WordPress backups and recovery: getting it right

WordPress Backups & Recovery

This is part four of the Lucid Cloud Platform WordPress security series. If you are just getting started, begin with the complete WordPress security guide. For backups beyond WordPress, see our guide to website and email backups.

Every other step in this series is about keeping trouble out. This one is about getting back on your feet quickly if trouble ever gets in. No defence is perfect, so a good backup and a clear recovery plan are what turn a serious incident into a minor one. Here is how to back up WordPress properly, and what to do if the worst happens.

What to back up, and how often

A complete WordPress backup has two parts: your files, which include themes, plugins and uploads, and your database, which holds your posts, pages, settings and users. A backup missing either one cannot fully restore your site. Run backups automatically, at least daily, and more often for a busy shop where even an hour of lost orders matters.

Where to keep your backups

A backup stored only on the same server as your site is not really a safety net, because the problem that takes down your site can take the backup with it. Keep at least one copy in separate, off-site storage. Keep a rolling history too, not just the latest copy, so that if a problem goes unnoticed for a few days you can still step back to a point before it started.

Test your restores

This is the step almost everyone skips, and the one that matters most. A backup you have never restored is only a promise. Every so often, restore your latest backup to a staging copy of your site and confirm everything comes back as expected. Discovering a broken or incomplete backup during a real emergency is a horrible way to learn the lesson, so prove it works while the pressure is off.

Backup plugins or host-level backups

You can back up WordPress with a plugin, or rely on backups provided at the hosting level. Plugins give you fine control and run inside WordPress, while host-level backups run independently of your site, which means they still work even if WordPress itself is broken. The strongest position is to have both, but if you choose one, host-level backups that store copies off-site and offer a one-click restore take the most worry off your plate.

Recovering a hacked WordPress site

If your site is compromised, stay calm and work in order. Panic and random deletions usually make things worse.

  • Take the site offline or into maintenance mode, so visitors are not exposed to anything harmful while you work.
  • Restore a clean backup from before the compromise if you have one. This is by far the fastest route back to a known-good state.
  • If you have no clean backup, scan for malware with a reputable tool, reinstall WordPress core, and replace your themes and plugins with fresh copies from their official sources rather than trusting the existing files.
  • Change every password and security key, including your WordPress users, hosting account and database. Assume anything the attacker could reach has been seen.
  • Update everything and remove any plugin or theme you do not recognise, then keep a close eye on the site for a while afterwards.

Throughout, do not be afraid to ask your host for help. A good support team handles this kind of thing regularly and can often spot what an untrained eye would miss. With Lucid Cloud Platform, automated off-site backups and one-click restore mean that, for most incidents, recovery is a matter of minutes rather than a lost weekend.

The full WordPress security series

This site uses cookies to offer you a better browsing experience. By browsing this website, you agree to our use of cookies.