The WordPress Backup Checklist
Nobody thinks about backups until they need one. That’s why I keep a simple backup checklist.
Then it’s the only thing they can think about.
A plugin update breaks the site. A hacker gets in. Someone deletes the wrong page. The host has a server problem. It happens to everyone eventually, and when it does, a good backup turns a disaster into a minor inconvenience.
The problem is that most people either don’t have backups, or they think they do but don’t really. So here’s a simple backup checklist to make sure yours are actually there when you need them.
1. Back up the right things
A WordPress site is really two parts, and you need both:
- Files: WordPress itself, your themes, plugins, and everything in the uploads folder (images, PDFs and so on).
- Database: your posts, pages, settings, users, orders, form entries. Basically, all your content.
A backup with only one half isn’t a backup. Make sure your tool grabs both.
2. Set the right schedule
How often should you back up? It depends on how often your site changes.
- Most small business sites: every two weeks is a good baseline. With UpdraftPlus I set files and database to fortnightly and keep the last 2 backups, which covers about a month.
- Sites that change daily (online stores, membership sites, busy blogs): back up the database daily. Orders and signups happen all the time, and you don’t want to lose a week of them.
- Before any big change: always make a fresh backup before updates, theme changes or redesigns. No exceptions.
I walk through the UpdraftPlus setup in my Monthly WordPress Maintenance Checklist.
3. Store them in the right place
This is where most people get burned.
A backup stored on the same server as your website isn’t much of a backup. If the server crashes, gets hacked, or your hosting account gets suspended, your backups go down with it.
Send your backups somewhere else: Google Drive, Dropbox, Amazon S3, or another remote storage service. UpdraftPlus connects to these in a few clicks, even in the free version.
The 3-2-1 rule: keep 3 copies of your data, on 2 different types of storage, with 1 of them off-site. You don’t have to be that strict for a small website, but at minimum: one copy on the server, one copy somewhere else.
4. Don’t rely only on your host
Many hosts include backups, and that’s great. Keep using them. But don’t make them your only backup.
- Host backups are usually stored on the host’s own systems.
- Some only keep a few days of history.
- Restores sometimes require a support ticket (and sometimes a fee).
- If you ever leave that host, or have a billing problem, those backups may disappear.
Your own backups, in your own storage, are the ones you control.
5. Test a restore
A backup you’ve never restored is a guess.
Every few months, restore a backup to a staging site or a test install and make sure it actually works. You’ll learn how the process goes while things are calm, instead of figuring it out in the middle of an emergency.
6. Check them every month
Backups fail quietly. A full storage account, an expired connection to Google Drive, a plugin that got deactivated. Nothing tells you until you need it.
Once a month:
- Check the date of the latest backup.
- Look in your remote storage and make sure the files are actually there.
- Glance at the backup log for errors.
7. Back up the stuff outside WordPress
Your website isn’t the only thing you’d hate to lose:
- Logins: keep your hosting, domain registrar, DNS and WordPress logins in a password manager.
- DNS records: take a screenshot or export of your DNS settings, especially your email records.
- Email: if your business email isn’t with a provider like Google Workspace or Microsoft 365, make sure it’s backed up too.
The backup checklist
- Back up both files and database
- Schedule it: fortnightly for most sites, daily database backups for stores
- Always back up before updates and big changes
- Store copies off the server
- Keep your own backups, not just your host’s
- Test a restore every few months
- Check monthly that backups are actually running
- Keep logins and DNS records saved somewhere safe
Backups aren’t exciting. But the day you need one, you’ll be very glad you took twenty minutes to set this up.
For the bigger picture on protecting your site, check out my book WordPress Security Made Simple: The No-Nonsense Guide to Protecting Your WordPress Site. And if you’d rather have someone handle backups and maintenance for you, that’s what WP Just Fix It does.
