
No matter how secure or well-maintained your WordPress site is, having reliable backups is non-negotiable. Server hardware fails, plugins conflict, hackers strike, and accidental deletions happen. A good backup strategy means the difference between a 30-minute recovery and losing everything. This guide covers every approach from automated cloud backups to fully manual procedures.
The 3-2-1 Backup Rule: Keep 3 copies of your data, on 2 different storage types, with 1 copy stored off-site (cloud). This ensures recovery even if your server is completely destroyed.
What WordPress Is Made Of: Files + Database
Before you back anything up, you need to understand that a WordPress site does not store everything in one place. It splits across two parts that work together — and if you back up only one of them, your restore will produce an incomplete site that often will not load at all. Understanding this structure is the single most important foundation of the whole backup topic.
Think of a WordPress site like a restaurant: the database is the recipe book and the order tickets, while the files are the building, the kitchen, and the ingredients. Lose either one and the restaurant cannot open.
1. The Database — the Heart of Your Content
WordPress uses a MySQL/MariaDB database to store everything that is "text" and "settings", including:
- Content: all posts, pages, custom post types, categories, and tags
- Comments: every comment and its approval status
- Users: all accounts with their roles and hashed passwords
- Settings: site URL, site title, permalinks, and all plugin/theme options (stored in the
wp_optionstable) - Metadata: SEO data, custom fields, WooCommerce products and orders
The database is usually small (a few MB to a few hundred MB) but it changes the most often — every comment, order, or new post modifies it. That is why you should back it up more frequently than your files.
2. The Files — Structure and Media
All files live in the WordPress install directory (usually public_html/), in three main groups:
- WordPress Core: system files such as
wp-admin/andwp-includes/— these can always be re-downloaded from WordPress.org, so they are low risk - wp-content/: the most important folder, containing
themes/,plugins/, anduploads/(images, video, documents). Theuploads/folder is usually the largest and cannot be recreated if lost - Config files:
wp-config.php(database credentials and security keys) and.htaccess(rewrite/redirect rules) — tiny files you cannot do without
Easy rule of thumb: Database = "content and settings", Files = "appearance and media". A complete backup needs both, taken at roughly the same moment so they stay consistent (a fresh plugin file paired with an old database can leave plugin settings out of sync).
Method 1: UpdraftPlus (Recommended for Most Sites)
UpdraftPlus is the most popular WordPress backup plugin with over 3 million active installations. The free version supports Google Drive, Dropbox, S3, FTP, and email destinations.
Setup Steps
- Install UpdraftPlus from Plugins → Add New
- Go to Settings → UpdraftPlus Backups
- Set schedule: Files — Weekly, keep 4; Database — Daily, keep 7
- Choose remote storage (Google Drive recommended)
- Click Save Changes then Backup Now to test
What UpdraftPlus Backs Up
- Database: All posts, pages, settings, user accounts
- Plugins: Plugin files (not settings — settings are in the database)
- Themes: Active and installed themes
- Uploads: All media files in wp-content/uploads/
- Others: Any custom folders you specify
Method 2: DirectAdmin Backup Manager
If you host with AsiaGB, DirectAdmin includes a built-in backup tool that backs up your entire hosting account — files, databases, emails, and DNS settings.
- Log in to DirectAdmin → System Info & Files → Backup / Transfer
- Select Create Backup
- Check all items: Domain data, Databases, Email accounts
- Click Create Backup
- Download the generated
.tar.gzfile to your local computer
Tip: Schedule DirectAdmin backups to run automatically. Go to Cron Jobs and add a command to run the backup script weekly. Download the backup file off-site afterward.
Method 3: Manual Backup (phpMyAdmin + FTP)
For full control, back up manually. This approach works even without plugin access and is useful for recovery when the site is broken.
Database Backup via phpMyAdmin
- Open DirectAdmin → MySQL Management → phpMyAdmin
- Select your WordPress database from the left panel
- Click Export
- Choose Quick export, format SQL
- Click Export — save the
.sqlfile
Files Backup via FTP
- Connect with FileZilla or any FTP client
- Navigate to your WordPress root directory (usually
public_html/) - Download the entire directory to your local machine
- Pay special attention to:
wp-content/uploads/,wp-config.php,.htaccess
How to Back Up: UpdraftPlus Plugin vs Manual via DirectAdmin/phpMyAdmin
The two approaches most people use are the UpdraftPlus plugin and a manual backup via DirectAdmin/phpMyAdmin. Each suits a different situation, so this section walks through both step by step to help you choose correctly.
Approach A: UpdraftPlus (Automated, Inside the Dashboard)
Best when you can still log in to wp-admin and want backups to run automatically without remembering to trigger them:
- In WordPress admin go to Plugins → Add New, search
UpdraftPlus, then Install and Activate - Go to Settings → UpdraftPlus Backups → Settings tab
- Set Files backup schedule = Weekly, retain 4; and Database backup schedule = Daily, retain 7
- Under Choose your remote storage, pick Google Drive and click Authenticate to grant access
- Click Save Changes, then go to the Backup / Restore tab and click Backup Now to test (tick both Database and Files)
- Wait until the log shows
The backup apparently succeeded and is now complete, then confirm the files actually appear in Google Drive
Pros: set once and it runs itself, ships off-site to the cloud, and restores from the same screen. Limitation: if the site is so broken you cannot reach wp-admin, you cannot trigger a new backup through the plugin (though older backups still restore fine).
Approach B: Manual via DirectAdmin + phpMyAdmin (Full Control)
Best for taking a snapshot before risky work (major updates, theme changes) or when the site is broken and wp-admin is unreachable — because it works at the hosting panel level, independent of WordPress. AsiaGB Hosting uses DirectAdmin, so you can follow this immediately:
- Back up the database: log in to DirectAdmin → phpMyAdmin → click your WordPress database on the left → Export tab → choose Method Quick, Format SQL → click Go to download a
.sqlfile - Back up the files: return to DirectAdmin → File Manager → open
public_html→ Select All → Compress to.tar.gz→ download it to your computer - Or back up the whole account at once: DirectAdmin → Create/Restore Backups → Create a Site Backup → tick Databases + Domain settings → Create, then download the
.tar.gzfrom/home/[username]/
For peace of mind, open the .sql file once in a text editor and confirm it starts with phpMyAdmin's comment header and contains CREATE TABLE statements — an incomplete export is often 0 KB or cut off mid-file.
Caution: do not leave backup files sitting inside public_html. A .sql or .zip placed in a public web folder can be downloaded by anyone. Always pull backups off the server, then delete the server-side copies.
Restoring WordPress from Backup
Restore with UpdraftPlus
- Go to Settings → UpdraftPlus Backups
- Find the backup in the Existing Backups list (or click "Rescan remote storage")
- Click Restore
- Select components to restore (Database + Themes + Plugins + Uploads)
- Click Restore and wait — the process may take several minutes
Manual Restore
- Upload all WordPress files via FTP to your hosting account
- Create a new empty database in DirectAdmin → MySQL Management
- Import the
.sqlfile via phpMyAdmin → Import - Update
wp-config.phpwith the correct database name, username, and password - Visit your site — if URLs are wrong, run this SQL to update them:
UPDATE wp_options SET option_value = 'https://yournewdomain.com'
WHERE option_name = 'siteurl' OR option_name = 'home';
Restoring WordPress Step by Step (Full Site Failure)
When disaster strikes — a white screen, an "Error establishing database connection", or a hack — a manual restore from your backup files is the most reliable path. Follow this order without skipping steps:
- Prepare the backup: extract your
.tar.gz/.zipand have the database.sqlfile ready - Create an empty database: in DirectAdmin → MySQL Management → create a new database and note the name, username, and password
- Import the database: open phpMyAdmin → select the new database → Import tab → choose the
.sqlfile → click Go (if the file exceeds the limit, gzip it to.sql.gzand import that) - Upload the site files: use FTP (e.g. FileZilla) or File Manager to upload every file into
public_html, especially thewp-content/uploads/folder - Update wp-config.php: open
wp-config.phpand set the database name, username, and password to match step 2
define('DB_NAME', 'your_new_db_name');
define('DB_USER', 'your_new_db_user');
define('DB_PASSWORD', 'your_new_db_password');
define('DB_HOST', 'localhost');
Open the site — if all content returns, the restore worked. If you moved to a new domain, update the site URL in the database via phpMyAdmin's SQL tab:
UPDATE wp_options SET option_value = 'https://yournewdomain.com'
WHERE option_name = 'siteurl' OR option_name = 'home';
Finally, log in to WordPress admin → Settings → Permalinks → click Save Changes once (without changing anything) so WordPress rewrites the .htaccess rules. This step commonly fixes inner pages (single posts) returning 404 after a restore.
Order matters: restore the database first, then point wp-config.php at it. Doing it in reverse triggers "Error establishing database connection". And always back up the broken site before restoring over it, in case you need to recover recently added data later.
Automate Backups and Keep an Off-site Copy (the 3-2-1 Rule)
Occasional manual backups are "better than nothing", but the risk is that you forget — and the day the site really fails, your last backup may already be a month old. The fix is to automate and distribute storage using the 3-2-1 rule:
- 3 copies: keep at least three copies of your data (1 live + 2 backups)
- 2 media types: store them on two different storage types, e.g. one on the server and one in the cloud
- 1 off-site: at least one copy lives away from the live site (Google Drive, Dropbox, S3) in case the whole server has a problem
A practical layout you can set up today for a site on AsiaGB Hosting:
- Layer 1 — Hosting system: AsiaGB Hosting backs up automatically twice a month (on the 1st and 15th) as a baseline safety net
- Layer 2 — UpdraftPlus to the cloud: configure UpdraftPlus to back up the database daily and files weekly to Google Drive or Dropbox (this is your off-site copy)
- Layer 3 — A copy on your own machine: once a month, download the latest backup to your computer or an external drive
These three layers give you more than three copies, on different media, with an off-site copy — exactly satisfying 3-2-1. Whatever causes data loss, you always have a recovery point.
Retention tip: never keep just one backup that overwrites itself. If your site is hacked and the latest backup was taken after the malware was planted, restoring it brings the infection back. Keep several historical copies (e.g. 7 database, 4 files) so you can roll back to a point where the site was still clean.
Frequently Asked Questions
How often should I back up WordPress?
It depends on how often your site changes. News sites and online stores with daily orders should back up the database daily and files weekly (themes and plugins rarely change daily). For a company site or blog updated weekly, a full backup once a week is fine. Always take an extra backup right before risky work such as a major WordPress update or theme change.
What is the difference between UpdraftPlus and the DirectAdmin backup — which should I use?
UpdraftPlus works at the WordPress level, ships to the cloud, and restores easily from the dashboard, making it a great daily backup. The DirectAdmin backup works at the hosting-account level, backing up the whole account (files, databases, email), which suits snapshots before big changes or when wp-admin is unreachable. The best answer is to use both so they complement each other under the 3-2-1 rule.
I restored the database and got "Error establishing database connection" — what now?
That error means WordPress cannot reach the database. The usual cause is that the database name, username, or password in wp-config.php does not match the database you just created. Open wp-config.php and verify DB_NAME, DB_USER, and DB_PASSWORD against what you set in DirectAdmin → MySQL Management, and confirm DB_HOST is localhost.
Does AsiaGB Hosting include automatic backups?
Yes. AsiaGB Hosting backs up automatically twice a month (on the 1st and 15th) on DirectAdmin at no extra cost. Even so, we recommend configuring UpdraftPlus to ship to the cloud and downloading your own copy as well, so you fully satisfy the 3-2-1 rule and control your recovery points.
WordPress Hosting with DirectAdmin Backup Manager
AsiaGB Hosting includes DirectAdmin with built-in backup tools and one-click restore. Store backups on our servers or download them off-site. Starting at 500 THB/year.
View Hosting Plans →