A lot of small business owners hear “backup your website” and think, right, database sorted, job done.
Nope.
If you only back up the database, you’re saving part of the house and hoping the rest rebuilds itself later. That database matters, yes. A lot. It usually holds your posts, pages, product info, customer orders, form entries, settings, and chunks of the stuff that makes WordPress function. But it does not hold everything. And that missing part is often what turns a quick recovery into a full-on miserable week.
I’ve seen this kill a launch. A shop owner updates a plugin, the site breaks, they proudly say “don’t worry, we have backups,” then find out they only saved the database from last Tuesday and none of the theme files, uploaded product images, or plugin settings that changed since then. Great. Now they’re rebuilding half the site by hand.
If you’re running a brochure site, a booking site, or a 47-product WooCommerce store, here’s what actually needs backing up.
The database is only one piece
Your WordPress database is the brainy bit. It stores content and settings. Without it, your site loses the stuff you typed into WordPress – pages, blog posts, WooCommerce orders, customer accounts, menus, and plenty more.
But the database doesn’t store your whole website. It doesn’t magically contain your theme files, plugin files, uploaded PDFs, product photos, custom code snippets living in files, or that favicon you spent 20 minutes trying to center before giving up.
So yes, back up the database. Obviously. But stopping there is a big mistake.
What you actually need to back up
Here’s the practical version. For most WordPress sites, you want backups of these parts:
- The database – posts, pages, settings, WooCommerce orders, customer data, forms, menus
- The uploads folder – images, PDFs, videos, downloadable files, product photos
- The themes folder – your active theme, child theme, custom template edits
- The plugins folder – installed plugins and sometimes plugin-specific assets
- Core configuration files – especially wp-config.php and .htaccess
- Custom code or tracking scripts – anything manually added for analytics, pixels, custom functions, schema, redirects
That’s the real backup set. Miss one of those and recovery gets patchy fast.
Why the uploads folder matters more than people think
This one gets ignored alot. And it’s usually the bit people regret later.
Your uploads folder holds the media library. Product photos. Team headshots. Before-and-after project galleries. Restaurant menu PDFs. Downloadable guides. Logo files. All the visual stuff that makes the site look like your business instead of a blank shell.
Picture a florist with 180 product photos, seasonal banner graphics, and three pricing PDFs. The database backup will remember that image attachments exist. Nice. But if the actual files in /wp-content/uploads/ are gone, WordPress just points to broken image links. That’s not a recovery. That’s a scavenger hunt.
And if you’re on WooCommerce, this gets even messier. Missing category thumbnails and product gallery images make a store look half-dead in seconds.
If your website is image-heavy, this folder is often the largest part of your backup. Which is annoying, sure. Still has to be backed up.
The files that quietly save your skin
Theme files and plugin files sound replaceable because, technically, you can reinstall many of them. Sometimes that’s true. Sometimes.
But here’s where people get caught out:
- You or your developer made custom edits to the theme
- A child theme contains templates, CSS, or functions you’ve forgotten about
- A plugin stores files outside the database
- Your redirects, caching rules, or security settings live in config files
That last one matters more than it seems. A missing .htaccess file can break redirects or permalinks. A missing wp-config.php file can stop the site loading at all. Tiny files. Huge headaches.
If your site was built professionally, or even semi-professionally, there are probably little bits tucked away in files that nobody remembers until the restore fails.
That’s why proper website maintenance and management usually includes full-site backups, not just a quick database export and a hopeful smile.
WooCommerce stores need tighter backup habits
If you sell online, backup timing matters almost as much as backup coverage.
A simple service business website might survive with daily backups. Not ideal, but survivable. A WooCommerce store taking orders every few hours? Different story. Lose half a day and you might lose paid orders, stock changes, customer details, coupon usage, and shipping updates.
For online stores, I’d usually suggest:
- Daily backups for low-order stores
- More frequent backups – every 1-6 hours – for busier shops
- Extra backups before updates to WordPress, plugins, or themes
Honestly, for a small WooCommerce store doing even 5-10 orders a day, daily-only backups can be a bit thin. One bad plugin update at 4 pm and you’re rolling back to breakfast.
If you’re still figuring out whether you even need the full store setup, this article on online store or simple website helps sort that out before you overbuild things.
Backups should live somewhere else. Not just on the site
This is the part people skip because it feels fussy.
If your backups live only on the same hosting account as the website, and that hosting account gets corrupted, deleted, locked, or hacked, guess what happens to your backups?
Yep. Gone too.
You want off-site copies. Cloud storage, remote storage, another server, somewhere separate. Doesn’t have to be fancy. It just has to still exist when your website doesn’t.
A decent backup setup for a small business site usually costs anywhere from €0 to €25 a month in plugin and storage costs, depending on site size. For many sites it’s cheap. For larger media-heavy stores, maybe a bit more. Still far cheaper than paying someone for emergency reconstruction because your only backup died with the hosting account.
A backup isn’t real until you’ve tested restoring it
Harsh, but true.
People love saying they have backups. What they often mean is they have backup files sitting somewhere mysterious, created by a plugin they installed 14 months ago, and they’ve never once tried restoring them.
That’s not confidence. That’s wishful thinking.
You should know:
- where the backups are stored
- how often they run
- how long they’re kept
- how to restore them
- whether the restore has actually worked before
Even one test restore on a staging site can tell you a lot. It might take 20 minutes. Maybe an hour if the site’s chunky. Worth it.
And if an update has already gone wrong on you, read what to do after a WordPress update breaks your site. That situation gets messy fast if your backups are half-baked.
What a sensible backup plan looks like for a small business
You do not need an enterprise disaster recovery department. You’re probably running a salon, a local shop, a small online store, a plumbing company, or a 6-page service site. Keep it sane.
A good small-business backup plan usually looks like this:
For a basic WordPress website:
Full-site backup daily, off-site storage, 30 days retention, plus a manual backup before big changes.
For a WooCommerce store:
Full-site backup daily at minimum, more frequent database backups if orders come in regularly, off-site storage, and restore testing every so often.
For sites updated often:
Backup before plugin installs, theme changes, design edits, and major content imports.
If this all sounds a bit too easy to forget, that’s because it is. That’s why some businesses hand it off to a proper website security and recovery setup, especially after the first scare.
The boring truth
Backups are dull right up until the moment they’re the only thing standing between “minor issue” and “we have to rebuild the site from scratch.”
So back up the database. Sure. But also back up your uploads, theme, plugins, config files, and custom code. Store copies somewhere seperate from the site itself. Test restores now and then. And if you run WooCommerce, tighten the schedule – because stores change by the hour, not the month.
It’s boring. It’s unglamorous. It’s absolutely worth doing properly.
Because the worst time to learn what your backup missed is after the site goes down.