Why you need a WordPress backup and what it protects

A backup is a copy of your entire WordPress site — all your posts, pages, images, settings, and the database that holds everything together. If your site gets hacked, a plugin breaks your homepage, your hosting account gets deleted, or your database corrupts, a backup lets you restore the whole thing to the way it was before the problem happened.

Without a backup, you are one bad update or one security breach away from losing months or years of work. With a backup, you lose maybe a few hours of posts or edits since the last backup was made. Most people who lose a WordPress site to a hack or crash did not have a backup.

A complete backup includes two things: your files (themes, plugins, uploads, configuration) and your database (posts, pages, comments, user accounts). You need both. A backup of just your files is useless if your database is gone, and a database backup without your files cannot be restored.

Key Takeaways

  • A complete WordPress backup requires both your files and your database, and you need to store the backup somewhere other than your hosting account.
  • The easiest method for most people is a backup plugin like UpdraftPlus or Duplicator, which automates the process and stores copies on cloud storage like Google Drive or Dropbox.
  • If your hosting company offers automated backups, check whether they store backups off-site and whether you can restore them yourself without contacting support.
  • Test your backup by actually restoring it to a test site before you need it in an emergency — a backup that cannot be restored is worthless.
  • Set backups to run automatically on a schedule (daily or weekly, depending on how often you post) rather than doing them manually.

Using a backup plugin: the simplest route for most sites

A backup plugin automates the entire process and is the method most WordPress users choose. The plugin creates a backup file containing your files and database, then sends it to cloud storage like Google Drive, Dropbox, or Amazon S3. You do not have to touch your hosting account or use command-line tools.

UpdraftPlus is the most popular choice. Install it from your WordPress dashboard: go to Plugins > Add New, search for "UpdraftPlus", click Install Now, then Activate. Once activated, go to Settings > UpdraftPlus Backups in your dashboard.

In UpdraftPlus settings, choose where to store your backups. Click the cloud storage option you want — Google Drive, Dropbox, OneDrive, or others. The plugin will ask you to log into that service and give permission. Once connected, set a backup schedule: daily if you post frequently, weekly if you post less often. Then click "Backup Now" to create your first backup immediately.

Duplicator is another solid option that works similarly. It is lighter on server resources and some people find the interface clearer. The setup is the same: install, activate, connect to cloud storage, set a schedule, and run your first backup.

Both plugins have free versions that work well for most sites. The paid versions add features like more frequent backups or longer backup history, but the free version is enough to keep you safe.

Backing up through your hosting control panel

Many hosting companies (Bluehost, SiteGround, Kinsta, WP Engine) include automated backups in their service. Log into your hosting control panel and look for a Backups, Backup Manager, or similar section. Some hosts back up your site daily or weekly automatically.

Before you rely on your host's backups, check two things: whether backups are stored off-site (not on the same server as your live site), and whether you can restore them yourself or have to contact support. If your server catches fire and the backups are on the same server, you have lost everything. If you have to wait for support to restore, you are down for hours or days.

Hosting backups are useful as a second layer of protection, but they should not be your only backup. Use a plugin to send backups to your own cloud storage account as well. That way you control the backups and can restore them instantly without waiting for your host.

Manual backup using FTP and phpMyAdmin

If you prefer not to use a plugin, you can back up manually. This takes longer and you have to remember to do it, but it gives you complete control. You will need FTP access (your host provides this) and access to phpMyAdmin (usually available in your hosting control panel).

Step 1: Download your files via FTP. Use an FTP client like FileZilla (free, works on Windows and Mac). Connect to your site using the FTP credentials your host provided. Navigate to your site's root folder (usually called public_html or www) and download the entire folder to your computer. This includes your wp-content folder (themes, plugins, uploads), wp-config.php, and all other WordPress files. This step can take 10 to 30 minutes depending on your site size.

Step 2: Export your database via phpMyAdmin. Log into your hosting control panel, find phpMyAdmin, and select your WordPress database from the left sidebar. Click Export at the top. Choose "Quick" export and the SQL format, then click Go. A file will download to your computer — this is your database backup.

Store both files (your downloaded folder and the SQL file) somewhere safe outside your hosting account: an external hard drive, a cloud storage folder, or both. Label them with the date so you know which backup is which.

Testing your backup before you need it

A backup that has never been tested is not a backup — it is a hope. Before you face a real emergency, restore your backup to a test site and make sure everything works.

If you used a plugin like UpdraftPlus, the plugin has a Restore button right in your dashboard. Click it, choose which backup to restore, and the plugin will do the work. This usually takes 5 to 10 minutes. Once restored, log in and check that your posts, pages, images, and settings are all there.

If you backed up manually via FTP and phpMyAdmin, ask your host to create a test subdomain (like test.yoursite.com). Upload your FTP files there, create a new database, and import your SQL file into it. This is more work, but it proves your backup is actually usable.

If the restore fails, you have found a problem while you still have time to fix it. If you skip this step and your site crashes, you might discover your backup is corrupted or incomplete — and by then it is too late.

How often to back up and how long to keep backups

How often you back up depends on how often your site changes. If you post daily or run an online store, back up daily. If you post once a week, weekly backups are enough. If your site is mostly static (you rarely change anything), monthly backups are acceptable.

Keep at least two weeks of backups on hand, and ideally a month. This gives you a window to notice a problem before all your old backups are gone. If you get hacked today but do not notice until next week, you want a backup from before the hack happened.

Most backup plugins let you set how many backups to keep. In UpdraftPlus, go to Settings > UpdraftPlus Backups and look for "Retention" — set it to keep at least 4 weekly backups or 14 daily backups. The plugin will automatically delete older ones.

What to do if your site goes down and you need to restore

If your site is hacked, crashes, or becomes unavailable, restore from your most recent backup. If you used a plugin, log into your WordPress dashboard (if you can still access it), go to the Backups section, and click Restore next to the backup you want. Choose what to restore — usually you want to restore everything: files, database, plugins, and uploads.

The restore will take several minutes. Your site may be down during this time. Once it finishes, log in and check that everything is working. If you cannot access your dashboard because the site is completely down, contact your hosting support and ask them to restore from a backup, or use FTP to upload your backed-up files and phpMyAdmin to import your database.

After you restore, figure out what caused the problem. If it was a plugin conflict, disable the plugin that caused it. If it was a hack, change all your passwords and run a security scan. Do not just restore and hope it does not happen again.

Frequently Asked Questions

Can I back up my WordPress site for free?

Yes. UpdraftPlus and Duplicator both have free versions that work well. You will also need free cloud storage like Google Drive or Dropbox to store the backups. The only cost is your time to set it up initially.

How much space does a WordPress backup take up?

It depends on your site size. A small blog with a few posts might be 50 MB to 200 MB. A site with thousands of posts and lots of images could be 1 GB or more. Most cloud storage services give you enough free space for several backups of a typical site.

What if I restore a backup and lose posts I made after the backup?

You will lose any posts, pages, or comments created after the backup was made. This is why testing your backup beforehand matters — you can decide whether the risk is acceptable. If you post frequently, use daily backups. If you rarely post, weekly backups are fine.

Do I need to back up if my hosting company already backs up my site?

Your host's backups are useful, but they should not be your only backup. Host backups are sometimes stored on the same server, can be slow to restore, or may require you to contact support. Having your own backup in your own cloud storage means you can restore instantly without depending on anyone else.

What should I do if my backup file is corrupted and will not restore?

This is why you keep multiple backups. Restore from an older backup instead. If all your backups are corrupted, contact your hosting company and ask whether they have server-level backups you can restore from. Going forward, test your backups monthly to catch corruption early.