Skip to content
All articles
July 11, 2026·4 min read

Automatic WordPress Backups: Where to Keep Them So You Don't Lose Your Site When Hosting Goes Down

A real backup lives on a different server than your site, runs on its own, and has been tested by actually restoring it. Here's how to set it up.

It happens: you open your site and see a blank page or an error from your host. You call support and hear "we're working on it." At that moment the question isn't "when does the server come back" but "if it comes back, is my data still intact?". That's where the gap shows between people who had a real backup and people who only thought they did.

Many owners feel covered because their host "does backups." The problem is simple: if the copy sits on the same server that went down, it's gone with it. A backup worth the name lives somewhere else, runs automatically, and has been tested at least once with a real restore. In this article I'll show you exactly how to build one, no jargon.

Why a "backup on the host" isn't really a backup

The classic rule is called 3-2-1: keep three copies of your data, on two types of storage, with one of them in a separate location. A backup taken by your host breaks that last part, because it sits on the same infrastructure as the site.

The real problems aren't just "the server was down for an hour." They're:

  • A suspended hosting account (an unpaid invoice, a dispute, an error on their side) and you can't reach anything, backups included.
  • An infected site, where the host's copies already contain the malicious code.
  • A provider that shuts the service down on short notice or goes out of business.

In all of these, a copy that lives on a different server, one you can reach independently of the host, is the difference between a lost afternoon and a lost business.

What a complete backup must contain

A WordPress site has two parts that must be saved together, or the restore won't work:

  • The files: themes, plugins, uploaded images and documents, plus the configuration files.
  • The database: this holds your text, pages, comments, settings and user accounts.

If you have the files but not the database, you recover an empty site. If you have only the database, you recover text with no images and no design. That's why a serious backup takes both, at the same moment, so they stay in sync.

One detail that matters: keep several versions over time, not just the latest. If a site gets infected on Monday and you notice on Thursday, the only "fresh" copy is already compromised. With a few days or weeks of history, you can roll back to a clean version.

Where to keep the copies, concretely

The idea is to get the backup out of your host's reach. Good options, from simple to solid:

  • A cloud storage service separate from the host: Google Drive, Dropbox, an S3 bucket or Backblaze B2. The copy lands there automatically and you can reach it even if the site is down.
  • A dedicated WordPress backup service that keeps the versions on its own servers, not yours.
  • A copy downloaded locally, onto a drive of yours, as a last fallback.

Ideally you combine two: one automatic in the cloud plus one you download periodically. Also check how long copies are kept - some free services only hold a few days. And a commonly forgotten point: don't keep the password to your backup storage in the same place as everything else, so a single breached account doesn't cost you both.

Automate and test - otherwise it doesn't count

A manual backup you intend to run "when you have time" doesn't exist in practice. Automation is mandatory: pick a frequency that matches how often the site changes. A brochure site that rarely changes can run on a weekly backup; a shop with daily orders needs a daily backup, or even more often.

The part almost everyone skips: testing. A backup you've never restored is only a guess. At least once, take the latest copy and restore it into a test environment or a subdomain. That's how you learn whether the archive is complete and whether you know the steps before you're under pressure. An untested backup can leave you stranded on exactly the day it mattered.

How we do it at MPO Web Studio

When we build a site, the backup isn't an option you tick at the end - it's part of delivery. We set up automatic copies that leave the main server, keep a version history, and run at least one test restore before we call the site done. That way we know the plan actually works, not just that it exists.

We work fully remote, across the whole country, and we explain in plain terms where the copies live and how you reach them if you're ever without us - without depending on a single provider. Pricing is transparent, no hidden costs.

If you've already had a hosting scare or you're not sure your site is truly protected, message us on WhatsApp. We'll tell you honestly what you have and what's missing, even if the answer is that you're already in good shape.

Frequently asked questions

How often should I run backups?+

It depends on how often the site changes. For a brochure site that rarely changes, a weekly backup is enough. For an online shop with daily orders, you need a daily backup or even more frequent, so you don't lose orders and new customers between two copies.

Is a free backup plugin enough?+

It can be a good start, but check two things: that it sends the copy off the server (not to the same host) and that it can run automatically. Many free options save locally or keep only the latest version. What matters isn't who makes the backup, but where it lands and whether you've tested it with a restore.

My host says it does daily backups. Isn't that enough?+

It's a plus, but don't rely on it alone. If the server fails badly, your account is suspended, or the site is infected, the host's copy may be inaccessible or already compromised. An independent backup you can reach even when the host is unavailable stays essential.

How do I know my backup actually works?+

The only proof is a real restore. Take the latest copy and try to rebuild the site in a test environment or on a subdomain. If the site comes back complete, with images and content, you're covered. If something is missing, you found out now, not on the day of the crisis.

I already lost my site and have no backup. Can anything still be done?+

Sometimes yes. You can try recovery from the host, from caches, or from old copies left in various places. It's not guaranteed and depends on the situation. Message us on WhatsApp with the details and we'll tell you honestly what real chances there are before promising anything.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
Free · no obligation

Want to see what your business's website could look like?

Message us on WhatsApp and we'll prepare a FREE demo website with your business name. See it first — decide after.

Request a free demo websiteWe reply on WhatsApp within minutes