“We have all the access.” That is the sentence I hear at the first meeting, when a company has just taken its website back from the agency that built it. In practice, “all the access” almost always means one username and one password for the WordPress admin. One.
That account lets you publish a page, install a plugin, break the site. It does not let you move to another host, update a paid theme, or recover three years of traffic history. Four different locks, and one key handed over.
A delivered website is not a password. It is a domain name, a hosting account, a codebase and a measurement stack. Four ownerships, four transfers.
1. Four locks, one key handed over
I lay all four out before running a single crawl.
| What you were given | What it actually opens | What is missing behind it |
|---|---|---|
| A WordPress administrator account | The content and the plugins | The server, the domain, the paid licences |
| FTP access or a hosting panel | The files and the database | The hosting contract, so the invoice and the right to cancel |
| “The domain is with that registrar” | Nothing at all | The registrant line in the Whois record, the only one that counts |
| An invitation to read the statistics | Reading the numbers | Ownership of the account, so the history on the day you leave |
2. The domain name, the one piece support cannot get back for you
The registrant of a domain name is the person or company listed as such in the Whois record, and that party alone holds the rights attached to it. Afnic, the registry for French .fr domains, states it in its practical guide for registrants, and goes further: it records a great many cases where a company used an IT provider who registered the domain “in its own name in place of its client”, and it names the usual motive, “for the sake of simplicity or convenience”. The wording is French, the situation is universal.
So this is rarely a trap. It is a shortcut taken three years earlier. The outcome is the same either way: the brand is renting its own name. And the real risk is almost never blackmail, it is oversight. Afnic points out that if the registrar has no contact with the registrant before expiry, it can send a deletion order rather than front the fee. The name then falls back into the public pool after a thirty day redemption period, first come first served. The guide adds a line that should make any director sit up: the negotiation that follows is all the more expensive “if the domain name had good search rankings”. A dissolved agency, a renewal notice sent to an intern’s mailbox, and twelve years of authority change hands for the price of a registration.
Checking takes one Whois lookup. If the registrant is not your company, the fix is a transfer of registrant, free, confirmed by both parties. To move the name to another registrar you need an auth-info code that your current registrar has to hand over. None of this happens without cooperation from the other side. Hence the order of play: this piece first.
3. Licences, the thing I check before speed
An inherited site runs on a premium theme and a stack of paid plugins. Everything works. Except the licences sit on the agency’s account, and an expired licence does not switch the site off: it switches the updates off. The site keeps running, quietly, on frozen code.
Patchstack’s latest State of WordPress Security report sizes the problem: 11,334 new vulnerabilities found across the WordPress ecosystem in 2025, 42% more than the year before, of which 91% were in plugins and 9% in themes. WordPress core itself accounted for six. The risk is not WordPress, it is what has been grafted onto it.
The paid side is the telling part for an agency-built site. Among premium components sold on marketplaces, 76% of the vulnerabilities found were exploitable in real attacks, and those components carry three times more actively exploited flaws than free ones. The reason is slightly perverse: paid code is harder for researchers to reach, so it gets less scrutiny, so it is not safer, merely less observed. The same study puts the median at five hours between the disclosure of a heavily targeted flaw and the first mass exploitation. At that speed, a dormant licence is not a saving. It is a door left ajar whose address is published in a database anyone can read.
One honest caveat from the same report: 46% of vulnerabilities had no patch available at the time of disclosure. A current licence is not enough on its own. Without one, you do not even get the choice. What I ask for fits in three lines: the list of paid themes and plugins, the account each licence sits on, and whether it can be transferred. Some transfer in one click. Others have to be bought again, and that is a cost to budget at handover.
4. What is buried in the code
The official WordPress documentation is explicit about what a child theme is for: it lets you customise a theme without touching the parent’s files, so you can keep receiving parent updates without losing your changes. It is the only clean way to modify a theme you bought.
When no child theme exists, everything the agency wrote lives in the parent’s files, and the first update wipes it. I have watched that scenario take out a Google Ads conversion tag placed straight into the theme header: nothing reported any more, the campaigns looked like they had collapsed overnight, and we went looking in the bidding. The cost of that episode was not the fix. It was the budget steered blind in the meantime.
The test takes two looks. Is there a folder ending in “-child” in the themes directory? And how many layers of code snippets are stacked on top of each other, between a snippets plugin, the functions file and a tag pasted into a page builder setting? On an inherited site there are often three patches doing the same job and one that still works. You unstack before you add, otherwise you are laying a fourth layer on top.
5. Two mirror settings nobody undoes
The first lives under Settings then Reading: the box that asks search engines not to index the site. It exists for the build phase, and it stays ticked after launch more often than you would think. The site is live, it looks good, it does not exist. The second is its mirror: the staging copy left open on a subdomain or a subfolder, with the whole site duplicated inside it. The day it gets crawled, two sites say the same thing and Google picks one. Not always yours. These two open my handover list: they are fixed immediately and they change what the crawler sees straight away.
6. Measurement history: one good piece of news, one bad
The good one concerns Search Console. A verified owner has full control of the property, and verification is additive: you become an owner in your own right by placing your own verification token, an HTML file or a DNS record, without asking anyone. The history does not belong to the agency’s account, it belongs to the property. You get all of it back, provided you control the server or the DNS zone. Which takes us back to point 2.
The bad one concerns Google Analytics 4. Moving a property from one account to another requires both the Administrator and Editor roles on both accounts at once. Without the agency’s cooperation the property does not move. At best you get read access. And starting on a fresh account means starting from a blank page, with nothing to compare the following year against.
So it is a matter of timing rather than technique: you ask for that move while the relationship is good. Once there is a disagreement over an invoice, nobody clicks a button as a favour. I put it in the first exchanges of a handover, before we even discuss what we are going to change.
What I ask for before touching anything
The Whois record with the registrant line. The hosting account, in your name, with the invoice. The list of paid themes and plugins and the account holding each licence. A verified Search Console owner that is you. The Analytics property moved across. Worst case, everything is already in order and you walk away with a clean inventory. Best case, we put a domain name back in your name before it expires in someone else’s. That is the first job on my WordPress engagements, ahead of the SEO work and ahead of rebuilding the measurement.
7. It is almost never bad faith
Afnic’s wording is the right one: simplicity, convenience. An agency shipping forty sites a year centralises its access to cope with the volume. A developer puts a developer licence on every project, which the vendor often allows. These situations are settled in a ten line email, as long as the conversation happens before the disagreement. And the right moment to ask is not the day you leave, it is the day you sign.
A line in the quote stating that the domain is registered in the client’s name, and that licences pass to the client at the end of the engagement, is worth more than a lawyer’s letter two years later. If the dispute already exists, Afnic offers free mediation and recommends turning to a lawyer or an industrial property adviser. The exact scope of your rights is judged on the documents, not in an article.
Then comes the question that always follows: should the site be rebuilt? Almost never straight away. A page builder is not a mistake, it is a choice that carries a maintenance cost, and that cost is priced separately: it is the subject of the piece on technical debt and migrating off a builder. You collect the keys first, you discuss the house afterwards.
Separating what is yours from what is lent to you
A delivered website is an alloy. Your brand, your copy, your traffic history, and fused into the same mass a set of licences and accounts belonging to somebody else. As long as nothing moves, the whole thing holds and nobody can see the seam. The day you change providers, it gives way exactly where nobody had looked.
Taking a site over is not about rebuilding it. It is about putting the piece back in the fire, line by line, and seeing what still carries your name once the heat dies down.