Learning how to back up a WordPress website is the single most important maintenance skill a site owner can have. One bad plugin update, one hacked admin account, or one host failure can wipe out months of work — and a good backup turns that disaster into a 10-minute restore.
The good news: in 2026 you have three solid options. A free plugin like UpdraftPlus handles everything automatically. Your hosting control panel (cPanel) can create full backups on demand. And most good hosts keep their own backups too. You don’t need to be technical for any of these — follow the steps below and you’ll have real protection by the end of the day.
Why WordPress Backups Matter More Than You Think
Your WordPress site is really two things: files (themes, plugins, uploads — everything in your wp-content folder) and a database (all your posts, pages, comments, and settings). A backup that misses either one is incomplete.
Here’s what can go wrong without a backup:
- A plugin or theme update breaks your site’s layout or code
- Your site gets hacked and files get infected
- You accidentally delete pages or media
- Your host has a server failure or you get locked out of your account
Most hosting companies keep server backups, but you can’t rely on them alone — they’re often stored on the same infrastructure as your site, sometimes overwritten weekly, and some hosts treat them as “courtesy” backups they don’t guarantee. Your own independent backup, stored somewhere your host doesn’t control, is the only protection you truly own.
The 3-2-1 Backup Rule (Your Safety Net)
Before the how-to, learn the rule professionals use: keep 3 copies of your data, on 2 different types of storage, with 1 copy offsite (somewhere other than your host).
For a WordPress site, that translates to:
- Your live site (copy one)
- Your host’s automated backup (copy two, different system)
- Your own backup stored in cloud storage like Google Drive or Dropbox (copy three, offsite)
If you follow just one method from this guide — the UpdraftPlus + Google Drive setup below — you’ll satisfy the rule automatically.
Method 1: Back Up with UpdraftPlus (Easiest, Recommended)
UpdraftPlus is the most-installed WordPress backup plugin for a reason: the free version handles scheduled backups and offsite cloud storage with no code and no configuration files. Here’s the full setup.
Step 1: Install and activate the plugin
In your WordPress dashboard, go to Plugins > Add Plugins, search for “UpdraftPlus,” and click Install Now, then Activate. A “Backup/Restore” option appears in your admin menu.
Step 2: Choose your backup schedule
Go to Settings > UpdraftPlus Backups and click the Settings tab. You’ll see two schedule dropdowns:
- Files backup schedule — set this to Weekly for most sites
- Database backup schedule — set this to Daily, because your posts and comments change more often than your theme files
The free version lets you schedule every 2, 4, 8, or 12 hours, daily, weekly, fortnightly, or monthly. For a typical blog, weekly files + daily database is the sweet spot.
Step 3: Connect a cloud storage destination
This is the crucial step. Scroll to “Choose your remote storage” on the Settings tab and click the icon for your preferred service — Google Drive is the simplest for most people. Click Save Changes at the bottom, then follow the authorization popup: sign in with your Google account, grant UpdraftPlus permission to manage its backup folder, and click Complete setup.
The free version supports Google Drive, Dropbox, Amazon S3, Rackspace Cloud Files, FTP, DreamObjects, OpenStack Swift, and email. If you need OneDrive, Backblaze, SFTP, or Google Cloud, that’s the Premium version.
Why cloud storage matters: if your hosting account itself is compromised or the server dies, a backup stored on that same server dies with it. Google Drive or Dropbox keeps your backup truly independent.
Step 4: Set retention and save
Decide how many backup copies to keep: at least 3–4 copies for files and 7–14 copies for database backups is a safe baseline. Then click Save Changes.
Step 5: Run your first backup
Go back to the Backup/Restore tab and click Backup Now. Choose to include both your database and files, check the box to send the backup to remote storage, and start the backup. It’ll appear under “Existing backups” when done — and from there, one click restores your whole site.
Is UpdraftPlus Premium worth it?
For most small sites, no — the free version covers everything above. Premium adds value in specific cases: incremental backups (only changed files, so big sites back up faster), automatic backups before plugin/theme updates, multiple simultaneous storage locations, time-of-day scheduling, and multisite support. If you run a WooCommerce store or a high-traffic site, consider it; otherwise free is plenty.
Method 2: Manual Backup with cPanel (Full Control)
If your host uses cPanel (Namecheap, A2, and many others do), you can create complete backups without any plugin. It’s manual — no automation — but it gives you a file you fully own.
Option A: The cPanel Backup Wizard (full backup)
- Log in to cPanel (usually at
yourdomain.com/cpanel). - Find the Backup or Backup Wizard icon under the Files section.
- Click Back Up, then choose Full Backup. This grabs everything: your home directory, databases, email accounts, and FTP settings.
- Choose where to save it — Home Directory is the standard choice. Click Generate Backup.
- Wait while cPanel packages everything (big sites can take a while). When it’s done, download the file and store it somewhere safe — your computer, an external drive, or cloud storage.
Important limitation: a full backup generated this way usually can’t be restored by you through the wizard — your host’s support typically has to restore it. Great for disaster recovery and migration, not quick self-service rollbacks.
Option B: Manual files + database (the DIY two-step)
This backs up the two parts of your WordPress site separately, and it gives you restores you can do yourself.
Back up your files:
1. In cPanel, open File Manager.
2. Select your public_html folder (or wherever WordPress is installed).
3. Click Compress to zip it, then Download the zip.
Back up your database:
1. In cPanel, open phpMyAdmin under the Databases section.
2. In the left sidebar, click your WordPress database. (Not sure which one? Check your wp-config.php file — the DB_NAME line tells you.)
3. Click the Export tab at the top, choose Quick export method and SQL format, then click Go. Your browser downloads the database file.
Store both files offsite. Together, they can rebuild your site from scratch on any host.
Method 3: Use Your Host’s Built-In Backups
Most quality hosts in 2026 include automatic backups:
- Hostinger: weekly backups on Premium, daily on higher plans, with one-click restore from hPanel
- SiteGround: daily automated backups with 30-day retention on every plan, plus on-demand backups on GrowBig and up
- DreamHost: daily automated backups with one-click restore
These are genuinely useful for quick rollbacks — a bad plugin update on Tuesday can be undone from Monday’s backup in minutes. But they’re stored on the host’s infrastructure, so treat them as a great layer of your strategy, not your only layer. Check your host’s dashboard for the retention window (7 days? 30 days?), confirm restores are free, then add your own UpdraftPlus backup on top — and you’re following the 3-2-1 rule. If you’re still choosing a host, our WordPress blog setup guide walks through picking a beginner-friendly plan.
How Often Should You Back Up?
Match the frequency to how often your site changes:
| Site type | Files | Database |
|---|---|---|
| Static site (rarely updated) | Monthly | Monthly |
| Typical blog (posts weekly) | Weekly | Daily |
| Active blog/business (daily content) | Weekly | Daily |
| WooCommerce/store | Daily | Every 4–6 hours (or real-time with a dedicated service) |
Non-negotiable rule: take a manual backup before any major change — a theme switch, a WordPress core update, a new plugin, or a host migration.
Also: backups are useless if they’re corrupt. Once in a while, spot-check that your backup files actually download and have a reasonable file size. A 0 KB backup file is a nasty surprise to discover during a crisis.
Quick Disaster Checklist
When something goes wrong, don’t panic — work this list:
- Identify what broke: a plugin update? A theme edit? A hack? Check your host’s error logs or recently changed items.
- Restore the most recent clean backup via UpdraftPlus’s Restore button or your host’s one-click restore.
- Test the site: load the homepage, check the admin dashboard, submit a test form or order.
- Fix the root cause (update the broken plugin, change your passwords, patch the theme) before it happens again.
- Update your backups so the new, working version is the one stored.
The whole process should take under 15 minutes with UpdraftPlus. Without a backup, it takes days and costs money.
Related: How to Speed Up WordPress Without Plugins (2026)
Frequently Asked Questions
What’s the best free WordPress backup plugin in 2026?
UpdraftPlus is the most popular and capable free option — scheduled backups, Google Drive/Dropbox/S3 storage, and one-click restore. Solid free alternatives include BackWPup and Duplicator’s free tier. All of them cover the essentials; UpdraftPlus has the smoothest beginner experience.
Do I need a backup plugin if my host makes backups?
Yes. Host backups are a great safety layer, but they’re stored on the host’s infrastructure, may have short retention windows, and some hosts don’t guarantee them. Your own independent backup (UpdraftPlus + Google Drive, for example) costs nothing and protects you if the host itself has a problem.
How do I back up WordPress without a plugin?
Use cPanel: the Backup Wizard’s Full Backup option packages your entire account, or do the manual two-step — compress and download your public_html folder via File Manager, then export your database as SQL through phpMyAdmin. Store both files offsite.
Where should I store my WordPress backups?
Follow the 3-2-1 rule: 3 copies, 2 storage types, 1 offsite. Practically: your host’s backup + a plugin backup sent to Google Drive, Dropbox, or Amazon S3. Never keep your only backup on the same server as your site.
How do I restore my WordPress site from a backup?
With UpdraftPlus, go to Settings > UpdraftPlus Backups > Backup/Restore, pick the backup date under “Existing backups,” and click Restore. For manual backups, import the SQL file via phpMyAdmin and upload/extract your files zip via File Manager. Host backups usually restore through a one-click button in your hosting panel.
How often should I back up my WordPress site?
Weekly file backups + daily database backups works for most blogs. Online stores need daily or more frequent backups. Always take a manual backup before updates, theme changes, or migrations — regardless of your schedule.
