The simplest way to back up WordPress
The easiest method is to use a backup plugin that runs automatically and stores copies off your server. UpdraftPlus is free, widely used, and backs up your entire site — all your posts, pages, images, settings, and the database — to cloud storage like Google Drive or Dropbox. You install it from your WordPress dashboard, set it to run daily or weekly, and it handles the rest. The backup sits safely away from your hosting account, so if your server gets hacked or crashes, you still have a copy.
Other popular free plugins that work the same way are BackWPup and Duplicator. All three let you restore your whole site from a single backup file if something breaks. The trade-off is that they use a small amount of your hosting account's resources while they run, though most hosts allow this.
Key Takeaways
- A backup plugin like UpdraftPlus automates the process and stores backups off your server, protecting you if your hosting account is compromised or fails.
- Manual backups through your hosting control panel (usually cPanel or Plesk) take 10 minutes and give you direct control, but you have to remember to do them regularly.
- Your database and your files are separate — backing up only one leaves you unable to restore the other, so always back up both.
- Test your backup by restoring it to a staging site before you need it for real, so you know it actually works.
Backing up manually through your hosting control panel
If you prefer not to install a plugin, you can back up WordPress manually using your hosting account's control panel. Most hosts use cPanel or Plesk. Log in to your hosting account, find the File Manager or Backup section, and download your entire public_html folder (or whatever folder holds your WordPress installation). This gives you all your site files — themes, plugins, uploads, and configuration.
Then back up your database separately. In cPanel, go to phpMyAdmin, select your WordPress database, and use the Export button to download a .sql file. In Plesk, the Backup Manager does both files and database in one step. Store both downloads on your computer or in cloud storage. This method takes about 10 minutes and costs nothing, but you have to do it yourself on a schedule.
Understanding what you're actually backing up
WordPress has two parts: your files and your database. The files are your themes, plugins, images, and the WordPress core code itself. The database is where WordPress stores all your posts, pages, comments, user accounts, and settings. You need both to restore a working site. If you back up only the files, you can restore the structure but not your content. If you back up only the database, you have your posts but no way to display them.
A backup plugin backs up both automatically. A manual backup requires you to download both the files and the database export. Either way, make sure you have both pieces before you consider yourself protected.
Where to store your backups safely
Never store a backup only on your hosting server. If your server is hacked or your account is deleted, a backup sitting on the same server goes with it. Store backups in at least one place outside your hosting account. Cloud storage like Google Drive, Dropbox, OneDrive, or Amazon S3 works well — most backup plugins connect to these directly. You can also download backups to your computer and keep them in a folder.
A good practice is to keep at least two backups: one recent (from this week) and one older (from a month ago). That way, if you discover a problem weeks after it happened, you have a backup from before the problem started. Many backup plugins let you set how many old backups to keep automatically.
Testing your backup before you need it
A backup that you've never restored is a backup you don't know works. Before you rely on it, test it on a staging site — a copy of your WordPress site that nobody sees. Most hosts offer free staging environments, or you can create one by installing WordPress on a subdomain like staging.yoursite.com. Download your backup file and restore it there using the same plugin or your host's restore tool. Make sure all your posts appear, your images load, and your plugins work.
This takes an hour the first time and catches problems while you still have time to fix them. If you wait until your live site is broken to test your backup, you might discover the backup is incomplete or corrupted — and then you have no recovery plan.
How often to back up and how long to keep them
How often you back up depends on how often you change your site. If you post daily, back up daily. If you post once a month, weekly backups are enough. If you rarely change anything, monthly is fine. The rule is simple: you can lose everything since your last backup, so back up as often as you can afford to lose.
Keep backups for at least 30 days. Malware and hacks sometimes go unnoticed for weeks, so a backup from two weeks ago might be your only clean copy. Some people keep backups for 90 days or longer. Cloud storage is cheap, so there's no harm in keeping old backups around.
Backing up before you make big changes
Before you update WordPress, install a new plugin, or change your theme, take a manual backup in addition to your regular schedule. This takes two minutes and gives you a known-good copy from right before the change. If an update breaks something, you can restore from that backup and roll back the change while you figure out what went wrong.
The same applies before you edit your theme code, change your database directly, or make any other risky change. A backup from five minutes before the problem is worth far more than a backup from yesterday.
Frequently Asked Questions
What's the difference between a full backup and a partial backup?
A full backup includes your entire WordPress installation — files, database, everything. A partial backup might skip your uploads folder or old posts to save space. For WordPress, always do a full backup. Partial backups save time but leave you unable to fully restore if something breaks.
Can I back up WordPress while my site is live and people are visiting?
Yes. Backup plugins are designed to run while your site is active. They may slow things down slightly during the backup, but they won't take your site offline or lose visitor data. Avoid backing up during your busiest hours if you can, but a backup during normal traffic is better than no backup.
How much storage space does a WordPress backup take?
It depends on your site size. A small blog with a few posts might be 50 MB. A site with thousands of posts and lots of images could be 500 MB to several GB. Check your current site size in your hosting control panel, then plan for backups to be roughly that size. Most cloud storage plans offer plenty of room for multiple backups.
What do I do if my backup file is corrupted and won't restore?
This is why you keep multiple backups. Restore from an older backup instead. If all your backups are corrupted, you may need to hire a WordPress specialist or your hosting support team to recover what they can from server logs. This is rare, but it's another reason to test your backups regularly.
Do I need to back up if my host says they back up my account?
Your host's backups protect you from hardware failure, but not from hacks, malware, or accidental deletion of your account. Host backups are also sometimes slow to restore and may cost money. Keep your own backups so you control when and how you restore, and so you have a copy outside the hosting company's control.