When you inherit a WordPress site, first secure control of the accounts that run it, then document its current state and make sure you can restore it. Only after that should you change users, update software, or alter the server. A WordPress administrator login alone does not transfer control of the domain, hosting, email, billing, analytics, payment services, or other connected accounts.
Use this sequence as a practical handover checklist. Transfer rules differ by provider, so confirm each service’s process directly with that provider.
1. Confirm ownership and recovery access
Make a list of the accounts and services the site depends on, and confirm that you can sign in, receive recovery messages, and manage billing for each one. These are separate from WordPress itself.
- Domain registrar and DNS management
- Web hosting account
- WordPress administrator accounts
- Business email used for account recovery and site notifications
- Connected services such as analytics, payment processing, forms, backups, and email delivery
Ask the previous owner or agency to complete each provider’s ownership or access transfer. There is no single transfer process that applies to every provider.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
2. Record the site’s current state before editing
Document what is installed and how the site is configured before making changes. This gives you a baseline for troubleshooting and helps you avoid mistaking an existing condition for a problem caused by your work.
In WordPress, open Tools > Site Health. The Status tab reports issues and recommended improvements. The Info tab provides technical details about WordPress, themes, plugins, the server, database, and file permissions. Info is for inspection; it is not a configuration panel. See the WordPress Site Health documentation.
Also record the environment, user count, active and inactive themes and plugins, and any server or PHP details you can access. Keep the notes somewhere the new site owner and future maintainers can find them.
3. Make sure a restorable backup exists
Before updates or other risky changes, verify that a backup includes both the site files and database. Find out where it is stored, when it was created, and who can access it. Most importantly, learn the restoration procedure; a backup should not be called restore-tested unless someone has actually completed a restoration test.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #2
WordPress recommends backing up before updates so you can restore the site if something goes wrong. Its maintenance guidance discusses keeping copies on the host and on a computer. A second local copy can add protection, but it does not by itself automate backups, capture the database, provide off-site redundancy, or prove that a restore will work. Read WordPress’s update guidance and site maintenance guidance.
4. Review users and privileges
Review the WordPress user list and decide who still needs an account. WordPress has six predefined roles with different capabilities, including Administrator, Editor, Author, Contributor, and Subscriber. Assign access according to each person’s responsibilities, and pay particular attention to who has Administrator privileges. The Roles and Capabilities documentation explains the built-in roles.
Do a separate access review for hosting, the domain registrar, email, and connected services. Removing or changing a WordPress user does not change access to those accounts.
5. Find out what the site depends on
Before removing unfamiliar software or integrations, map how the site works. Record the active theme and plugins, forms, analytics, backup arrangements, renewals, and important business workflows. Ask the previous owner, agency, or vendors what each unfamiliar component does.
Rank #3
A plugin that appears unused may support a critical feature, and Site Health cannot identify every external integration or contractual dependency. Use its inventory as a starting point, not as a complete map; see the Site Health documentation.
6. Check Site Health and identify existing issues
Review the critical issues and recommended improvements under Tools > Site Health > Status. Check the WordPress version, available updates, plugin and theme state, PHP version, server configuration, and permissions. The documentation gives outdated PHP, pending plugin updates, and background updates that are not working as expected as examples of issues Site Health may flag.
Record what you find before trying to fix it. For information on what the Status and Info tabs report, consult the Site Health screen guide.
7. Update WordPress, themes, and plugins carefully
Once you have confirmed a backup and know how to restore it, bring WordPress, themes, and plugins up to date in a controlled way. Avoid making several unrelated changes at once: if something breaks, it is easier to identify the cause. After each update, check important pages and site workflows.
Rank #4
WordPress recommends using the latest version and notes that updates affect installation files. Its guidance for automatic plugin and theme updates recommends having a rollback-capable backup; scheduled updates also rely on WordPress Cron tasks. Review Updating WordPress and Plugin and themes auto-updates.
8. Coordinate PHP and server changes with the host
If Site Health reports outdated PHP or a server configuration problem, do not change versions blindly. Check compatibility and back up first. WordPress’s PHP guidance recommends preparing by backing up, updating WordPress, themes, and plugins, and checking compatibility before changing PHP.
Some server settings are controlled by the hosting provider, so you may need its help. See WordPress’s PHP update guidance and the Site Health documentation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.9. Test the site’s public and operational behavior
Check the site as a visitor, not only from the dashboard. Test the pages and functions that matter to the organization, such as navigation, links, forms, checkout or donation paths, email delivery, analytics, and mobile presentation. A brochure site and a store do not need identical checks; tailor the test list to what the inherited site actually does.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
WordPress’s maintenance guidance also recommends reviewing site statistics, 404 errors, and internal and external links. See WordPress site maintenance.
10. Set a maintenance routine and document the handoff
Keep a handoff record that identifies who owns each account, where backups are kept, how restoration works, which services renew, and who to contact for support. Set a schedule for backups and routine checks that reflects how often the site’s content and transactions change. WordPress recommends regularly scheduled backups and routine maintenance checks, but does not prescribe one cadence for every site; see its maintenance guidance.
Also check the current WordPress supported versions page when planning updates. WordPress’s documented support policy can change, so do not assume an older branch will continue receiving security updates.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

