A WordPress maintenance handoff is complete when the incoming team can operate and recover the site without relying on the outgoing agency's private accounts. A ZIP file and an administrator password are not enough. Transfer ownership, prove the important workflows, then retire access in a controlled order.
Build an Ownership Register
List the domain registrar, DNS provider, hosting, CDN, backups, transactional email, premium plugins, source repository, analytics, Search Console, payment services, and CRM. For each system, record the legal owner, billing owner, recovery contact, access method, and incoming operator.
Keep passwords and recovery codes in an approved secret-sharing system, not the handoff document. The document should point to a secure access location and record that the intended recipient successfully signed in.
| System |
Proof required |
Common gap |
| Domain and DNS |
Client-controlled account and recovery method |
Registrar belongs to a former contractor |
| Hosting |
Access to files, logs, database, and restore controls |
WordPress admin access only |
| Premium software |
License holder and renewal decision |
Agency license cannot transfer |
| Integration |
Named credential owner and test result |
Automation depends on a personal account |
Inventory the Parts Outside the Plugin List
Include child-theme overrides, code-snippet plugins, must-use plugins, server cron jobs, custom webhooks, deployment secrets, and external workers. Record where changes are maintained and which source repository is authoritative. Ask the host which files it manages before altering platform-specific code.
If a custom component has no maintainer, record that as an unresolved risk. The must-use plugin guide explains why deactivating normal plugins does not remove every extension to WordPress behavior.
Prove Recovery With the Incoming Team
Restore an agreed backup into a private, isolated environment. Check the database, uploads, external media, and configuration needed to render a representative page. Prevent the copy from emailing customers, charging payments, or duplicating CRM activity.
Have the incoming operator perform the exercise. A demonstration by the outgoing agency does not establish that the new team has the access required during an outage. Keep the archive date, missing dependencies, and restoration result in the handoff record.
Test sheet for wordpress maintenance handoff checklist for agencies. Record your own evidence.
Replace Machine Access Before Revoking It
List application passwords, API tokens, SSH keys, OAuth connections, and scheduled workers separately from human users. Give replacement integrations the minimum required capabilities and verify a controlled transaction before removing the old credential.
WordPress application passwords are separate API credentials associated with a user. Changing an interactive login password is not a substitute for reviewing every machine credential. After revocation, verify both that the old connection fails and that the replacement still completes its intended task.
Do not delete a departing author's account casually. Decide whether content must be reassigned, and preserve the necessary attribution and audit records under the client's retention policy.
Sign Off on Known Exceptions
Use a final list with accepted items, untested items, owners, and deadlines. Verify one customer enquiry, one store transaction if applicable, the backup alert destination, and the emergency escalation route. Cancel duplicate paid services only after the replacement is confirmed.
Align future responsibilities with the maintenance-plan scope checklist. A handoff does not automatically include redesigns, incident cleanup, or integration rebuilds. For an unresolved technical failure, use a scoped WordPress fix and attach the relevant evidence rather than transferring the whole secret inventory.
References checked September 28, 2026. Diagrams and worked examples are explanatory, not customer measurements.