Website Handover Checklist: Take Over Your CMS
Home  /  Blog

Website Handover Checklist: Take Over Your CMS

The Short Answer: A proper website handover checklist gives you working control, not just a login. Before the final invoice, confirm you hold the domain, hosting and a CMS administrator account in your own name. Add plugin licences, an off-site backup you have restored once, working email and forms, and owner access to analytics and Search Console. Then remove or downgrade every account you did not create.

Most website projects end with an email: “Here are your login details.” That is not a handover. It is a password on a site you still cannot fully control, renew, restore or move without the person who built it.

This website handover checklist from IZI Digital Marketing is for business owners and marketing managers about to take over a content management system (CMS) from a designer or agency. Most often, that CMS is WordPress. It helps you decide what to ask for, in what order, and which items you should never let someone else hold. If you are still choosing a website designer in Malaysia, put this list in the contract now. The short WPBeginner video below explains CMS user roles, which is where most handover mistakes start.

Beginner’s Guide to WordPress User Roles and Permissions

Source video: WPBeginner – WordPress Tutorials

PART 1 · DIAGNOSE

What Should a Website Handover Include?

IN BRIEFA website handover should include every account and file you need to run, renew, restore and move the site without the builder. The legal side, who owns the design and content, is covered in our guide to website ownership at handover. This checklist covers the working side: the CMS itself.

Ownership and control are different things. You can own the copyright to your website and still be unable to renew a plugin, fix a broken form or restore the site after a hack. Control is what you test at handover. The table below shows the eight areas to check and the simple proof that you really hold each one.

Handover area Who should hold it Proof you have it
Domain and DNS Your company, company email You can log in to the registrar and see the renewal date
Hosting account Your company, billed to you Invoice in your name; you can open the control panel
CMS administrator A named person in your team Your own admin login, not a shared “admin” account
Premium plugin and theme licences Your company account with each vendor Licence keys and renewal dates listed in your records
Backups Stored off the server, in your cloud storage One test restore has worked
Email and forms Your mailbox and sending service A test enquiry lands in your inbox, not spam
Analytics, tags and Search Console Your company Google account as owner You can add and remove users yourself
Documentation Shared folder you own A plugin list, an account register and a short editing guide

If any row fails the proof test, the handover is not finished. Treat it the same way you would treat a missing Google Ads account ownership clause: fix it before you pay the final instalment, while you still have leverage.

Bottom Line: A handover is complete when you can renew, restore and move the site without calling the builder. Anything less is a login, not a handover.

Not sure your contract covers all eight areas?

We can read the handover clause with you and flag what is missing before the project starts. See how we review website projects

BENCHMARK BRIEFING 1 OF 4

Why Taking Over Your CMS Is a Security Job

IN BRIEFThe day you take over a CMS, you also take over its security risk. Almost all known WordPress weaknesses sit in plugins and themes, not in WordPress itself, so the add-ons your builder chose matter most. Ask about them early, alongside the other points in your website brief.

The Patchstack State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem during 2025, a 42% rise on 2024. The table puts the key numbers next to what each one means on handover day.

WordPress Security Signals That Matter at Handover, 2025 Data
Seven WordPress security measures from 2025, including total new vulnerabilities, share in plugins and themes, core vulnerabilities, high-severity share, unpatched share at disclosure and median time to mass exploitation, each paired with its handover implication.
Measure (2025) Value What it means when you take over
New vulnerabilities found 11,334 Updates are a weekly job, not a yearly one
Share found in plugins 91% Get a full plugin list and remove what the site does not use
Share found in themes 9% Confirm the theme can still be updated in your name
Found in WordPress core 6, all low priority WordPress itself is rarely the weak point
High severity (mass-attack risk) 1,966 (17%) Someone must watch for urgent alerts after handover
No fix available at public disclosure 46% Updating alone is not enough; backups and access control matter
Weighted median time to mass exploitation 5 hours A site with no named owner for updates is exposed within a day

Aggregated by IZI Digital Marketing from the Patchstack State of WordPress Security in 2026 report (2025 vulnerability data, published February 2026). Handover implications by IZI Digital Marketing.

The same report found that 76% of vulnerabilities in premium plugins and themes were exploitable in real attacks. That matters at handover because premium add-ons are the ones most often left on the builder’s licence. If the licence lapses, the updates stop, and the site keeps running an old version nobody is patching.

PART 2 · DESIGN

The Website Handover Checklist, Step by Step

IN BRIEFWork through the website handover checklist in order: domain first, then hosting, then the CMS, then everything that connects to it. Each step depends on the one before. For bigger projects, list these ten items in your digital marketing RFP so every bidder prices the same handover.

  1. Confirm the domain registrant. The domain should be registered to your company, with a company email as the contact. Check the renewal date and switch on auto-renew.
  2. Move hosting billing to you. Hosting should sit in an account you pay for. If the builder hosts many clients on one reseller account, plan a move to your own plan.
  3. Create your own CMS administrator. Add a named administrator for a person in your team. Never rely on one shared “admin” login.
  4. Downgrade or remove old accounts. Delete accounts you do not recognise. If the builder stays on for support, change their role to the lowest level that still lets them do the work.
  5. Turn on two-factor authentication. Switch on 2FA for every administrator and store passwords in a company password manager, not in email threads.
  6. Transfer plugin and theme licences. Move each premium licence to your company account with the vendor, or buy your own. Record every renewal date.
  7. Set up off-site backups and test one. Schedule daily backups to storage you own. Then restore one to a test copy. A backup you have never restored is only a hope.
  8. Check email and forms. Send a test enquiry from every form. Confirm it reaches the right inbox and that your domain’s SPF, DKIM and DMARC records are set.
  9. Take owner access to data tools. Make your company account the owner of Google Analytics, Tag Manager, Search Console and any ad pixels.
  10. Collect the documentation. Ask for a plugin list, an account register and a one-page editing guide, and a short training session for your team.

Two steps need a little more detail. On email, Google’s email sender guidelines require every sender to Gmail to set up SPF or DKIM, and bulk senders to set up SPF, DKIM and DMARC. Website form emails that fail these checks often end up in spam, so a “working” contact form can still lose leads. On Search Console, Google’s guide to owners, users and permissions explains that a delegated owner can be removed by any owner, so you want to be a verified owner yourself.

DECISION BOX · WHO KEEPS ADMIN ACCESS AFTER HANDOVER

Set-up How it works Right for
Clean break You hold all admin access; the builder’s accounts are deleted Teams with an in-house web person or a new maintenance provider
Owner plus support admin You hold the top-level accounts; the builder keeps a separate, named admin for maintenance Most SMEs on a maintenance retainer
Builder holds everything You get an editor login; the builder owns domain, hosting and admin Only fully managed subscription sites, with exit terms in writing

Verdict: Choose “owner plus support admin” by default. It keeps your support simple and still lets you remove the builder in minutes. Accept “builder holds everything” only if you have compared a website subscription vs a one-off build and the contract spells out how you leave.

Consultant’s Note: The most common gap we see is not the password. It is the email account behind everything. If the domain, hosting and Google accounts were all opened with the designer’s Gmail, every password reset goes to them. Change the recovery email on each account to a company address before anything else. It takes ten minutes and closes the biggest back door.
Bottom Line: Order matters. Secure the domain and recovery emails first, because whoever controls those can take back everything else.

BENCHMARK BRIEFING 2 OF 4

Is Plugin and Theme Risk Getting Worse?

IN BRIEFYes. More vulnerabilities were found in 2025 than in 2024, and a bigger share had no fix when they went public. That makes the plugin list a core handover document, and a reason to question heavy add-on use when you compare web design quotations.

WordPress Vulnerability Trends, 2024 vs 2025
Comparison of WordPress ecosystem vulnerability measures for 2024 and 2025: total new vulnerabilities, share in plugins, share in themes, vulnerabilities in core and share not patched by public disclosure, with the direction of change.
Measure 2024 2025 Change
New vulnerabilities 7,966 11,334 +42%
Share in plugins 96% 91% Still the vast majority
Share in themes 4% 9% More than doubled
Vulnerabilities in core 7 6 Stable and low
Not patched by public disclosure 33% 46% +13 points

Aggregated by IZI Digital Marketing from the Patchstack State of WordPress Security in 2025 report (2024 data) and the State of WordPress Security in 2026 report (2025 data).

The Patchstack 2025 report also noted that 1,614 plugins and themes were removed from the WordPress repository in 2024 for unpatched security issues, and that abandoned plugins are not flagged to site owners. An old plugin can sit on your site for years without a warning. At handover, ask the builder to confirm each plugin is still maintained, and replace any that are not.

PART 3 · DEPLOY

How to Run Handover Day Without Breaking the Site

IN BRIEFPlan handover as a short, scheduled session with the builder, not an email of passwords. Take a full backup first, change one thing at a time and test after each change. Book it into the project plan, because a rushed handover is one of the quiet reasons website projects get delayed.

Most breakages happen when too many changes land on the same day. Moving hosting, changing DNS and removing the builder’s access all at once leaves nobody able to tell what went wrong. A calmer sequence looks like this:

  • Before the session: take a full backup and download it to your own storage. Agree a quiet time slot, outside campaign launches and sales periods.
  • During the session: create your admin account, switch on 2FA, update recovery emails and transfer licences while the builder is on the call to answer questions.
  • Test straight away: submit every form, place a test order if you sell online, and check the site on mobile. Do this again after each change.
  • Only then remove access: downgrade or delete the builder’s accounts once you have confirmed everything works without them.

If you are also moving to new hosting, treat that as a separate project with its own checks. Our website migration guide covers how to move without losing rankings. If the site has more than one language, check that every version, redirect and language switcher survived; our guide to multilingual websites in English, BM and Chinese explains what to look for.

Bottom Line: Take access before you remove access. The builder should be the last account to change, not the first.

BENCHMARK BRIEFING 3 OF 4

What Website Incidents Are Reported in Malaysia?

IN BRIEFDefacements, compromised accounts and login attacks show up every quarter in Malaysia’s national incident figures. Most of them trace back to weak access control, which is exactly what a handover fixes. Make access part of the scope when you check what a website design package includes.

Website-Related Incidents Reported to Cyber999, Q1 2025
Number of website-related incidents reported to the Cyber999 Incident Response Centre of CyberSecurity Malaysia in January to March 2025, by sub-category, shown as horizontal bars: defacement, account compromise, vulnerability probes, login brute force, misconfiguration disclosures and web vulnerability reports.
Incident sub-category Handover item that reduces it Incidents, Q1 2025
Website defacement Updates owner, tested backups

68

Account compromise Named accounts, 2FA, recovery emails

64

Vulnerability probes Plugin list, remove unused add-ons

61

Login brute force No shared “admin” login, 2FA

40

Misconfiguration disclosure Hosting review, remove old test files

22

Web vulnerability reports Maintained plugins and theme

11

Aggregated by IZI Digital Marketing from the MyCERT Cyber Incident Quarterly Summary Report Q1 2025 (Cyber999 Incident Response Centre, CyberSecurity Malaysia; January to March 2025 monthly sub-category totals). Handover mapping by IZI Digital Marketing.

According to the MyCERT Q1 2025 summary report, intrusion incidents rose 76% from Q4 2024, from 75 to 132 cases. These are only reported incidents, so the real number is higher. Most of these categories are access problems: old accounts, shared passwords and plugins nobody updates.

Taking over a site and unsure who still has access?

Tell us what you received at handover and we will point out the accounts and settings still worth checking. Ask for a handover review

PART 4 · DRIVE

Your First 90 Days After Taking Over the CMS

IN BRIEFAfter handover, somebody must own updates, backups and access reviews, or the site slowly drifts back to risk. Set a simple routine for the first 90 days and keep it. Our guide to what website maintenance should cover shows how to turn it into an ongoing plan.

When What to do
Week 1 Check backups are running, forms are arriving and Search Console shows no new errors
Every week Apply plugin, theme and core updates on a copy first, or with a backup taken just before
Day 30 Remove plugins you do not use and check page speed has not dropped
Day 60 Review user accounts and roles; confirm privacy notice and consent forms still match how you collect data
Day 90 Do a second test restore and update your account register with every renewal date

The Day 60 check links to your legal duties too. Contact forms collect personal data, so our note on PDPA and your website is worth reading once you own the forms. Keep an eye on accessibility as your team adds content; our guide on whether your designer covers website accessibility lists simple content rules. For admin roles, the official WordPress roles and capabilities documentation explains what each level can do.

Bottom Line: A handover sets the starting point. A named owner and a written routine keep it from sliding back.

BENCHMARK BRIEFING 4 OF 4

How Long Does a Proper CMS Takeover Take?

IN BRIEFPlan for a working day on a simple brochure site and two to three days on an online store or custom build. The platform choice drives most of the effort, which is worth weighing when you compare WordPress, Webflow and custom builds.

Illustrative Hours to Complete a Full CMS Takeover, by Site Type
Illustrative hours needed for access transfer, audit and clean-up, and backup and restore testing when taking over four types of website: a hosted site builder, a brochure WordPress site, a WooCommerce store and a custom-coded site, shown as stacked bars.
Site type Access transfer + audit and clean-up + backup testing (hours) Total hours
Hosted site builder

2 + 1 + 1

4
Brochure WordPress site

3 + 3 + 2

8
WooCommerce store

5 + 8 + 4

17
Custom-coded site

6 + 10 + 6

22

Illustrative model by IZI Digital Marketing, built on the Patchstack 2025 and 2026 WordPress security reports and typical handover workflows for Malaysian SME websites, 2026. Dark = access transfer; orange = audit and clean-up; light = backup and restore testing. Hours are planning estimates, not quotes or measured client data.

Hosted builders are quick because the platform handles hosting, updates and backups; you mainly transfer the account. Stores and custom builds take longer because there is more to check: payment gateways, order emails, stock sync and code only the original developer understands. For a custom build, insist on access to the code repository and a written deployment guide, or the takeover is never truly finished.

THE VERDICT

Take Control Before You Make the Final Payment

A website handover checklist is only useful if you run it while you still have leverage. Write the ten items into the contract, schedule a handover session, test every form and restore one backup before the last invoice is paid.

The builder can stay on as your support partner; that is often the sensible choice. What changes is who holds the keys. When you brief a website designer, ask how they hand over a CMS. A clear, confident answer tells you a lot about how they will manage the rest of your website design project, and a clean handover also protects the SEO work you build on top of it.

FAQ

Frequently Asked Questions

1. What should I receive when a website is handed over?

You should receive working control, not just a password. It depends on the platform, but for most sites that means the domain, hosting, your own CMS administrator account, plugin licences, off-site backups, form and email settings, owner access to analytics and Search Console, and basic documentation.

2. Should my web designer keep admin access after handover?

Yes, if they still maintain the site, but on a separate named account. It depends on your support arrangement. You should hold the top-level accounts, and the designer’s access should be removable by you in minutes without breaking anything.

3. How do I know if my website backups actually work?

Restore one. It depends on your host and backup tool, but the only real proof is a successful restore to a test copy of the site. Store backups off the main server, in storage your company controls, and repeat the test every few months.

4. What if my previous developer will not hand over the website?

Start with what you can prove you own. It depends on whose name the domain and hosting are in. If they are in your company’s name, you can regain control through the registrar and host. If not, check your contract and seek legal advice before the next renewal date.

5. Do I need to change passwords after a website handover?

Yes, for every account the builder knew. It depends on how access was shared, but you should also change recovery emails, switch on two-factor authentication and remove any unused accounts. Store the new passwords in a company password manager.

About to take over your website and want a second opinion first?

Book a free Blueprint consultation. We will help you decide what to demand at handover, who should keep access and what your team needs to run the site with confidence.

Book my free consultation

Have a campaign in mind? Let's talk.