Blog
WordPress Website Handover Checklist for Agencies
A messy WordPress handover can turn a finished website into a support nightmare within a week.
If you are an agency handing a WordPress site to a client, another provider, or an internal marketing team, the launch is not the finish line. The real finish line is when the new owner has the access, documentation, training, backups, and confidence to run the site without guessing.
This checklist is written for agencies working with Canadian small businesses, but it also helps business owners understand what they should receive before accepting a completed WordPress project.
What a Good WordPress Handover Should Accomplish
A proper handover should answer three simple questions:
- Who owns every account connected to the website?
- Who is responsible for updates, security, backups, hosting, and support?
- What happens if something breaks after launch?
If those answers are vague, the handover is not finished.
Agencies sometimes treat handover as a quick ZIP file, a login, and a “good luck.” That may feel efficient, but it usually creates problems later: expired plugin licences, lost domain access, broken forms, missing analytics, or a client who does not know the difference between editing a page and updating a plugin.
Tip: Do not hand over only the WordPress admin login. A website depends on hosting, DNS, email, domains, backups, plugin licences, analytics, forms, and security tools. WordPress access is only one piece.
1. Confirm Ownership Before Anything Else
Before you transfer files, passwords, or admin rights, confirm who legally owns the website assets.
This should be clear in your agency agreement, but it is worth reviewing during handover. Ownership can include design files, written copy, images, custom code, plugin licences, domain names, hosting accounts, and third-party integrations.
Confirm ownership of these items
- Domain name registration, including .ca domains
- Hosting account
- WordPress website files and database
- Theme and child theme files
- Custom plugin or custom code work
- Premium plugin and theme licences
- Brand assets, logos, icons, and graphics
- Photography and stock image licences
- Written website content
- Analytics, tag manager, search console, and ad accounts
If the client does not own something, say so plainly. For example, some agencies use developer licences for premium plugins. That can be fine during the project, but the client needs to know whether they must purchase their own licence after handover.
Do not assume this is obvious. It rarely is to a non-technical client.
2. Clean Up the WordPress Dashboard
Before giving the client access, tidy up the WordPress admin area. A cluttered dashboard makes the site feel more complicated than it is.
Remove test pages, demo posts, unused themes, inactive plugins, placeholder media, sample products, and old form entries unless there is a reason to keep them.
Pre-handover cleanup checklist
- Delete unused plugins instead of leaving them inactive
- Remove unused themes, keeping only the active theme and a safe default fallback if needed
- Clear spam comments and test comments
- Remove draft pages that are not part of the final site
- Delete test users and temporary agency accounts
- Check that the site title, tagline, timezone, and language are correct
- Confirm the homepage and blog page settings are correct
- Make sure menus and footer links point to live pages, not staging URLs
- Check that no “noindex” setting was accidentally left on after launch
This is also a good time to review plugin bloat. If a plugin was only needed during development, remove it. Every unnecessary plugin adds maintenance work and potential security exposure.
3. Create the Right User Accounts
Do not hand over your agency’s master admin account as the client’s main login. Create named accounts for the people who will actually use the site.
Use the least access required. A client who only updates staff bios or blog posts may not need full administrator access for daily work.
Suggested WordPress roles
- Administrator: For the site owner, maintenance provider, or technical manager
- Editor: For staff who manage pages, blog posts, and media
- Author: For people who only write their own posts
- Shop Manager: For WooCommerce staff who manage orders and products
If the client insists on administrator access, that is their right if they own the site. Just explain the risk: admins can delete plugins, change themes, break layouts, remove users, and expose private data if they are careless.
For security, encourage two-factor authentication for all administrator accounts. If the client needs a refresher, Ambrite has a guide on WordPress Two-Factor Authentication Setup Guide.
4. Transfer Credentials Securely
Never send all passwords in a plain email thread. It is convenient, but it is also risky and hard to control later.
Use a reputable password manager or secure credential-sharing method. If the client does not use one yet, recommend they start. At minimum, separate usernames from passwords across different messages and require password changes after transfer.
Credentials to include
- WordPress admin accounts
- Hosting control panel or client portal
- Domain registrar login
- DNS provider access, if separate from hosting
- Email hosting access
- SMTP or transactional email account access, if used
- Backup service account
- Security monitoring account
- Analytics and search console access
- Payment gateway access for e-commerce sites
- Shipping, booking, CRM, or marketing platform access
Once the client confirms they have access, remove any temporary agency users that are no longer needed. If you are providing ongoing support, keep a named agency support account rather than using a shared login.
5. Document Hosting, Domain, DNS, and Email
Many website problems after launch are not actually WordPress problems. They are DNS, email, SSL, or hosting issues.
Your handover should clearly explain where each service lives. If the domain is with one company, hosting with another, and email with Microsoft, Google, or a separate mail host, write that down.
Include these details
- Domain registrar name
- Domain expiry date, if visible in the registrar account
- Hosting provider name and plan type
- DNS provider and nameserver location
- Email provider
- SSL certificate provider or renewal method
- Whether CDN or caching services are active
- Who receives renewal notices
For Canadian businesses using .ca domains, confirm the registrant contact is correct and controlled by the client. Agencies should not leave themselves as the long-term registrant unless there is a clear written agreement.
If the handover involves pointing a domain to a new website, be careful with mail records. Changing nameservers without copying email-related DNS records can break email. This guide may help: How to Point Your Domain to a New Website Without Breaking Your Email.
6. Provide a Plugin and Theme Licence Inventory
Premium plugin licences are one of the most common handover gaps.
A client may think their site is fully “done,” but six months later a form plugin, builder, security tool, or WooCommerce extension stops receiving updates because the licence was tied to the agency account.
Create a simple licence table
- Plugin or theme name
- What it does
- Free or paid
- Licence owner
- Renewal responsibility
- Renewal frequency, if known
- Where to get support
Do not guess current plugin pricing in the handover document. Pricing changes often. Instead, tell the client to check the official plugin or theme website for current renewal details.
If a plugin is critical to the business, mark it clearly. For example, a booking plugin for a clinic, an online ordering plugin for a restaurant, or a payment gateway extension for a WooCommerce store should not be treated as optional.
7. Hand Over Backups and Restore Information
A backup is not useful if nobody knows where it is, what it includes, or how to restore it.
At handover, explain the backup setup in plain language. The client does not need to understand every technical detail, but they should know whether backups are daily, weekly, stored off-server, and tested.
Backup details to document
- Backup frequency
- What is backed up: files, database, uploads, or full account
- Where backups are stored
- How long backups are retained
- Who can restore a backup
- Whether restores have been tested
If the site takes payments, receives form submissions, or changes often, backups should be more frequent. A brochure site can usually tolerate a longer restore point than a busy WooCommerce store.
For more detail, see Ambrite’s guide on WordPress Backup Guide: What You Need to Know.
8. Explain the Maintenance Plan
Every WordPress site needs maintenance after launch. The only question is who is doing it.
Do not leave the client thinking WordPress updates are harmless one-click chores. Some updates are simple. Others can break layouts, forms, checkout flows, or integrations.
Clarify who handles
- WordPress core updates
- Plugin updates
- Theme updates
- PHP compatibility reviews
- Security scans
- Uptime monitoring
- Backup checks
- Broken link checks
- Form testing
- Performance reviews
If your agency does not provide ongoing maintenance, recommend someone who does. Leaving a non-technical client alone with updates is not a great client experience.
Ambrite offers WordPress maintenance plans for Canadian small businesses starting from $49/month CAD. That can be useful when an agency wants to stay focused on design and development while a maintenance team handles updates, monitoring, backups, and security.
9. Confirm Security Basics Are in Place
Security should not be an afterthought during handover. It should be part of the final acceptance checklist.
At minimum, confirm the site uses HTTPS, strong admin passwords, limited admin accounts, regular backups, and some form of malware or vulnerability monitoring.
Security handover checklist
- SSL/HTTPS is active on all public pages
- Admin accounts use strong, unique passwords
- Two-factor authentication is enabled or recommended
- Unused admin accounts are removed
- File editing from the dashboard is disabled if appropriate
- Security plugin or server-level protection is documented
- Backups are running
- Login protection or brute-force protection is active
- Hosting includes malware protection or scanning where possible
On Ambrite’s cloud hosting, we use LiteSpeed, NVMe SSD storage, and Imunify360 security tools. Our cloud web hosting starts at $7.99/month CAD, which can be a practical option when a client needs Canadian hosting with performance and security features built in.
10. Review Privacy and Canadian Compliance Items
If the client is in Canada and the website collects personal information, privacy needs to be part of the handover.
This includes contact forms, quote request forms, appointment booking forms, newsletter signups, job applications, client intake forms, and WooCommerce checkout data.
Privacy items to review
- Privacy policy is published and linked in the footer
- Contact forms only collect information the business actually needs
- Form notifications are sent to the correct inbox
- Stored form entries are reviewed and deleted when no longer needed
- Newsletter opt-ins are clear
- Cookie or tracking notices are considered where appropriate
- Analytics and marketing tools are documented
- Client understands who has access to personal data
PIPEDA may apply to many Canadian private-sector businesses that collect, use, or disclose personal information during commercial activity. This is not legal advice, but it is worth flagging for the client. Ambrite has a related guide here: How to Comply with PIPEDA: Essential Privacy Policy Requirements for Canadian Websites.
If the business serves customers in both English and French, especially in Quebec or bilingual markets, confirm whether the website content, forms, privacy text, and transactional emails need bilingual review. Do not promise compliance casually. Recommend proper legal or regulatory guidance when needed.
11. Test Forms, Email, and Notifications
Forms are easy to overlook because they often work during development and fail after DNS or email changes.
Before handover, submit every important form from the live website. Then confirm the notification arrives in the correct inbox and the submission is stored where expected.
Test these items
- Contact form
- Quote request form
- Appointment or booking form
- Newsletter signup
- Job application form
- Client intake form
- Password reset email
- WooCommerce order emails, if applicable
If the site uses SMTP or a transactional email service, document it. Also note who owns that account and who receives delivery warnings.
Do not assume “the form says success” means the email was delivered. Check the actual inbox.
12. Hand Over Analytics and SEO Access
The client should not lose historical marketing data when the project ends.
Make sure analytics, search console, tag manager, ad accounts, and local SEO assets are owned by the client or transferred properly. Agency-owned accounts can create headaches later if the client changes providers.
Include these SEO and analytics items
- Google Analytics access
- Google Search Console access
- Google Business Profile manager access, if relevant
- Rank tracking tools, if used
- SEO plugin settings
- XML sitemap location
- Redirect list from the old site
- Important keyword or page notes
- Any schema or structured data setup
If you changed URLs during a redesign, provide a redirect map. This does not need to be fancy. A spreadsheet with old URLs and new URLs is often enough.
Also remind the client that SEO results do not instantly reset after launch. Search engines need time to crawl changes, especially after a redesign or migration.
13. Document Caching, Performance, and Image Rules
Performance settings are often set once and forgotten. Then someone installs a new slider, uploads huge images, clears the wrong cache, and wonders why the site is slow.
Give the client a short explanation of the caching setup. If the site uses server caching, plugin caching, CDN caching, or image optimization, explain what each tool does in plain language.
Performance notes to include
- Which caching plugin or server cache is active
- How to clear cache safely
- Image size recommendations
- Preferred image formats, where appropriate
- What not to upload, such as massive uncompressed photos
- Pages that are intentionally excluded from caching, such as checkout or account pages
This is especially useful for restaurants, real estate sites, trades businesses, and e-commerce stores where staff may frequently upload new images.
14. Provide Editing Instructions for Common Tasks
Do not give the client a 60-page manual they will never open. Give them short instructions for the tasks they actually need to perform.
A few short screen recordings can be more useful than a long PDF. Keep them specific to the client’s website, not generic WordPress tutorials.
Common training topics
- How to edit a page
- How to add a blog post
- How to update staff profiles
- How to change service descriptions
- How to upload and replace images
- How to update menus or hours
- How to manage form submissions
- How to add products, if using WooCommerce
- How to avoid breaking layouts
Also include a “do not touch without support” section. This might include theme settings, caching configuration, SEO templates, payment settings, shipping rules, or plugin updates.
15. Prepare an E-commerce-Specific Handover, If Needed
WooCommerce sites need a deeper handover than standard brochure websites.
A store has payments, taxes, shipping, order emails, inventory, refund workflows, customer accounts, and privacy considerations. Missing one of these can cost real money.
WooCommerce handover checklist
- Payment gateway account ownership is confirmed
- Test transaction has been completed, if appropriate
- Tax settings have been reviewed by the client or their accountant
- Shipping zones and rates are documented
- Order notification emails are tested
- Refund process is explained
- Inventory settings are confirmed
- Coupon settings are explained
- Checkout page is excluded from aggressive caching
- Backup frequency matches order volume
Do not give tax advice unless you are qualified to do so. For Canadian stores, GST, HST, PST, and place-of-supply rules can get complicated. The client should confirm tax setup with their accountant.
16. Confirm Staging Site Access and Rules
If the site has a staging environment, explain what it is for and what it is not for.
A staging site is useful for testing updates, redesigns, new plugins, and layout changes before touching the live website. But it can also cause confusion if the client edits staging content thinking it is live.
Document staging rules
- Staging URL or access method
- Who can access staging
- Whether staging is password protected
- How staging is refreshed from live
- Who is allowed to push staging changes live
- What content should not be edited on staging
For busy WooCommerce stores, be very careful pushing staging to live. You do not want to overwrite new orders or customer data. In those cases, use a more controlled deployment process.
17. Explain What Support Is Included After Launch
This is where agencies can save themselves a lot of frustration.
Clients often assume everything after launch is included. Agencies often assume the project is done. Put the support window in writing.
Clarify these support details
- How long post-launch support lasts
- What counts as a bug
- What counts as a new request
- Expected response times
- Who the client should contact
- Whether emergency support is available
- What happens after the support window ends
A bug might be “the contact form does not send after launch.” A new request might be “add a new landing page for a campaign.” Spell this out before emotions get involved.
If the client wants ongoing help but your agency does not offer it, you can refer them to a maintenance provider. Ambrite works with Canadian businesses that need hosting, updates, security monitoring, backups, and practical WordPress support. Agencies can also contact Ambrite if they need a maintenance partner for client handoffs.
18. When Not to Complete a Handover Yet
Sometimes the best handover decision is to pause.
Handing over a site too early can create confusion, risk, and unpaid support work. It is better to delay handover than transfer a half-finished system that nobody understands.
Do not complete handover if
- The final invoice or contractual milestone has not been resolved
- The domain is still controlled by the wrong party
- The site is still blocked from search engines by mistake
- Forms have not been tested on the live domain
- Payment processing has not been verified for an e-commerce site
- Critical plugin licences are unclear
- Backups are not running
- The client has no idea who is responsible for maintenance
- There is no written support agreement after launch
There is a difference between being helpful and creating future chaos. A clean pause with a checklist is better than a rushed handover that causes a crisis later.
19. Simple Final Handover Checklist
Use this as a practical final review before closing the project.
- Client has their own WordPress account
- Agency-only temporary accounts are removed or documented
- Hosting, domain, DNS, and email ownership are confirmed
- All credentials are transferred securely
- Plugin and theme licences are documented
- Backups are active and restore process is known
- SSL/HTTPS is working
- Security basics are in place
- Privacy policy and data collection points are reviewed
- Forms are tested from the live website
- Analytics and search tools are transferred
- SEO redirects are checked after launch
- Caching and performance tools are documented
- Client training has been delivered
- Maintenance responsibility is clear
- Post-launch support terms are written down
20. A Good Handover Protects Everyone
A strong WordPress handover protects the client, the agency, and the website itself.
The client gets clarity. The agency avoids endless “quick questions.” The website is less likely to become outdated, insecure, or unmanaged after launch.
The best handovers are not complicated. They are just honest, organized, and specific.
If you are an agency, create a repeatable handover template and improve it after each project. If you are a business owner, ask for the items above before accepting final delivery of your WordPress website.
This article was written with the help of AI and reviewed by the Ambrite team. Pricing, features, and technical details may change — always verify with official sources before making decisions.
Was this article useful?
Related Articles
Your WordPress site loads in 8 seconds on mobile. Meanwhile, your competitor's site loads in 2...
Running a restaurant in 2026 means juggling a thousand things at once. Your WordPress site...
Your WordPress site has 47 active plugins and takes 8 seconds to load. Sound familiar? Plugin...
Your real estate website is more than just a digital business card—it's a 24/7 sales machine...
Your staff page hasn't been updated since Jessica left in 2022, and your services page still...
