Why backups are non-negotiable
Every WordPress site is one bad plugin update, one hack, or one server failure away from losing everything. Backups are the difference between a 10-minute restore and rebuilding your site from scratch.
A real backup is:
- Automatic — happens without you remembering
- Off-server — not on the same machine as the site
- Tested — you've actually restored from it at least once
This guide covers the three layers: host backups, plugin backups, and the restore drill. Security and recovery go hand-in-hand — pair this with WordPress hosting security.
What a WordPress backup contains
A complete backup has two parts:
- Files — themes, plugins, uploads,
wp-config.php - Database — every post, page, setting, order, and user
Backing up only files, or only the database, isn't a backup. Both are required for a full restore.
Layer 1: Host-level backups
The easiest layer is often already paid for:
- SiteGround — daily backups free, plus an on-demand backup button
- Hostinger — weekly free backups, daily on higher tiers
- Bluehost — daily (older) / weekly (newer) depending on plan
- Kinsta, WP Engine, Cloudways — automatic daily backups with one-click restore
Check your host's control panel and enable the automatic backup schedule if it's off by default. Managed plans run on managed WordPress hosting usually include them — that's part of what you pay for.
Layer 2: Plugin backups to the cloud
Host backups can fail (and they're usually on the same infrastructure). The industry rule is the 3-2-1 rule: 3 copies, 2 media types, 1 off-site.
The standard plugin is UpdraftPlus (free tier is genuinely useful):
- Install UpdraftPlus and open Settings → UpdraftPlus Backups
- Under Settings, add a remote storage destination (Google Drive, Dropbox, or S3)
- Set a backup schedule — daily files + database for active sites
- Click Backup Now
BackupBuddy (paid) and Jetpack VaultPress (paid) are the main alternatives if you want premium scheduling or one-click restores from the plugin itself.
Layer 3: The restore drill
A backup you've never tested is a hope. Monthly:
- On your host, create a staging copy of the site (see staging environments)
- Delete something harmless (a draft post or a test plugin)
- Restore from backup into staging and confirm it returns
When a real disaster hits, restoration paths in order of preference:
- Host one-click restore — Kinsta/WP Engine/Cloudways/SiteGround dashboard restore
- Plugin restore — UpdraftPlus/BlogVault restore from cloud storage
- Manual restore — import the database via phpMyAdmin and upload files via FTP (the slow route)
If you're moving hosts rather than recovering, use our migration guide instead.
Frequently asked questions
How often should I back up WordPress? Daily minimum; nightly for stores or actively-updated sites. Weekly is only acceptable for a static, rarely-changed site.
Are host backups enough? Not alone — a host outage or account issue can take backups with the site. Add an off-site plugin backup to cloud storage for the 3-2-1 rule.
What is the best free WordPress backup plugin? UpdraftPlus — free cloud backups with scheduling, plus restore from the plugin. The paid version adds incremental backups and clones.
How do I restore WordPress from a backup? Most hosts have one-click restore in the dashboard (the fastest route). Otherwise restore via your backup plugin. Full walkthrough: our move WordPress guide covers the file+DB restore mechanics.
Do managed hosts back up WordPress automatically? Yes — Kinsta, WP Engine, and Cloudways all include automatic daily backups and one-click restore in every plan. See managed WordPress hosting.