WordPress Backup Best Practices: What to Save, How Often and Where to Keep It

Laptop on a clean desk following WordPress backup best practices

Most people only think about WordPress backup best practices on the worst day of the month: a plugin update has broken the homepage, a client is about to visit the site, and the only backup on hand turns out to be four months old. We get those calls at Design Fly 24 more than we would like, and almost every one of them could have been a ten minute fix.

Disclosure: Some links in this article are referral links. If you sign up through them, Design Fly 24 may earn a small commission at no extra cost to you. We only recommend hosting we use for our own clients.

Picture a school security consultant who just sent a proposal to a district. The procurement officer clicks the link in the email signature and lands on a white screen. Nobody on that committee is going to wait for a fix. A good backup system is what turns that moment into a minor annoyance instead of a lost contract.

This guide covers the WordPress backup best practices we use on client sites: what to save, how often, where to keep it, how host backups and plugins fit together, and how to prove a restore actually works. No scare tactics, just the routine.

Key takeaways

  • Back up the files and the database together. One without the other is only half a website.
  • Match how often you back up to how often the site changes, and always back up right before updates.
  • Keep at least two copies, and make sure one lives somewhere other than your hosting account.
  • Host backups and plugin backups do different jobs. Most small business sites should use both.
  • Test a restore on a schedule. Of all WordPress backup best practices, this is the one people skip. A backup you have never restored is a hope, not a plan.

Why WordPress backup best practices matter for a small site

A consultant website is small, but it carries a lot of weight. It is where a law firm checks out an expert witness, where an event planner confirms a speaker is real, and where a referral goes after hearing your name at a conference. When it breaks, the damage is not traffic numbers. It is trust, which is why WordPress backup best practices are not just for big companies.

WordPress sites break in a handful of predictable ways. A plugin update conflicts with the theme. Someone deletes the wrong page. A hosting server has a bad night. A weak password gets guessed and spam pages show up in Google. Each of these has a different fix, but every fix starts with the same thing: a clean copy of the site from before the problem.

That is all WordPress backup best practices really are. A short set of habits that makes sure the clean copy exists, is recent, is stored somewhere safe, and can be put back quickly. If you already follow our WordPress maintenance checklist, backups are the step that protects every other step on it.

1. Back up the whole site, not just the content

A WordPress site has two halves, and you need both. The first of the WordPress backup best practices is simply knowing what those halves are.

The database

The database holds your pages, posts, settings, menus, form entries, user accounts and most plugin settings. If you write a new case study, it lives here. If you change your phone number in the theme options, that probably lives here too. Lose the database and the site is an empty shell.

The files

The files include WordPress itself, your theme, your plugins and the uploads folder with every image and PDF you have added. The uploads folder is the one people forget. Your headshots, speaker one sheets and downloadable checklists are all in there, and they are often the hardest things to recreate.

The small extras

Two files deserve a mention. The wp-config.php file holds the database connection details and a few security keys, and the .htaccess file often holds redirects and caching rules. Good WordPress backup best practices include both in every full backup. If a plugin only offers a “database only” option by default, change it.

  • Database: content, settings, users, form entries
  • wp-content/uploads: images, PDFs, media
  • wp-content/themes and plugins: your design and features
  • wp-config.php and .htaccess: configuration and redirects

2. Match backup frequency to how often the site changes

There is no single right schedule. The honest answer to “how often should I back up?” is: often enough that losing everything since the last backup would not hurt. WordPress backup best practices start from that question rather than from a default setting in a plugin.

For a typical consultant site that changes a few times a month, a daily database backup and a weekly full backup is plenty. For a speaker who blogs twice a week and collects booking inquiries through a form, daily full backups make more sense, because those form entries are leads you cannot get back.

If you run a small online store or a membership area, orders and signups happen every hour. That site needs backups every few hours, or a real time option, because a daily copy could still lose a full day of orders.

3. Keep at least two copies, one off site

This is the rule people skip most often, and it is the one that matters most. If your only backups live inside the same hosting account as your website, they share the same risks. A hacked account, a billing problem or a serious server failure can take the site and the backups at the same time.

Among all WordPress backup best practices, this is the one we push hardest with clients. Keep one copy close by for fast restores (usually your host’s backups), and a second copy somewhere completely separate. Cloud storage such as Google Drive, Dropbox or Amazon S3 works well, and most backup plugins can send copies there automatically.

If your backups live in the same place as your website, you do not have a backup. You have a second copy of the same risk.

Web developer following WordPress backup best practices on a laptop
Two copies, two places: the simplest of the WordPress backup best practices.

4. Use host backups and plugin backups together

A question we hear constantly about WordPress backup best practices: do I need a backup plugin if my host already backs up the site? The short answer is usually yes, because the two do different jobs.

What host backups do well

Host backups run at the server level, so they do not depend on WordPress working. If the site is so broken you cannot log in, a host backup can still be restored from the control panel in a few clicks. They are usually quick to restore and do not slow down the site while they run.

For example, Hostinger, which we use for many client sites, includes daily backups on its Business plans and up. That is a good first layer. The catch with any host backup is that it lives with the host, so it does not satisfy the off site rule above.

What plugin backups do well

A backup plugin such as UpdraftPlus, BlogVault, Jetpack VaultPress Backup or Duplicator can send copies to your own cloud storage, keep the history you choose, and make it easy to move a site to a new server. You control where the copies go, and they survive even if you leave your host.

The weakness is that a plugin runs inside WordPress. On a very large site it can time out, and if WordPress is badly broken you may need to restore through the plugin’s own tools or by hand. That is why our version of WordPress backup best practices treats the host as layer one and the plugin as layer two.

Backup typeStrengthWeaknessBest use
Host backupsWork even when WordPress is down, fast restoresStored with the host, retention set by the planQuick rollbacks after a bad update
Plugin backupsOff site storage you control, flexible schedulesRun inside WordPress, can struggle on large sitesYour independent copy and site moves
Manual downloadsFully offline, no third party involvedEasy to forget, only as fresh as your last downloadMonthly or quarterly archive

5. Lock down where your backups live

A backup is a full copy of your website, including user accounts and anything people typed into your forms. If someone gets hold of it, they get all of that. Good WordPress backup best practices treat the backup storage with the same care as the site itself.

  • Use a separate cloud account for backups with a strong, unique password and two factor login.
  • Never store backups in a public folder on the web server where someone could download them by guessing the file name.
  • Turn on encryption if your plugin or storage service offers it.
  • Limit who can access the backup account. Your web person, yes. Every intern who ever touched the site, no.

This matters more for some clients than others. An HR consultant collecting intake forms or an expert witness receiving case details through a contact form is holding sensitive information. For them, WordPress backup best practices include encryption and tight access, not just a schedule. Our website security checklist covers the wider steps.

6. Keep enough history to go back far enough

Retention is how many old backups you keep. It sounds like a boring setting, but it decides if you can recover from problems you did not notice right away.

Here is the situation we see: a site gets quietly infected, and spam links sit in the footer for three weeks before anyone notices. If you only keep seven days of backups, every single copy is already infected. WordPress backup best practices call for enough history to reach past the problems that hide.

A simple retention rule from our WordPress backup best practices: keep 14 to 30 daily backups, plus a few monthly ones going back several months. Storage is cheap compared to rebuilding a site from scratch.

7. Test a restore on a schedule

This is where most backup plans quietly fail. The plugin says “backup complete” every night, and nobody ever checks whether that file can actually rebuild the site. Then the day comes, the restore fails halfway through, and the backup turns out to be missing the uploads folder.

Testing a restore does not have to be dramatic. You do not need to overwrite your live site. Restore the backup to a staging site (most good hosts offer one) or to a spare test install, and click through it.

  • Does the homepage load with the right design and images?
  • Do the menus, service pages and blog posts look correct?
  • Do the contact form and booking links still work?
  • Can you log in to the dashboard with your normal account?

Do this every quarter at a minimum, and after any big change to the site or your backup setup. Of all the WordPress backup best practices in this post, this one gives you the most confidence for the least effort. It takes about twenty minutes and tells you whether everything else on the list is actually working.

Not sure your backups would work?We will check your current setup, run a test restore and tell you plainly what is missing.

See our maintenance plans

8. Back up right before every risky change

Scheduled backups cover the slow, everyday risk. Manual backups cover the moments you know are risky: updating WordPress core, switching themes, changing your page builder, adding a big plugin, or letting a new freelancer into the site.

This is the easiest of all WordPress backup best practices: take a fresh backup before any of these, every time, even if the nightly backup ran a few hours ago. Content may have changed since then, and you want the restore point to be minutes old, not hours.

If you are planning a bigger project, such as the work in our website redesign checklist, keep the backup you took before the project for months rather than days. If the client decides they liked the old services page better, you can pull the content right back.

Consultant checking that a restored website works on a laptop
A test restore is the step of WordPress backup best practices most people skip.

9. Write it down and give it an owner

The last of our WordPress backup best practices is the least technical. Write a short note that answers four questions: where the backups are, how often they run, who has access, and how to restore one. Keep it somewhere you can find even if the website is down.

Then give your WordPress backup best practices an owner. If it is you, put a recurring reminder in your calendar. If it is your web team, ask them to send a short monthly note confirming backups ran and when the last test restore happened. That is exactly what we send clients on our WordPress maintenance plans.

WordPress backup best practices at a glance

If you only remember one section of this post, make it this summary of WordPress backup best practices. Print it, stick it next to your monitor, or hand it to whoever looks after your site.

PracticeHow oftenWho usually owns it
Full backup (files and database)Daily or weekly, based on how often content changesHost plus backup plugin
Database only backupDaily, more often for stores and formsBackup plugin
Off site copyEvery scheduled backupBackup plugin to cloud storage
Manual backup before changesBefore every update or big editWhoever makes the change
Test restoreQuarterly at minimumYour web team or you
Review retention and accessTwice a yearSite owner

Common mistakes that break WordPress backup best practices

Most failed restores we see come from skipping a few WordPress backup best practices. None of them are exotic, which is good news, because they are easy to fix once you know about them.

  • Trusting the default settings. Many plugins back up only the database out of the box, or store copies on the same server.
  • Ignoring failure emails. Backup plugins send warnings when a job fails. Those emails often go to an old address nobody checks.
  • Keeping too little history. Seven days is not enough to recover from a problem that hid for two weeks.
  • Never testing. A backup file that will not restore is just a large, expensive file.
  • Losing access. The cloud account holding the backups belongs to a former employee or an agency you no longer work with.

How WordPress backup best practices fit with updates and security

Backups are not a replacement for security or updates. They are the safety net under both. A well secured site can still be broken by a bad update, and a carefully updated site can still be hit by a stolen password.

In practice, WordPress backup best practices and updates work as one routine: take a backup, run updates, check the site, and keep the backup if something looks off. Pair that with a firewall, strong logins and regular scans, and you cover most of the ways a small WordPress site gets into trouble.

The official WordPress Advanced Administration Handbook has more detail on backups and server setup if you want to go deeper, and the WordPress.org documentation covers the basics of updating safely. For most consultants, though, the WordPress backup best practices above are enough.

Frequently asked questions

What are the most important WordPress backup best practices for a small business?

Back up both files and the database, keep at least one copy away from your host, back up before every update, and test a restore every quarter. Those four habits cover most real world problems on a small site.

How often should I back up my WordPress site?

Following WordPress backup best practices, it depends on how often the site changes. A brochure style consultant site is usually fine with daily database backups and weekly full backups. Sites with frequent blog posts, form leads or online orders need daily or more frequent backups.

Are my host’s backups enough on their own?

They are a good first layer, but most WordPress backup best practices recommend a second copy you control in separate cloud storage. If something happens to your hosting account, the host’s backups may be out of reach too.

Which backup plugin should I use?

UpdraftPlus, BlogVault, Jetpack VaultPress Backup and Duplicator are all well known options, and each suits slightly different needs. The plugin matters less than following WordPress backup best practices: off site storage, enough history and regular test restores.

Can Design Fly 24 manage backups for me?

Yes. Our maintenance plans follow the WordPress backup best practices in this guide: scheduled backups, off site copies, updates and periodic test restores, with a short monthly report so you know everything is working.

Make sure your next bad day is a short one

Following WordPress backup best practices is not glamorous work, and nobody will ever compliment you on it. But the day a plugin update breaks your homepage the morning a big client is reviewing your proposal, you will be glad the restore takes ten minutes instead of ten days.

If you would rather not think about any of this, that is what we do. We build sites through our website design services and look after them afterward, backups included. You can see some of the sites we care for on our work page, or book a free call and we will review your current backup setup with you.

Imtiaz Ahmed
Written by

Imtiaz Ahmed

Imtiaz is the founder of Design Fly 24, a New York web design agency. He has designed and launched 30+ websites for security consultants, expert witnesses, speakers, coaches and professional firms, and helps them turn their sites into steady lead sources through SEO and strong personal branding.

About ImtiazLinkedIn

Keep reading

All articles →

Ready for a website that works as hard as you do?

Design Fly 24 builds fast, search ready websites for consultants and experts across the US. No templates, no fluff. Just a site that earns trust and books calls.