Backups are your undo button for the whole website. Hacks, bad updates, accidental deletions and host outages happen to everyone eventually. With good backups, they’re a minor inconvenience instead of a catastrophe.
What a WordPress backup includes
A complete backup has two parts:
- The database: posts, pages, comments, users and settings.
- The files: especially
wp-content(themes, plugins and uploads) pluswp-config.php.
Back up both. A database without your images, or images without your posts, won’t bring your site back.
The 3-2-1 rule
- 3 copies of your data: the live site plus two backups.
- 2 different types of storage, for example your host’s backup system and a cloud storage service.
- 1 copy off-site, stored somewhere completely separate from your hosting account.
Why off-site? If your hosting account is compromised or suspended, backups stored only in that same account may be unreachable too.
How often?
Match backup frequency to how often your site changes. A blog that publishes weekly might be fine with daily backups. A store or membership site with constant orders needs more frequent database backups, sometimes real-time. Keep several past versions, not just the latest, because problems like malware aren’t always noticed right away.
Professor’s warning: A backup you’ve never restored is just a hope. Practice a restore on a staging site or a local test install at least once, so you know it works and you know the steps before an emergency.
Setting it up
- Check what your host provides: frequency, retention and how to restore.
- Add a backup plugin or service that sends copies to off-site cloud storage automatically.
- Always take a fresh backup before major updates, theme changes or big edits.
Find backup options on our plugins page and resources page.
Your assignment
- Confirm your host’s backup schedule and retention.
- Set up automated off-site backups so you meet the full 3-2-1 rule.
- Perform one test restore on staging and write down the steps.