Skip to content
Webcrab
All posts

Security · 4 October 2026 · 6 min read

How to back up a WordPress website (and check the backup works)

What to back up, how often, where to keep it, and how to test a restore, so a hack or a bad update never costs you the site.

Most business owners only think about backups after losing something. A bad plugin update, a hack, a hosting problem or a deleted page can all take a website down. A good backup turns a disaster into an inconvenience. A bad one, or an untested one, turns it into a long, expensive week.

What a WordPress backup needs to include

A WordPress site has two parts, and you need both:

  • Files: WordPress itself, your themes, your plugins and your uploads folder with every image and document
  • Database: your pages, posts, settings, users and, for shops, orders and customers

A backup that has only one of these cannot rebuild your site.

How often should you back up?

Match the schedule to how often the site changes:

Type of siteBackup
Brochure site, rarely changesWeekly, plus before every update
Blog or active business siteDaily
Online shop with ordersDaily at minimum, with database backups more often

If you take orders, losing a day of them can mean customers who paid and you cannot find.

Where to store backups

Do not keep backups only on the same server as the website. If the server is hacked or fails, the backups go with it. Follow a simple rule:

  1. One copy on your hosting account (convenient and quick)
  2. One copy off-site, for example cloud storage in another service
  3. If the site matters a lot, one more copy somewhere you control

Your options

Your host's backups. Many hosts include daily backups. Check how long they keep them and how you restore. Do not assume they are enough, as some only keep a few days.

A backup plugin. Plugins can schedule backups and send them to cloud storage. Choose a well-known, regularly updated one and keep it updated, because an abandoned backup plugin is itself a risk.

A managed care plan. The least effort: someone else runs the schedule, stores the copies off-site and tests them. Our Care Plans include daily off-site backups.

The step most people skip: test a restore

A backup you have never restored is a hope, not a backup. At least once a quarter:

  1. Create a staging copy of the site, or use a spare test space
  2. Restore the latest backup there
  3. Check the pages, the forms, the shop and the admin login
  4. Write down how long it took and what was missing

If it fails, you find out on a quiet afternoon, not in the middle of a crisis.

Before you update

Always take a fresh backup before updating WordPress, themes or plugins, or changing hosting. Updates are the most common reason sites break. Many backup tools let you take a one-click snapshot first.

What to do after a hack

A backup from before the infection can save a lot of work, but only if it is clean. Check the date, restore it, then update everything and close the hole that let the attacker in. Our guide to removing malware from WordPress explains how.

A simple backup checklist

  • Files and database both included
  • Daily for active sites, more often for shops
  • At least one copy off the web server
  • Kept for at least 30 days
  • A restore test every quarter
  • Someone named who is responsible

Want this handled for you? See our security and care service, or get in touch.

Let's build something that lasts.

Tell us about your business. You'll get a written quote with a fixed price within one working day.

Get a quote