How to back up a WordPress website, and how often to do it
Bizer · 2026-10-01
A WordPress site lives in two places, and a backup that only saves one of them will not bring your site back. The official WordPress documentation is blunt about this: you need both the database and the files to fully restore a typical WordPress site.
The files are the WordPress software, your theme, your plugins, your uploaded images, and the configuration file called wp-config.php. The database holds your pages, posts, settings, users and form entries. It lives in a separate database system on the server, which is why downloading your website folder over FTP does not back it up.
How often should you back up?
The WordPress.org backup guide, as of September 2026, suggests weekly backups for smaller sites with few posts and daily backups for high-activity sites.
Our recommendation is a little stricter, and simpler to remember:
- Daily automatic backups for any site that takes orders, bookings or form submissions. Those submissions live in the database, and a weekly backup can lose six days of them.
- Weekly is fine for a brochure site that changes a few times a year.
- Always take a manual backup right before updating WordPress, changing themes, or installing a plugin you have not used before.
Backups cost almost nothing to run. Losing a week of customer orders costs a lot.
Where should the copies live?
Not only on the same server as the site. If the host has an outage, gets breached, or closes your account over a billing problem, backups stored there disappear with it.
WordPress.org recommends keeping at least three to five recent backups in separate places, for example one on the hosting server, one in cloud storage such as Google Drive or Dropbox, and one downloaded to your own computer. You do not need all three. You do need at least one copy that does not depend on your host.
What are the ways to do it?
There are three common methods, roughly from easiest to most hands-on.
Your host's backups
Many hosts take automatic daily backups and let you restore with a click. Check three things in your host's dashboard: how many days of backups are kept, whether you can download one, and whether restoring is free. Some hosts charge for restores or only keep a few days. Host backups are a good first layer. They should not be the only one, for the reason above.
A backup plugin
Plugins such as UpdraftPlus, BackWPup or Jetpack VaultPress Backup can run on a schedule and send copies to cloud storage automatically. When choosing one, check its page on wordpress.org for recent updates and a large number of active installs. Set it to back up both the database and the files, and point it at a storage account that you control, not one your web designer set up under their own name.
Manual backups
You can export the database through your host's control panel (usually with a tool called phpMyAdmin) and download the files with an FTP or SFTP client. The WordPress documentation describes both. This is worth knowing how to do once, because it works even when the site itself will not load. It is too tedious to rely on week to week.
How do you know a backup actually works?
You restore it. That is the only test.
The WordPress.org guide recommends occasionally checking automated backups with a manual one, because an automated job can fail quietly for months. A better habit, a couple of times a year:
- Create a staging copy of the site (many hosts offer this with one click) or a local test install.
- Restore your latest backup onto it. WordPress.org's order is files first, then the database.
- Click through the home page, a service page, the contact form and the admin area.
If anything is missing, you found out on a quiet afternoon instead of during an emergency.
What does the old "cron" approach have to do with this?
Older guides talked about scheduling backups with cron, the server's job scheduler, and some plugins still use WordPress's built-in scheduler, called WP-Cron. One catch worth knowing: WP-Cron only runs when someone visits the site. On a quiet site, a 2 a.m. backup may not run until the first visitor arrives that morning. If backups seem to skip days, ask your host to trigger WP-Cron with a real server cron job.
What does this cost?
A backup plugin's free version plus a cloud storage account you already pay for covers most small sites. Premium plugin tiers and host add-ons cost more but mainly add convenience, such as one-click restores and offsite storage included. The real cost is the hour it takes to set up and test, plus the discipline to look at the backup log once a month.
What is uncertain
We cannot tell you which backup plugin will be best next year. Plugins get sold, change their free tiers, or stop being maintained, and that happens without much notice. That is why the advice here is about principles that do not change: both parts, more than one location, and a restore you have actually tried. If you are still setting up the site, start with how to build a business website on WordPress.