WordPress Backup: What to Save, How, and How to Restore


WordPress Backup: What to Save, How, and How to Restore

A WordPress backup is the one thing that turns a disaster into an inconvenience. A failed update, a hacked plugin, an accidental deletion or a host outage can all be undone in minutes if you have a recent, complete, tested copy of your site stored somewhere safe. This guide explains exactly what a complete backup contains, compares the main methods (host, plugin, manual and command line), and shows how to store and test backups so they work when you need them.

What a complete WordPress backup contains

A WordPress site lives in two places, and a backup needs both:

  • The database. Posts, pages, comments, users, settings, menus, widget settings and, for block themes, any templates you have customized in the Site Editor. WooCommerce orders and customers live here too. See WordPress database tables explained for what each table holds.
  • The files. Above all wp-content/, which holds uploads/ (your media), themes/ and plugins/. Also wp-config.php, which contains database credentials and security keys, and .htaccess if your server uses one.

WordPress core files (wp-admin/, wp-includes/) can always be downloaded again from WordPress.org, so some backup tools skip them to save space. That is fine, as long as you know the exact WordPress version to restore onto. A database-only backup is not a full backup: without uploads/ every image on the site disappears.

The 3-2-1 rule for WordPress backup storage

The 3-2-1 rule is a long-standing data-protection guideline that applies well to websites:

  • 3 copies of your data: the live site plus two backups.
  • 2 different storage types, for example your host’s backup system and a cloud storage service.
  • 1 copy off-site, meaning not on the same server or with the same company as your hosting.

The off-site copy is the one people skip and later regret. A backup stored in the same hosting account is lost along with the account if it is suspended, compromised or closed, or if the host has a serious incident. Good off-site destinations include Amazon S3, Backblaze B2, Google Drive, Dropbox and similar services. Use storage credentials that can write new backups but, ideally, cannot delete old ones, so an attacker who gets into your site cannot wipe your history too.

Method 1: Host-level backups

Most WordPress hosts take automatic backups, typically daily on managed plans and sometimes less often on entry-level shared plans. They are usually snapshots of the whole account, run at the server level without slowing your site, and can be restored from the control panel in a few clicks.

Check four things about your host’s backups: how often they run, how long they are kept (retention), whether you can download them, and whether restores cost extra. Host backups are an excellent first layer, but they are by definition not off-site, so they should not be your only copy. Backup policy is one of the main differences between plan types; our guide to managed WordPress hosting covers what to ask.

Method 2: Backup plugins

A backup plugin runs inside WordPress, creates archives of your files and database on a schedule, and sends them to remote storage. UpdraftPlus is one of the most widely used: its free version supports scheduled backups to common cloud services and restores from the dashboard, while paid add-ons extend it with features such as incremental backups and migration. Other established options include Jetpack VaultPress Backup, BlogVault, Duplicator and WPvivid, each with a different balance of free features, real-time backups and migration tools. Check each vendor’s current pricing page, as plans and feature splits change.

A typical plugin setup looks like this:

  1. Install and activate the plugin from Plugins → Add New Plugin.
  2. Open its settings (for UpdraftPlus, Settings → UpdraftPlus Backups).
  3. Set separate schedules for files and database. The database changes more often, so it can run more frequently.
  4. Choose how many backups to retain.
  5. Connect remote storage and authorize access.
  6. Run a manual backup immediately and confirm the files arrive in remote storage.

The trade-off: plugin backups run on your server using PHP, so very large sites can hit time or memory limits on cheaper hosting. Real-time or incremental services that copy changes off-server handle large and busy sites better.

Method 3: Manual and command-line backups

Manual backups are worth knowing even if you automate everything, because they work when the dashboard does not. The Advanced Administration handbook on developer.wordpress.org has an official backup overview covering the same ground.

Through the control panel

Export the database from phpMyAdmin (select the database, then Export, format SQL), and download wp-content/ and wp-config.php with the File Manager or an SFTP client. Compressing the folder into a zip first makes the download much faster.

With WP-CLI and mysqldump

If you have SSH access, the command line is the fastest and most scriptable option:

# Database export with WP-CLI (run from the WordPress root)
wp db export backup-$(date +%F).sql

# Or directly with mysqldump, using the credentials in wp-config.php
mysqldump --single-transaction -u DB_USER -p DB_NAME > backup-$(date +%F).sql

# Archive the files
tar -czf files-$(date +%F).tar.gz wp-content wp-config.php .htaccess

The --single-transaction flag gives a consistent snapshot of InnoDB tables without locking the site. Do not leave backup files inside the public web root, where anyone who guesses the filename could download your database; move them off the server or to a directory outside public_html. The wp db export reference lists further options. A cron job running these commands and then copying the results to remote storage gives you a dependable, plugin-free backup.

Choosing a WordPress backup schedule

Site typeDatabaseFilesRetention
Brochure site, rarely editedWeekly, plus before changesWeeklyA few weeks
Active blog or news siteDailyDaily or weekly30 days or more
WooCommerce store or membership siteHourly or real-timeDaily30 days or more

The right frequency is set by one question: how much work could you afford to lose? On a store, a day-old database means a day of missing orders. Whatever the schedule, always take a fresh backup before updating WordPress core, a theme or a major plugin. Long retention matters because some problems, such as a quiet malware infection, are discovered weeks after they start.

Test your restores

An untested backup is a hope, not a plan. Archives can be incomplete, corrupted or missing the database, and you do not want to discover that during an emergency. At least every few months:

  1. Restore a recent backup to a staging site or a local install, never over the live site.
  2. If the domain differs, run a search-replace on URLs, for example wp search-replace 'https://example.com' 'https://staging.example.com', which handles serialized data correctly.
  3. Log in, open several posts, check images load, and confirm recent content is present.
  4. Time the process and write down the steps, so a real restore is calm and quick.

After restoring a hacked site, change all passwords and security keys and update everything before going live again; the backup brings back your content but not the fix for whatever let the attacker in. The security hardening guide covers the follow-up steps.

Frequently asked questions

Are my host’s backups enough?

They are a good first layer, but not enough alone, because they live with the same provider as your site. Add at least one automated off-site copy.

How big will my WordPress backup be?

Mostly the size of your uploads/ folder. The database is usually much smaller, unless it has accumulated logs, revisions or expired transients; cleaning those up shrinks backups and speeds restores.

Can I use a backup to move my site to a new host?

Yes. Several backup plugins include migration tools, and a manual database export plus a wp-content archive is all a migration fundamentally needs, followed by a URL search-replace if the domain changes.

Key takeaways

  • A complete WordPress backup includes the database plus wp-content, wp-config.php and .htaccess.
  • Follow the 3-2-1 rule, and keep at least one copy off-site with credentials that cannot delete old backups.
  • Layer methods: host snapshots, a plugin or script sending copies to remote storage, and manual backups before big changes.
  • Match frequency to how much work you can afford to lose; stores need near real-time database backups.
  • Test restores on staging regularly and document the steps.

Backups are part of routine upkeep alongside updates and monitoring; the WordPress maintenance checklist shows where they fit in a weekly and monthly schedule.

stephog Avatar

Share Article

Need a Custom Theme?

We create unique, high-performance WordPress themes tailored to your brand.

ABOUT US