Website Maintenance Takeover Checklist: Switching Providers Safely

WordPress maintenance dashboard for routine website updates and checks

Changing website maintenance provider should not mean rebuilding your site, losing access or risking downtime. A safe takeover is mainly about control: knowing who owns the domain, hosting and administrator accounts, capturing a working backup, understanding licences and integrations, and agreeing exactly when the new provider becomes responsible.

This checklist is for UK businesses moving an existing WordPress, Elementor or WooCommerce website from one developer, freelancer or agency to another.

Quick answer

Do not cancel the old support arrangement before the new provider has verified access and recovery.

The safest sequence is: confirm ownership, inventory access, take a verified backup, document the current setup, test the critical customer journey, transfer responsibility, then remove old access only after the new provider is fully in control.

Website maintenance takeover checklist

1. Domain
Confirm the business controls the registrar account and renewal details.
2. DNS & email
Record DNS, MX, SPF, DKIM and DMARC before anybody changes them.
3. Hosting
Verify hosting login, server details, PHP version and current backups.
4. WordPress
Create a named administrator account for the new provider rather than sharing logins.
5. Licences
Check who owns premium plugin, theme, Elementor and integration licences.
6. Recovery
Take a fresh full backup and know how the site would be restored.
7. Customer journey
Test forms, booking, checkout, payments and transactional email.
8. Responsibility
Agree the exact handover point and who handles an urgent fault during transition.

1. Make sure the business controls the domain

The domain is the first asset to verify because losing control of it can affect the website, email and other connected services at the same time.

Confirm which registrar holds the domain, whose account it sits in, which email address receives renewal notices and whether the business can independently renew or transfer it.

A domain should not depend on a former freelancer’s personal email account or an agency login the business cannot access.

2. Record DNS before changing anything

DNS is easy to overlook because most records are invisible to visitors. But changing the wrong record can break email, verification services, subdomains or third-party systems even when the website itself still loads.

Before any hosting or DNS move, record the current A, AAAA, CNAME, MX and TXT records. Pay particular attention to Microsoft 365 or Google Workspace mail records, SPF, DKIM and DMARC.

Changing maintenance provider does not automatically require a hosting migration.

If the existing hosting is suitable, the new provider can often take over maintenance without moving the site at all. Avoid introducing migration risk unless there is a genuine reason to change infrastructure.

3. Verify hosting access and server details

The new provider should know where the site is hosted, how to access the hosting account and whether there are server-level tools that affect the website.

Useful details include the hosting provider, control-panel access, PHP version, database access, caching, CDN or Cloudflare configuration, scheduled tasks and backup system.

Do not remove the previous provider’s access until the new provider has independently confirmed that the required systems are reachable.

4. Create proper WordPress administrator access

Each person or provider should ideally have their own account. Sharing one generic administrator login makes it harder to see who changed what and creates unnecessary security risk when somebody leaves.

Create a named administrator account for the incoming provider. Once the takeover is complete, review old administrator users and remove access that is no longer required.

5. Check premium themes, plugins and licences

A site can continue working after a provider leaves while silently losing access to updates because a premium licence belonged to the old agency.

Check Elementor Pro, premium themes, WooCommerce extensions, booking plugins, security tools, form plugins, SMTP services and any other paid components.

For each one, identify whether the licence belongs to the business, the outgoing provider or a third party. If a licence must be replaced, do it deliberately rather than discovering the problem during a future update.

6. Capture a full backup before the first major change

Before the new provider updates plugins, changes hosting or edits critical configuration, take a full backup of both files and database.

Where possible, store a copy independently of the live hosting account. A backup is most useful when it remains available even if the live server becomes inaccessible.

If recovery is important to the business, the new provider should also understand how that backup would actually be restored.

7. Establish a technical baseline

A takeover is easier when everybody knows what “working” looks like before changes begin.

Record the current WordPress, theme and plugin versions, PHP version, obvious errors, security warnings, storage usage and any known custom code. Note anything intentionally left outdated because of a compatibility dependency.

This prevents the incoming provider from treating every unusual setting as a mistake and reduces the chance of breaking something that was built for a specific reason.

8. Test the functions that make the business money

The front page loading is not enough.

Test the actual conversion journey: contact forms, quote forms, bookings, customer logins, WooCommerce checkout, payment gateways and transactional emails.

For ecommerce sites, include a controlled test order where practical. For lead-generation sites, confirm that form submissions actually arrive in the intended inbox or CRM.

If a site already has intermittent issues, record them during the takeover rather than allowing the new provider to inherit blame for an existing fault.

9. Check analytics and Search Console ownership

Changing developer should not reset your measurement history.

Confirm access to Google Analytics, Google Search Console, Tag Manager and any advertising or call-tracking platforms connected to the site. Add the new provider using their own account rather than transferring a shared password.

If the site is moved or materially changed later, these tools give you a baseline for spotting traffic, indexing or conversion problems quickly.

10. Document integrations and external services

Modern business websites often depend on services outside WordPress.

Examples include Stripe, PayPal, Xero, booking platforms, CRM systems, email marketing, SMTP, Cloudflare, maps, review widgets, live chat, APIs and webhooks.

The new provider does not necessarily need ownership of every account, but they should know which services are connected and who to contact if one stops working.

11. Agree what the new maintenance plan actually covers

A successful technical handover can still lead to frustration if the ongoing scope is unclear.

Before responsibility transfers, agree what happens with routine updates, backups, security monitoring, uptime, small content edits, form testing, WooCommerce checks and urgent faults.

Also clarify what sits outside the monthly plan, such as major redesigns, custom development, large content projects or recovery from a serious pre-existing compromise.

For a broader comparison of UK pricing and scope, see our website maintenance cost guide.

12. Set a clear handover point

The riskiest arrangement is one where the old and new providers both assume the other person is responsible.

Choose a clear handover date or acceptance point. By then the new provider should have verified access, captured the baseline, secured a current backup and tested the critical customer journey.

Only after that should old access be removed or the previous support arrangement be allowed to end.

Before you remove the old provider
  • Domain control confirmed
  • Hosting and WordPress access verified
  • Fresh backup captured
  • Licences reviewed
  • Forms, booking or checkout tested
  • Analytics and Search Console accessible
  • New support scope agreed
  • Emergency contact route confirmed

Do you need to rebuild when changing maintenance provider?

Usually, no.

A new provider can often take responsibility for an existing WordPress website after an initial review. A rebuild only makes sense when there is a separate technical or commercial reason, such as an unsupported platform, severe security problems, inaccessible source code or a site that genuinely cannot meet the business’s needs.

Changing support company by itself is not a reason to throw away a functioning website.

What if the previous developer has disappeared?

Start with the assets the business still controls: domain registrar, hosting account, WordPress administrator access, company email and billing records.

If you have hosting access but no WordPress login, access can often be recovered safely. If you control the domain but not the hosting, a recovery or migration may be possible from available backups or files.

If the website is already broken, hacked or offline, the priority becomes stabilising it first. Our Emergency Website Fixes service covers urgent faults before an ongoing maintenance takeover.

Website maintenance takeover with Core Web UK

Core Web UK can take over an existing WordPress, Elementor or WooCommerce website even if somebody else designed or built it.

We start by understanding access, hosting, backups, licences, existing problems and the functions your business depends on. We then agree what ongoing maintenance should cover before making unnecessary changes.

See our website maintenance and support service for ongoing UK support. If you are specifically comparing local options, our Website Maintenance London guide explains what to look for in a maintenance provider and support plan.

The takeover is not complete until access is tested

A handover document can look complete while the new provider still cannot restore a backup, change DNS, access billing or reach the correct analytics property. Before the old provider leaves, test every critical login and confirm who owns the domain, hosting, WordPress administrator accounts, email/SMTP, CDN, analytics, Search Console, licences and payment services.

A stronger acceptance test

Create a fresh restore point, prove it can be restored to an isolated environment, submit every lead form, run a test checkout where applicable, confirm analytics/conversion tracking, and document any unresolved risks. That converts a folder of passwords into evidence that the site can actually be operated.

Protect ownership before the relationship changes

The business should control the domain registrar and primary hosting/account ownership wherever practical. Supplier access can then be delegated rather than the company depending on a former agency’s personal account. This is one of the most important takeover checks because losing domain or hosting control can turn a routine provider change into a business-continuity problem.

Maintenance takeover questions businesses actually search

The strongest search intent around switching website providers is usually about ownership, access, licences, hosting, SEO risk and whether the site needs to be rebuilt. A useful takeover guide therefore has to answer practical handover questions, not just list credentials.

Can another company maintain a website they did not build?

Usually yes. The new provider needs enough access and documentation to understand the site safely. A rebuild should be a separate technical decision, not an automatic condition of changing support company.

Who should own the domain and hosting?

The business should retain control of core assets and be able to renew or transfer them independently. Shared or agency-owned logins create avoidable risk during disputes, staff changes or emergencies.

What happens to agency-owned licences?

Premium themes, Elementor Pro, WooCommerce extensions and other tools may be licensed through the outgoing provider. Identify which licences must be replaced and what will happen to updates or support if they are disconnected.

Could changing provider hurt SEO?

Not by itself. SEO risk appears when the handover also changes DNS, hosting, URLs, templates, canonicals, redirects or content. Freeze unnecessary structural changes until the baseline is recorded.

Competitor gap: classify the takeover before touching the site

Clean takeover
Site healthy; transfer access and responsibility.
Repair-first takeover
Document faults, stabilise, then maintain.
Migration takeover
Hosting/platform move needs its own plan.
Rebuild case
Only when the current foundation is genuinely unsuitable.

FAQ

Can another company maintain a website they did not build?

Yes. In most cases a new provider can take over an existing website after checking access, hosting, backups, licences, integrations and the current technical condition.

Should I cancel my old website maintenance before switching?

Not until the new provider has verified the access and information they need. Ending the old arrangement too early can make missing credentials, licences or backups harder to recover.

Do I need to move hosting when I change maintenance company?

No. Maintenance provider and hosting provider can be separate. Move hosting only when there is a technical, commercial or support reason to do so.

Will changing website provider affect SEO?

Changing support provider alone should not affect rankings. Risk appears when URLs, hosting, DNS, site structure or content are changed carelessly during the handover.

Who should own the domain and website accounts?

The business should retain control of core assets such as the domain and should be able to access essential services independently of any one freelancer or agency.