Skip to content

Security

How to Back Up WordPress to Dropbox Safely

Set up complete WordPress backups to Dropbox, choose a sensible schedule, verify remote files, and test restoration before an emergency.

Updated for 2026: Dropbox can be a useful off-site destination for WordPress backups, but uploading a ZIP file is not the same as having a recovery plan. A complete backup needs the database and site files, an appropriate schedule, retention, monitoring, and a restore test.

This guide uses UpdraftPlus because its current WordPress.org listing supports Dropbox in the free version. The principles apply to other maintained backup tools as well. Use one backup system intentionally rather than installing several plugins that run large jobs at the same time.

What a complete WordPress backup must contain

A typical WordPress site has two separate parts:

  • Database: posts, pages, users, settings, comments, orders, form entries, and plugin data stored in MySQL or MariaDB.
  • Files: uploads, themes, plugins, WordPress files, configuration, and other files stored on the server.

Downloading only the WordPress directory does not usually include the database. Exporting only the database does not include images, themes, plugins, or configuration files. WordPress’s official backup documentation recommends treating the database and files created around the same time as one backup set.

Is Dropbox enough for WordPress backups?

Dropbox is better than keeping the only backup on the same server as the live site. If the server fails or the hosting account is compromised, an off-site copy may remain available. It should not be the only copy for a business-critical site.

A practical approach is the 3-2-1 principle: keep multiple copies, use more than one storage location or medium, and keep at least one copy away from the production server. Your exact retention should reflect how much data the site changes and how much loss the business can tolerate.

Before connecting WordPress to Dropbox

  • Create a fresh manual backup using your host or existing system.
  • Confirm the Dropbox account is owned by the business, not an employee or freelancer.
  • Enable two-factor authentication on Dropbox.
  • Check available storage and expected backup size.
  • Decide how many daily, weekly, and monthly versions to retain.
  • Identify sensitive data in the backup and who should have access to it.
  • Avoid running the first large backup during peak traffic.

How to back up WordPress to Dropbox with UpdraftPlus

1. Install the plugin from the official directory

In WordPress, go to Plugins → Add New, search for UpdraftPlus, confirm the author and listing, then install and activate it. The official UpdraftPlus plugin page currently lists Dropbox as a supported remote-storage destination.

If the site already has a backup plugin or host integration, understand how the systems overlap before adding another scheduled job.

2. Open the backup settings

Go to Settings → UpdraftPlus Backups → Settings. Interface labels may change between versions, but the essential choices are the file schedule, database schedule, retention count, and remote-storage destination.

3. Choose sensible schedules

The database often changes more frequently than the files, so the schedules do not have to be identical.

  • Small brochure site: weekly files and daily or weekly database backups may be sufficient.
  • Active content site: daily database and regular file backups.
  • WooCommerce, membership, or booking site: database backups may need to run much more frequently because orders and user activity change throughout the day.

A backup frequency should match the recovery point objective: how much recent data the business can accept losing. A daily database backup can still mean losing almost 24 hours of orders.

4. Select Dropbox as remote storage

Choose Dropbox from the remote-storage options and save the settings. The plugin will provide an authentication link. Follow it while logged in to the correct Dropbox account, approve the requested access, and return to WordPress to complete the connection.

Do not paste Dropbox passwords or tokens into support messages. Use the provider’s authorization flow and revoke access from Dropbox if the integration is retired.

5. Create the first remote backup

Open the Backup/Restore tab and choose Backup Now. Include both the database and files, and confirm that the backup should be sent to remote storage.

Keep the tab open while the initial job starts, but remember that large sites may continue processing in background requests. Check the log if progress stops. Low PHP memory, execution limits, blocked cron requests, insufficient disk space, or a remote-storage quota can interrupt the job.

6. Verify Dropbox—not just WordPress

A success message inside WordPress is not enough. Open Dropbox and verify that the new backup files exist. Check that the set contains the expected database and file components and that their timestamps match.

How to test whether the backup can be restored

The safest restore test happens on staging or in an isolated temporary environment:

  1. Create a clean WordPress destination that is blocked from indexing and email delivery.
  2. Download or connect the selected backup set.
  3. Restore the files first and then the matching database when the tool requires that order.
  4. Update database credentials or URLs if the environment differs.
  5. Test login, media, forms, navigation, scheduled jobs, and important plugin data.
  6. For WooCommerce, confirm products, orders, customer accounts, and checkout configuration without sending live transactions.
  7. Record the restore time and any manual steps that were required.

A backup that has never been restored is an assumption. Periodic recovery tests reveal missing uploads, incomplete database tables, inaccessible encryption keys, or credentials that belong to someone who no longer works with the business.

How many WordPress backups should you keep?

Retention depends on available storage, site activity, compliance requirements, and how quickly corruption might be noticed. Keeping only the latest copy is risky because malware or a bad configuration can be present before the next backup runs.

A common structure is several recent daily copies, several weekly copies, and a smaller number of monthly archives. WordPress’s current backup guidance suggests keeping multiple recent backups in different locations rather than relying on one version.

Common Dropbox backup problems

The Dropbox connection expired

Reconnect using the plugin’s current authorization flow, then run and verify a new backup. Check who owns the Dropbox account before reconnecting it.

The backup completes locally but not in Dropbox

Review the job log, Dropbox quota, authentication status, server outbound connections, and PHP execution limits. Remove unnecessary local archives only after confirming a valid remote copy exists.

Backups fill the server disk

Uploading remotely does not always remove temporary local files immediately. Review retention and cleanup settings, failed partial jobs, and hosting disk usage.

The database backup is present but images are missing

The database and files are separate components. Confirm that uploads were included and that the complete backup set was transferred.

WooCommerce orders are missing after restore

The restored database represents the moment it was created. Do not overwrite a live store with an older database without a plan for orders and customer activity created after that point.

When not to use a WordPress backup plugin

Very large sites, high-volume stores, multisite networks, and environments with strict recovery requirements may need host-level snapshots, incremental backups, database replication, or a managed backup service. A WordPress plugin is convenient, but it runs inside the same PHP application and resource limits as the website.

Assign backup ownership across a site portfolio

A backup policy should name the system of record, retention period, encryption and access owner for every website. Record which sites need database snapshots more frequently because they receive orders, registrations or form submissions, and schedule restore tests instead of assuming that uploaded archives are usable.

Use the portfolio maintenance audit to identify missing or duplicated backup systems. Then document restoration responsibility and escalation in a website support SLA, including who may authorize a rollback that discards recent transactions.

Backups should be connected to an incident response and recovery plan that defines who can authorize restoration, how recent transactions are handled and which journeys must be tested before the incident closes.

Frequently asked questions

Does Dropbox back up WordPress automatically?

No. Dropbox stores the files sent to it. WordPress or a backup system must create the database and file archives, schedule the job, transfer the files, and report failures.

Can I restore WordPress directly from Dropbox?

That depends on the backup tool. With a supported integration, reconnect the tool or upload the matching backup set, then follow its restore workflow. Test on staging before replacing a live database.

Should backups be stored on the same hosting account?

A local copy can speed up recovery, but it should not be the only copy. Server failure, account suspension, malware, or accidental deletion can affect the site and local backups together.

Should I back up before updating plugins?

Yes. Create or verify a current restorable backup before changes. Follow our safe WordPress plugin update checklist.

Prefer to have backups monitored and tested?

CodaStudio’s WordPress maintenance service includes managed backups, updates, monitoring, and recovery planning. If a backup has failed or a site already needs restoration, use our WordPress support service. For a host or domain move, continue with the guide to migrating WordPress without losing SEO.

Done reading?

Let us handle the website.

Updates, fixes and ongoing care from real WordPress experts.

Choose your plan →