“Backups included” is not the same as “we can restore the website”. A small-business owner needs to know what was copied, where it lives, who can retrieve it and what will be tested after a recovery. This guide is about a safe acceptance process, not instructions to overwrite a live WordPress site.
WordPress stores posts, pages, settings and other data in a database. Site files—including uploaded images, themes and plugins—also matter. A database-only export may not restore a missing photo library; files without their matching database may not form a working website. A multisite setup needs particular care because site-level and network-level pieces may be owned by different people.
Ask for a recovery record, not a green tick
Copy these fields into a handover note: last successful backup time; database included? files and uploads included? storage location and retention; an independent way to retrieve a copy; restore owner and access route; staging location for a test; and the business functions that must pass before the restored site is accepted. Record what the provider supplies and what the business must do itself. Do not publish an unverified recovery-time promise.
What should a restore test prove?
Use an isolated staging or recovery environment and an authorised administrator. For an illustrative appointment-based business, an acceptance test could check the homepage, a representative service page, current images, a booking route, the contact form, mobile navigation and relevant notifications. This is an example—not a claim that we restored a salon website or tested this installation.
| Possible gap | Question to settle in advance |
|---|---|
| Backup reports success; images are missing | Were uploads and any external media stores included? |
| Latest copy contains unwanted changes | Are earlier retention points available and retrievable? |
| Provider can restore, owner cannot request it | Who has authority, credentials and a contact route? |
| Pages load, enquiries do not | Which forms, integrations and emails are in acceptance testing? |
Make the test safe
- Agree scope and owner; do not initiate a restore over the live site.
- Confirm the test environment cannot accidentally take real orders or send customer messages.
- Retrieve the actual backup set, restore it, and record what succeeded or failed.
- Run the written functional checks on phone and desktop, including a harmless test enquiry where appropriate.
- Document gaps, next actions and a re-test date. Protect any personal data contained in the copy under the business’s actual procedures.
The broader website maintenance checklist covers ongoing responsibilities, while our hosting comparison helps frame what to ask a provider. If you are planning a new site or a handover, see our web-design guidance and describe your project; the exact support scope must be agreed.
Source checked 19 September 2026: WordPress backup handbook. It explains backup components; it does not certify your current backup.



