inCloudServer guide

WordPress Backup: Files, Database, Frequency & Restore Checklist

A complete WordPress backup is more than a copy of the uploads folder. A typical WordPress site has two major parts that must be recoverable together: the files and the database. If either side is missing, a full restore may be impossible or incomplete.

WordPress’s official backup documentation recommends regular backups and specifically notes that the database and files are separate. This guide turns that into a practical backup strategy for business websites, WooCommerce stores and sites preparing for updates or migration.

What does a complete WordPress backup include?

Backup component What it contains Why it matters
Database Posts, pages, comments, users, many settings and application data stored in MySQL/MariaDB. A file-only backup usually cannot recreate the current content or application state.
wp-content Uploads, themes, plugins and other site-specific files. This is where much of the site’s custom content and code lives.
Configuration files wp-config.php, web-server configuration and other environment-specific files where applicable. They can be needed to reconstruct database connectivity, redirects and site behavior.
Other custom files Custom scripts, static files, verification files or directories outside the standard WordPress structure. These are easy to miss if a backup tool only understands a default WordPress install.

Official reference: WordPress Backups and Backing Up Your WordPress Files.

How often should you back up WordPress?

The right frequency depends on how much data can change between backups and how much loss the business can tolerate.

Site type Planning approach
Mostly static brochure site Regular scheduled backups plus an additional backup before updates or major changes may be sufficient.
Active blog or membership site Back up often enough that recent posts, users and comments can be recovered within your acceptable data-loss window.
WooCommerce store Orders, customers and inventory can change continuously. A once-a-week copy may be far too old after an incident.
Site being updated or migrated Create a current backup immediately before the risky change and keep it separate from the environment being modified.

WordPress’s handbook says backup frequency should reflect how often the site changes. For a business, turn that into a recovery objective: how much recent data could you afford to lose?

Hosting backup vs independent backup

Hosting-level backups are useful, but they should not be confused with an independent recovery strategy. A backup stored only inside the same account or infrastructure can be harder to reach if that account is compromised, suspended or inaccessible.

A stronger plan uses more than one recovery path where the business risk justifies it. That can include host-provided backups, a separate backup service and periodic downloadable copies stored outside the production account.

What the current inCloudServer Website Backup plans include

The current reseller catalog offers 5 GB, 25 GB and 50 GB Website Backup tiers. The current product descriptions list:

  • Automatic daily backups.
  • Built-in daily malware scanning.
  • File, folder or database backup support.
  • Continuous security monitoring.
  • Downloads to local storage.
  • One-click restore.
  • Secure cloud storage.
  • One website per account.

Use the live Website Backup plans for current pricing, storage limits and final product terms rather than relying on an old static price.

How much backup storage do you need?

Do not size backup storage from the compressed WordPress installation alone. Include the database, uploads, media growth and the number of recovery points the service retains within its current product design.

  • Small document-heavy sites: may fit the smaller tier if the complete protected data set remains comfortably below the limit.
  • Photo-heavy sites: images can make wp-content/uploads the largest part of the backup.
  • Video/multimedia sites: large media files can consume backup capacity quickly; confirm whether those files should live in WordPress at all.

Leave room for growth rather than selecting a tier that is already close to full on day one.

Back up before WordPress updates

Before a significant WordPress core, plugin or theme update, make sure you have a recent recovery point. A backup is especially important when the update touches ecommerce, authentication, page builders, payment integrations or a custom theme/plugin stack.

Staging and backups solve different problems: staging lets you test a change away from production; a backup gives you a recovery point if production still goes wrong.

Backups before a WordPress migration

A migration should begin with a restorable copy of the source site. Keep the backup independent from the source account so a failed migration or account problem does not remove the rollback path.

Use our WordPress Migration guide for the full files/database, staging, DNS, SEO and cutover checklist.

WooCommerce backup strategy

A WooCommerce store changes more frequently than a brochure site because orders, customers, inventory and transactional data can be created throughout the day. Restoring an old database can overwrite newer orders.

Define how much transaction data can be lost and choose the backup/recovery approach accordingly. Test restores on a non-production environment when possible, and coordinate backup timing with migrations or maintenance windows.

For hosting selection, compare WooCommerce Hosting and review our WooCommerce requirements guide.

How to verify that a WordPress backup is actually useful

  • Confirm both database and required files are included.
  • Verify the backup completed successfully rather than merely being scheduled.
  • Know where the backup is stored and how administrators can access it.
  • Document the restore procedure before an emergency.
  • Test a restore periodically on staging or another safe environment.
  • Check that important custom directories, uploads and configuration files are not excluded.
  • Keep credentials and encryption keys needed for restore accessible to authorized staff.

Backup vs website security

Backups do not prevent attacks, and malware scanning does not replace backups. Security tools aim to reduce or detect compromise; backups give you a recovery path after data loss, corruption or a bad change.

Compare Website Security if you need malware scanning/removal, firewall or other current protection features in addition to backup.

Need a separate website backup service?

Compare the current 5 GB, 25 GB and 50 GB Website Backup tiers, live pricing and current recovery features.

Compare Website Backup plans →

Frequently asked questions

Does backing up WordPress files also back up the database?

Usually no. WordPress files and the database are separate components. A complete recovery plan normally needs both.

How often should I back up WordPress?

Back up often enough to meet the site’s acceptable data-loss window, and create a fresh recovery point before significant updates, migrations or other risky changes.

Is a backup plugin enough?

It can be part of the strategy, but verify what it includes, where backups are stored, whether jobs complete successfully and whether you can restore the site when the production environment is unavailable.

Do I need backups if my host already backs up the server?

First understand exactly what the hosting backup covers, how long recovery points are kept and how restores work. Businesses with higher recovery requirements may choose an additional independent backup path.

Related guides

Keep learning.

Pin It on Pinterest

Share This

Share This

Share this post with your friends!