WordPress Backups: What to Back Up, How Often and How to Restore

By: Irina Shvaya | October 1, 2026
This guide is part of our WordPress resource hub: costs and hosting, the block editor, plugins, SEO and speed, security, maintenance, WooCommerce, development, comparisons and migrations.

A WordPress backup is only useful if it contains everything needed to rebuild the site, is stored somewhere the problem cannot reach, and has actually been restored at least once. Many site owners discover the gaps in their backups on the worst possible day: after a hack, a failed update or a hosting account that disappears.

The short answer: back up both the WordPress files and the database, automatically, on a schedule that matches how often your site changes. Keep several recent copies in more than one location, including at least one off your web server. Then test a restore before you need one.

The official WordPress documentation gives a practical baseline. It suggests weekly backups for smaller sites with few posts and daily backups for high-activity sites, and it recommends keeping at least 3 to 5 recent backups stored in different places, for example one on the server, one in cloud storage and one on a local computer.

This guide explains what to include, how often to run backups, where to keep them, how host and plugin backups compare, and how to test a restore.

Key Takeaways

  • A complete backup has two parts: the WordPress files (including wp-content and wp-config.php) and the database.
  • Match frequency to change: weekly can work for a brochure site, while stores and membership sites usually need daily or more frequent database backups.
  • Keep several versions in at least two locations, and make sure one copy is off the web server and outside the hosting account.
  • Host backups and plugin backups solve different problems; many businesses use both.
  • A backup you have never restored is a guess: schedule a test restore to a staging site.

What a WordPress backup must include

The WordPress backup documentation splits a site into two parts.

The files

These are everything in your WordPress directory on the server:

  • wp-content: your themes, plugins and the uploads folder (images, PDFs, media). This is the irreplaceable part. Uploads in particular cannot be downloaded again from anywhere.
  • wp-config.php: database credentials, security keys and custom constants.
  • .htaccess (on Apache servers) and any other server configuration files in the web root.
  • WordPress core files: these can be downloaded fresh from WordPress.org, but including them makes a full restore simpler.

The database

The database (usually MySQL or MariaDB) holds posts, pages, users, comments, settings, menus, widget settings, and for WooCommerce, products, orders and customers. A file-only backup gives you a site with no content. A database-only backup gives you content with no images, theme or plugins. You need both, taken close together in time so they match.

What a backup does not cover

  • Email accounts hosted with your web host are usually separate.
  • DNS records live with your registrar or DNS provider. Keep a written or exported copy.
  • Off-site services such as payment processors, CDN settings, form services and email marketing lists.
  • Licenses for premium plugins and themes. Keep a list of what you own and where to download it.

How often should you back up?

The right frequency depends on how much data you can afford to lose. Ask: if the site broke right now, what is the oldest backup I could accept?

Type of siteHow often content changesA sensible starting schedule
Brochure or small business siteA few edits a monthWeekly full backup, plus a manual backup before updates
Active blog or publisherSeveral posts a week, commentsDaily database, weekly or daily files
WooCommerce storeOrders around the clockDaily at minimum; real-time or hourly database backups if orders are frequent
Membership, LMS or booking siteUser data changes constantlyDaily at minimum; real-time options worth considering

Two rules apply to every site. First, take a manual backup before every update, theme change, migration or major edit. Second, the database usually changes more often than the files, so many tools let you back it up more frequently.

For stores, think carefully about restoring. Restoring yesterday's database overwrites today's orders. Real-time or incremental backup services exist partly to reduce this gap. Our guide to automating website backups goes deeper on scheduling.

Where to store backups

A backup stored only in the same hosting account as the site shares the site's risks. If the account is hacked, suspended, deleted or the server fails, the backup can go with it. The official documentation recommends copies in different locations, and a common rule of thumb is to keep:

  • Several versions, not just the latest. Malware or a bad change may go unnoticed for days, so the most recent backup can already be infected or broken.
  • At least one copy off the server, in cloud storage such as Amazon S3, Google Drive, Dropbox or a backup service's own storage.
  • Separate credentials, so someone who gets into your WordPress admin cannot also delete your backups.

Also consider privacy. Backups contain user accounts, email addresses and, on stores, order details. Store them in private, access-controlled locations, and delete old copies on a schedule.

Host backups vs plugin backups vs backup services

Host backups

Many hosts take automatic daily backups, especially managed WordPress hosts. They are convenient and run at the server level, so they still work if WordPress itself is broken. The drawbacks: retention may be short, the backup is often stored with the same company, and downloading a copy can be awkward or, on some plans, cost extra. Read your host's terms for how long backups are kept and whether you can restore a single file or only the whole site. Our guide to managed WordPress hosting covers what is typically included.

On WordPress.com, real-time backups and one-click restores are listed on the Business, Commerce and Enterprise plans as of October 2026; automated backups are not part of the lower paid plans.

Backup plugins

Plugins run inside WordPress and send backups to storage you choose. They are portable between hosts and often double as migration tools. The drawbacks: they use your server's resources while running, they can time out on large sites with cheap hosting, and if the site is completely broken you may need to restore manually.

Backup services

Some products, such as Jetpack VaultPress Backup and BlogVault, process backups on their own infrastructure and store them off your server. They usually cost more but reduce load and simplify restores.

Common WordPress backup tools

This is a neutral overview, not a ranking. Install counts are bands from WordPress.org and prices are from each vendor's site, both as of October 2026. Check the vendor page before buying, since prices change.

ToolWhat it isActive installs (WordPress.org)Pricing model
UpdraftPlusScheduled backups to remote storage, with restore and migration4+ millionFree plugin; Premium from $70/yr (2 sites)
All-in-One WP Migration and BackupExport and import of full sites, widely used for migrations5+ millionFree plugin with paid extensions
DuplicatorPackages a site into an archive for backup or migration1+ millionFree plugin with a paid Pro version
Jetpack VaultPress BackupOff-site backups processed by Automattic, part of JetpackJetpack plugin: 3+ millionIncluded in Jetpack Security ($19.95/mo regular, billed yearly) and Complete
BlogVaultOff-site incremental backups with staging and restore80,000+Per site per year, from $99 (Personal)
WP STAGINGBackups, restore and staging copies100,000+Free plugin with a paid Pro version

When comparing tools, check: where backups are stored, whether storage is included, incremental vs full backups, restore steps when the site is down, retention length, and how the tool handles very large uploads folders. Recent security history matters too, since backup and migration plugins handle your entire site. Keep them updated like any other plugin.

How to test a restore

The WordPress documentation suggests occasionally backing up your automatic backups with a manual one to confirm the process works. Going one step further, a real restore test is the only proof. A simple routine, every quarter or after you change backup tools:

  1. Pick a recent backup at random, not the newest one.
  2. Restore it to a staging site or a local copy, never over the live site.
  3. Check that pages load, images display, you can log in, forms submit and, for stores, recent orders and products are present.
  4. Time how long the restore took. That is your realistic downtime if disaster strikes.
  5. Write down the exact steps, logins and storage locations, and keep that note somewhere other than the website.

If the restore fails, you found the problem on a quiet day instead of during an emergency.

Manual backups for developers

If you have SSH access, WP-CLI makes quick manual backups easy. wp db export runs mysqldump with the credentials in wp-config.php and writes the database to a SQL file. Pair that with an archive of wp-content and wp-config.php. Store both off the server. This is a good habit before running risky commands, such as a database search-replace or a major plugin migration.

Backups and security incidents

After a hack, restoring a backup is often the fastest way back online, but only if you restore a clean copy and close the hole that let the attacker in. Otherwise the site gets reinfected. That means updating the vulnerable plugin, changing passwords and salts, and checking for unknown admin users. See our guides to a hacked WordPress site and website backup and recovery.

Conclusion

Good WordPress backups are complete (files and database), automatic, frequent enough for how your site changes, stored in more than one place, and proven by a test restore. Combining host backups with an off-site plugin or service covers most risks for most businesses. Explore more guides in our WordPress hub. If you would rather not manage this yourself, eSEOspace includes monitored backups in its website maintenance services.

Frequently asked questions

Are my host's backups enough?

Sometimes, but check three things: how long backups are kept, whether you can download a copy, and whether they are stored somewhere independent of your hosting account. If the answer to the last one is no, add an off-site backup through a plugin or service.

How often should I back up WordPress?

The official documentation suggests weekly for smaller, low-activity sites and daily for high-activity sites. Stores and membership sites often need more frequent database backups, and every site should get a manual backup before updates.

Do I need to back up WordPress core files?

Core files can be downloaded again from WordPress.org, so they are the least critical part. The essentials are wp-content (themes, plugins, uploads), wp-config.php and the database. Including core simply makes a full restore faster.

How many backups should I keep?

The WordPress documentation recommends at least 3 to 5 recent backups in different locations. Keeping older versions too, such as a monthly copy, helps when a problem like malware went unnoticed for weeks.

Can I restore a backup to a different host?

Yes. Most backup plugins can restore to a new server, which is how many site migrations work. If the domain or paths change, the database will also need its URLs updated, ideally with a tool that handles serialized data.

Put this into action with eSEOspace

We help businesses grow with website design that actually performs. Explore the services behind this guide:

Book a free strategy call →

Get a FREE Audit

We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.

Don't have a site yet? Get in touch →

Get a FREE GEO/AEO/SEO Audit

We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.

Don't have a site yet? Get in touch →

You Might Also like to Read