored, whether storage is included, incremental vs full backups, restore steps when the site is down, retention length, and how the tool handles very large uploads folders. Recent security history matters too, since backup and migration plugins handle your entire site. Keep them updated like any other plugin.
How to test a restore
The WordPress documentation suggests occasionally backing up your automatic backups with a manual one to confirm the process works. Going one step further, a real restore test is the only proof. A simple routine, every quarter or after you change backup tools:
- Pick a recent backup at random, not the newest one.
- Restore it to a staging site or a local copy, never over the live site.
- Check that pages load, images display, you can log in, forms submit and, for stores, recent orders and products are present.
- Time how long the restore took. That is your realistic downtime if disaster strikes.
- Write down the exact steps, logins and storage locations, and keep that note somewhere other than the website.
If the restore fails, you found the problem on a quiet day instead of during an emergency.
Manual backups for developers
If you have SSH access, WP-CLI makes quick manual backups easy. wp db export runs mysqldump with the credentials in wp-config.php and writes the database to a SQL file. Pair that with an archive of wp-content and wp-config.php. Store both off the server. This is a good habit before running risky commands, such as a database search-replace or a major plugin migration.
Backups and security incidents
After a hack, restoring a backup is often the fastest way back online, but only if you restore a clean copy and close the hole that let the attacker in. Otherwise the site gets reinfected. That means updating the vulnerable plugin, changing passwords and salts, and checking for unknown admin users. See our guides to a hacked WordPress site and website backup and recovery.
Conclusion
Good WordPress backups are complete (files and database), automatic, frequent enough for how your site changes, stored in more than one place, and proven by a test restore. Combining host backups with an off-site plugin or service covers most risks for most businesses. Explore more guides in our WordPress hub. If you would rather not manage this yourself, eSEOspace includes monitored backups in its website maintenance services.
Frequently asked questions
Are my host's backups enough?
Sometimes, but check three things: how long backups are kept, whether you can download a copy, and whether they are stored somewhere independent of your hosting account. If the answer to the last one is no, add an off-site backup through a plugin or service.
How often should I back up WordPress?
The official documentation suggests weekly for smaller, low-activity sites and daily for high-activity sites. Stores and membership sites often need more frequent database backups, and every site should get a manual backup before updates.
Do I need to back up WordPress core files?
Core files can be downloaded again from WordPress.org, so they are the least critical part. The essentials are wp-content (themes, plugins, uploads), wp-config.php and the database. Including core simply makes a full restore faster.
How many backups should I keep?
The WordPress documentation recommends at least 3 to 5 recent backups in different locations. Keeping older versions too, such as a monthly copy, helps when a problem like malware went unnoticed for weeks.
Can I restore a backup to a different host?
Yes. Most backup plugins can restore to a new server, which is how many site migrations work. If the domain or paths change, the database will also need its URLs updated, ideally with a tool that handles serialized data.
Put this into action with eSEOspace
We help businesses grow with website design that actually performs. Explore the services behind this guide:
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!
On this page





