
Someone told you to keep backups, and you nodded. Then the questions started. Does your host already make them? What is actually in one? Where do the copies live, and how far back do they go? The worry underneath is simple: the day you need a website backup, it might be missing, too old, or unable to bring the site back. You do not need to become a developer to settle this. You need to know what a full copy contains, where it should be kept, and how to prove it works before a bad day arrives. You can check most of it yourself in about fifteen minutes.
Key Takeaways
It covers site files, the database, media and settings, plus the records around the site: hosted email, DNS records and the logins to your domain, host and platform.
A backup stored only inside the same hosting account depends on that account staying healthy and reachable, so keep at least one copy somewhere else.
Restore a recent copy to a staging or test site, check the pages that earn money, and write down the date and result.
Know Exactly What Your Website Backup Needs to Cover
A complete website backup includes the website files, the theme and plugins, uploaded images and documents, the database, configuration files and site settings. The database matters more than it looks. On a WordPress site it holds your pages, posts, form entries and, for a store, products and orders. The files hold the design and the media. A backup with one and not the other will not rebuild a working site.
Then there are the things around the site that a normal backup often leaves out. If your email runs on the same hosting account, confirm separately that mailboxes and messages are backed up. Save a copy of your DNS records, because they point your domain to your site and your email. Keep a current list of who holds the logins for your domain registrar, your host and your website platform, along with the payment and integration accounts the site depends on, such as the payment processor, booking tool or email list service.
| Item | What it holds | Usually in a host backup? |
|---|---|---|
| Site files, theme and plugins | The design, code and features | Usually, but confirm |
| Uploaded media | Photos, PDFs and video | Usually, but confirm |
| Database | Pages, posts, forms, products and orders | Usually, but confirm |
| Configuration and settings | How the site is set up to run | Usually, but confirm |
| Hosted email | Mailboxes and messages | Check separately |
| DNS records | Where your domain sends web and email traffic | Keep your own copy |
| Account access | Domain, host, platform and integration logins | Keep your own record |
"Usually, but confirm" is the key phrase. The only way to know what your plan covers is to read your provider's own documentation or ask them in writing.
Find Out What Your Host Already Keeps in Fifteen Minutes
Before you buy anything, find out what you already have. Log in to your hosting account, WordPress dashboard, or builder admin and look for a section called Backups, Restore, Site History or similar. Then write down the answers to these questions:
- Latest backup: The date and time of the most recent successful backup.
- Oldest restore point: How far back the available copies go.
- What it includes: Database, media, theme, plugins, products, orders and settings.
- Where copies are stored: Inside the same hosting account, or somewhere separate.
- Download option: Whether you can download a copy or export your content.
- Who can restore: The account or person with permission to run a restore.
- Restore terms: Any fees or limits the provider lists for restoring.
- Last test: The date and result of the last time anyone restored a copy.
If the screen does not answer a question, ask your host or maintenance provider for written answers on backup scope, how long copies are kept, how a restore works and what it costs. A written reply gives you something to check against later, and it tells you quickly where the gaps are.

If every answer comes back clear, and your host keeps copies long enough and somewhere separate, you may not need anything new. Keep what you have and put a test restore on the calendar. Buying a second backup product only makes sense when you can name the gap it fills: scope, how long copies are kept, where they are stored, alerts when a backup fails, access, or testing.
See What Your Platform Backs Up by Default
Each platform handles backups differently, and the names can be confusing. A revision history, an export file and a restorable backup are three different things. A revision lets you roll back changes inside the platform. An export gives you some of your content in a file. A restorable backup brings the whole working site back. The details below come from each provider's own help pages; check them again for your plan, because plans and terms change.
| Platform | What it provides | What to watch |
|---|---|---|
| WordPress.com Business and Commerce | Automatic backups at least daily, kept six months while eligible | Copies kept 30 days after plan removal |
| GoDaddy Website Backup | Restores from successful daily backups in the previous 90 days | Confirm which plan and product you have |
| Wix | Site History revisions and manual site duplication | No complete external backup; duplicate stays in your Wix account |
| Squarespace | Partial export in WordPress XML format | Store pages, drafts and style settings are not exported |
| Shopify | CSV exports and theme downloads | Settings such as taxes, shipping, checkout and payments are rebuilt by hand |
WordPress.com and GoDaddy
WordPress.com's backup documentation says sites on its Business and Commerce plans are backed up automatically at least once a day, with backups kept for six months while the site stays eligible and for 30 days after the plan is removed. GoDaddy's Website Backup help page describes restoring from successful daily backups made in the previous 90 days. Both are useful starting points, and both still leave you to confirm whether the copies sit outside the account and whether email and DNS are included.
Wix
Wix saves revisions in Site History when you save or publish, and you can duplicate a site inside your account as a manual copy. Wix's help center says a complete backup stored outside Wix is not currently available, and a duplicate does not update when you change the original. For a Wix site, keep your own record of page text, images, forms and settings, and duplicate the site before large changes.
Squarespace
Squarespace's export page explains that an export covers selected pages, text and image blocks, one blog, comments up to 1,000 per post, and some gallery content, in WordPress XML format. It leaves out store pages, product blocks, video blocks, drafts, style settings, custom CSS and parts of the site structure. Treat the export as a copy of your words and some images, and keep your original photos and files somewhere of your own.
Shopify
Shopify's backups and duplication page explains that you can export CSV files for products, customers, orders and other store data and download your theme, then combine them into a backup. Store settings such as taxes, shipping, checkout and payments have to be set up again by hand, and some content, including menus, blog content, apps and reports, may need manual rebuilding too. Orders cannot be imported through the standard admin. Export your CSV files on a schedule and keep them outside Shopify.
If your platform's exports leave out too much, that is worth knowing now, before a plan change or shutdown forces the question. What to save when a platform changes its terms is covered in what to do when your website builder is shutting down or changing plans.
Pick a WordPress Backup Setup That Fits Your Site
A WordPress site gives you more choices than a builder does. There are four practical routes, and they can be combined:
- Host backups: Convenient and often included. They can be limited by how long copies are kept, by sharing the same infrastructure as the live site, by who can reach them, or by restore fees.
- A WordPress backup plugin: Runs on your site and sends copies to storage away from your host, such as a cloud storage account you control.
- A managed backup service: Automated schedules, off-site storage, activity logs and one-click restores, for a monthly or yearly fee.
- Manual exports: An occasional extra copy you download yourself, useful before a big change.
As one example of a managed service, Jetpack VaultPress Backup offers real-time cloud backups, 10 GB of starting storage, a 30-day archive and one-click restores. Jetpack's pricing page lists it at $9.95 a month billed yearly, with a lower promotional price of $4.95 a month for the first year. Plugin prices change with plans and promotions, so check the checkout page before you commit to any website backup plugin.
Match the choice to the site. A small brochure site that changes once a month can often rely on host backups plus an off-site copy. A store that takes orders every day needs frequent backups and a restore process that will not wipe out the orders placed since the last copy. Make a fresh copy before updates; the checks to run around a plugin update are in what to do when you get a WordPress plugin vulnerability warning.

Keep a Copy That Survives a Bad Day at Your Host
A backup that lives in the same account as the site shares its risks. If the account is locked, the plan lapses, or the host has an outage, the live site and its backups can go missing together. That is why separate storage appears in the federal guidance. NIST's backup controls (control CP-9 in SP 800-53) call for protecting backups, testing them, and storing critical backup information separately from the live system. CISA's #StopRansomware Guide advises keeping offline, encrypted backups of critical data and regularly testing their availability and integrity.
For a small business site, that can be as plain as a plugin or service that sends copies to a cloud storage account you own, plus an occasional downloaded copy kept offline. What matters is that you can reach at least one copy without logging in to the host that runs your site.

Access belongs in the same plan. Record which accounts hold your domain, host and platform, and make sure more than one trusted person at the business can log in. A perfect backup is no help if the only person who can restore it is unreachable.
Prove the Backup Works With a Safe Test Restore
A backup that finished without an error is not yet proof that it restores. The test is to bring a copy back somewhere safe and check that the site works. Done this way, the live site stays untouched while you learn exactly what a restore involves. The steps below cover where to restore, what to check and what to record.
Restore to a place that is not your live site
Never test by overwriting the live site. Restore a recent backup to a staging site, a temporary subdomain, a local WordPress install, or a separate test installation. Check whether your hosting control panel includes a staging option. If it does not, ask your host or developer to set one up for the test.
Check the parts of the site that earn money
Walk through the restored copy as a customer would. Open the homepage and your most important pages. Confirm that images load, menus work, forms send, logins work and redirects still point to the right places. On a store, check products, the cart and recent orders. On any site, compare the newest content in the restored copy with the live site to see how much recent work the backup would lose.
Write down what happened
Record the backup date, how long the restore took, anything missing and every step you had to take. That note becomes your restore runbook, the instructions someone else can follow if you are not there. If something was missing, fix the backup settings and test again.

A restore can also bring back problems. If the site was ever compromised, an older backup may carry the same damage, so pick a known-clean copy and scan it before trusting it. And restoring an older copy over a live store can replace orders, messages and form entries made since that copy was taken, which is why you reconcile recent records before any real restore.
Set a Testing Schedule You Can Keep
NIST's guidance says backups should be tested for reliability and integrity, and that restoring a sample should be part of contingency testing. NIST SP 800-34, its contingency planning guide, adds recovery procedures and data testing to the plan. None of this sets a legal schedule for a small business, so pick one you will actually keep.
A practical website backup testing schedule
- 1
Weekly
Confirm the latest backup finished successfully, or check that failure alerts are switched on and go to someone who reads them.
- 2
Monthly or quarterly
Restore part of the site, such as a few pages and their images, to staging and check it works.
- 3
Once a year
Run a full recovery test to staging and update your written restore steps.
- 4
After any big change
Test again after a new host, a redesign, a platform move or a major plugin change.
Stores and sites that change every day need testing more often, because each day between copies is a day of orders or leads you could lose. For backup frequency itself, the useful question is how much recent work you could afford to redo. If the answer is a day, back up at least daily. If the answer is a week, weekly may be enough.
Know When a Website Backup Service Is Worth Paying For
You can run the first check yourself, and for a simple site that may be all you need, plus a test on the calendar. Outside help earns its cost in specific situations: the site brings in meaningful revenue, you cannot confidently restore it yourself, several systems have to be brought back together, your platform's exports leave out too much, or nobody at the business owns the restore test.
A good website backup service does specific, checkable work. It documents what is backed up, moves a copy away from the host, switches on failure alerts, records who holds each login, restores to staging, tests forms and checkout, and leaves you a written recovery record. What it cannot do is promise that nothing will ever go wrong. It shortens recovery when something does.
Would your website backup actually bring your site back?
Pick an answer to begin.
1. Your host says it backs up your site daily. What should you confirm next?
2. What is the safest way to test a restore?
3. Which of these is a restorable backup rather than a partial export?
Frequently Asked Questions About website backup
Does my host automatically back up my website?
Sometimes. Check your plan's documentation for what is backed up, how often, how long copies are kept, where they are stored and whether restores cost extra. If it is not written down, ask your host.
What does a website backup include?
Usually the site files and the database. Media, settings, hosted email, DNS records and account access may be separate, so confirm each one.
Is one host backup enough?
It helps, but a second copy stored away from the host means you can still recover if the hosting account itself has a problem.
What is the best website backup plugin for WordPress?
The right one sends copies off your host, runs on a schedule, alerts you when a backup fails and restores cleanly in a test. Managed services such as Jetpack VaultPress Backup add one-click restores for a monthly or yearly fee.
Can I back up a Wix, Squarespace or Shopify site?
Each offers revision history or partial exports, and none gives a complete independent copy by default. Export what you can on a schedule and keep your own copies of images, files and store data.
How long should I keep website backups?
Long enough to cover a problem you might not notice right away. A copy from before the problem started is only useful if it still exists when you find it.
Moving Forward
A website backup you can trust has three parts. It covers the files, database, media and settings, plus the email, DNS and logins around the site. At least one copy lives away from your host. And it has been restored to a test site at least once, with the result written down. Start with the fifteen-minute check in your own panel, and let the answers tell you whether anything needs to change.
Once that is in place, a broken update or a lost page becomes a restore you have already practiced, not a scramble. You know where the copies are, how far back they go and who can bring the site back.
If you would rather hand the checking to someone else, Web Leveling can run the audit with you, set up off-host copies and test a restore on staging. Our website maintenance work keeps backups checked and restores tested on a schedule, and if your current setup already covers you, we will say so and leave it alone. We work with small and medium businesses across the country and overseas. Tell us how your site is backed up today, and we will help you find the gaps.
Terms
Website backup words in this post
Tap a term to see what it means.
Database. The part of a site that stores pages, posts, form entries, products and orders as records.
Staging site. A private copy of your website used to test changes or restores without touching the live site.
Restore point. A saved backup you can return the site to, marked with the date it was taken.
Retention. How long a provider keeps each backup before deleting it.
Off-site copy. A backup stored somewhere other than the host that runs your live site.
DNS records. The settings that point your domain name to your website and your email.
Restore runbook. Written steps for bringing a site back from a backup, so someone else can follow them.




