Class, settle in. Today’s lesson is the one nobody thinks they need until the morning their site shows a white screen, a hacked homepage, or a “database connection error” right before a big launch. Backups are not glamorous, but they are the single most reliable safety net a WordPress site owner can have. Professor Press has seen plenty of sites saved by a boring backup, and plenty lost for the lack of one.
The good news: a solid backup strategy is simple. It fits in one memorable rule, and you can set it up in an afternoon.
What Is the 3-2-1 Backup Rule?
The 3-2-1 rule is a long-standing data protection guideline used far beyond WordPress. It says you should keep:
- 3 copies of your data — your live site plus two backups.
- 2 different storage types — for example, your host’s server and a cloud storage service.
- 1 copy off-site — somewhere completely separate from your hosting account.
Why so many copies? Because every storage location can fail in its own way. Servers crash, hosting accounts get suspended, cloud folders get accidentally emptied, and malware can sometimes reach backups stored on the same server as the infected site. Spreading copies around means one bad day cannot wipe out everything.
Professor’s note: A backup that lives only on the same server as your website is really a “copy,” not a backup. If the server goes, both go together.
What a Complete WordPress Backup Includes
A WordPress site is made of two parts, and you need both to restore it:
1. The database
This holds your posts, pages, comments, users, settings, and most plugin data. It changes every time you publish or someone leaves a comment, so it needs frequent backups.
2. The files
This includes the wp-content folder (your themes, plugins, and uploaded media), plus important files like wp-config.php and .htaccess (on Apache servers). WordPress core files can be re-downloaded, but backing them up does no harm and makes restores faster.
Heads up: wp-config.php contains your database password and security keys. Store backups somewhere private and access-controlled, never in a public folder or a shared link anyone can open.
Choosing Your Backup Tools
You have three broad options, and many site owners combine them.
Host-level backups
Many managed WordPress hosts take automatic backups. These are convenient and often allow one-click restores. However, they usually live inside the host’s infrastructure, so they count as one copy, not your off-site copy. Check how often they run and how long they are kept.
Backup plugins
Established plugins such as UpdraftPlus, BlogVault, Jetpack VaultPress Backup, and Duplicator can schedule backups and send them to remote storage like Google Drive, Dropbox, Amazon S3, or similar services. Features vary between free and paid tiers, so read each plugin’s documentation to see what fits. You can compare options in our plugin guides.
Manual backups
You can export the database with a tool like phpMyAdmin or WP-CLI (wp db export) and download files over SFTP. Manual backups are great before risky changes, but relying on memory alone is how backups quietly stop happening.
Setting Up 3-2-1 in Practice
Here is a practical setup that works for most small and medium sites:
- Copy 1: Your live site — this is the original, running on your host.
- Copy 2: Host backups — turn on your host’s automatic daily backups if available.
- Copy 3: Off-site plugin backups — configure a backup plugin to send scheduled copies to a cloud storage account you control, separate from your host.
- Set a schedule that matches your activity — a busy store or daily blog may need daily (or more frequent) database backups; a brochure site that rarely changes can back up weekly.
- Set retention — keep several restore points, not just the latest one. If malware sneaks in and goes unnoticed for a week, you need a backup from before the infection.
- Back up before big changes — always take a fresh backup before core, theme, or plugin updates, and before editing code.
Tip: Use a separate cloud account (with strong, unique credentials and two-factor authentication) just for backups. If your main email or hosting account is ever compromised, your backups stay out of reach.
Test Your Restores (Seriously)
A backup you have never restored is a backup you are hoping works. Professor Press recommends a restore drill every few months:
- Spin up a staging site or a local environment.
- Restore your latest backup there, not on your live site.
- Click around: check posts, images, forms, logins, and any store checkout.
- Write down the steps you took, so a stressed future you can follow them.
Testing reveals common surprises early: a backup that silently excluded the uploads folder, a cloud connection that expired months ago, or a file too large for your plugin’s settings.
Backups Are Part of a Bigger Security Picture
Backups are your recovery plan, not your prevention plan. Pair them with good habits: keep WordPress, themes, and plugins updated, use strong passwords and two-factor authentication, remove plugins you no longer use, and choose reputable hosting. Our WordPress course walks through a full security checklist, and the tools page lists handy utilities for maintenance.
If you are brand new, head to Start Here to get your bearings before tackling server settings.
Homework
- Find out whether your host takes automatic backups, how often, and how long they are kept.
- Set up one off-site backup destination you control.
- Schedule a restore test on a staging or local site within the next month.
- Bonus credit: write a one-page “how to restore my site” note and store it somewhere you can reach even if your site is down.
Then check your knowledge with today’s pop quiz. No peeking at your notes!