Having a backup and having a reliable, restorable backup are two different things. Many business owners discover this when their site breaks and their backup turns out to be corrupt, incomplete, or gone. Here's how to do it correctly.
What to Back Up
A complete WordPress backup requires both: Files — your WordPress installation, wp-content folder (uploads, plugins, themes). Database — all your content, settings, users, and WooCommerce orders. Without both together, recovery is impossible.
How Often?
Daily minimum for any business WordPress site. WooCommerce stores processing orders: consider hourly database backups. Truly static informational sites: weekly may be acceptable.
Where to Store Backups
NEVER only on the same server as your site. If your server fails, both your site and your "backup" disappear simultaneously. Store backups offsite: Amazon S3, Google Drive, Dropbox, or Backblaze B2. Follow the 3-2-1 rule: 3 copies, on 2 different storage types, with 1 offsite.
How Long to Keep Backups
Minimum 30 days. Some hacks are not immediately obvious — you may not discover a compromise until weeks after it happened. Thirty days of history gives you a clean restore point.
Most Critical: Test Your Backups
An untested backup is not a backup you actually have. Untested backups fail more often than you'd expect. Test restoring from backup at least quarterly.
Recommended Plugins
UpdraftPlus: Most popular, reliable, free tier handles basics well. BackupBuddy: Premium, excellent for complete site backups. WPVivid: Solid free alternative with multiple remote destinations.
Need help with your WordPress site?
Fast Web Experts provides WordPress maintenance, security, speed, and expert support for small businesses. Start with a free audit — results in 24 hours.
Get a free WordPress site audit →