Most website projects end with an email: “Here are your login details.” That is not a handover. It is a password on a site you still cannot fully control, renew, restore or move without the person who built it.
This website handover checklist from IZI Digital Marketing is for business owners and marketing managers about to take over a content management system (CMS) from a designer or agency. Most often, that CMS is WordPress. It helps you decide what to ask for, in what order, and which items you should never let someone else hold. If you are still choosing a website designer in Malaysia, put this list in the contract now. The short WPBeginner video below explains CMS user roles, which is where most handover mistakes start.
Beginner’s Guide to WordPress User Roles and Permissions
Source video: WPBeginner – WordPress Tutorials
PART 1 · DIAGNOSE
What Should a Website Handover Include?
IN BRIEFA website handover should include every account and file you need to run, renew, restore and move the site without the builder. The legal side, who owns the design and content, is covered in our guide to website ownership at handover. This checklist covers the working side: the CMS itself.
Ownership and control are different things. You can own the copyright to your website and still be unable to renew a plugin, fix a broken form or restore the site after a hack. Control is what you test at handover. The table below shows the eight areas to check and the simple proof that you really hold each one.
| Handover area | Who should hold it | Proof you have it |
|---|---|---|
| Domain and DNS | Your company, company email | You can log in to the registrar and see the renewal date |
| Hosting account | Your company, billed to you | Invoice in your name; you can open the control panel |
| CMS administrator | A named person in your team | Your own admin login, not a shared “admin” account |
| Premium plugin and theme licences | Your company account with each vendor | Licence keys and renewal dates listed in your records |
| Backups | Stored off the server, in your cloud storage | One test restore has worked |
| Email and forms | Your mailbox and sending service | A test enquiry lands in your inbox, not spam |
| Analytics, tags and Search Console | Your company Google account as owner | You can add and remove users yourself |
| Documentation | Shared folder you own | A plugin list, an account register and a short editing guide |
If any row fails the proof test, the handover is not finished. Treat it the same way you would treat a missing Google Ads account ownership clause: fix it before you pay the final instalment, while you still have leverage.
Not sure your contract covers all eight areas?
We can read the handover clause with you and flag what is missing before the project starts. See how we review website projects
BENCHMARK BRIEFING 1 OF 4
Why Taking Over Your CMS Is a Security Job
IN BRIEFThe day you take over a CMS, you also take over its security risk. Almost all known WordPress weaknesses sit in plugins and themes, not in WordPress itself, so the add-ons your builder chose matter most. Ask about them early, alongside the other points in your website brief.
The Patchstack State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem during 2025, a 42% rise on 2024. The table puts the key numbers next to what each one means on handover day.
| Measure (2025) | Value | What it means when you take over |
|---|---|---|
| New vulnerabilities found | 11,334 | Updates are a weekly job, not a yearly one |
| Share found in plugins | 91% | Get a full plugin list and remove what the site does not use |
| Share found in themes | 9% | Confirm the theme can still be updated in your name |
| Found in WordPress core | 6, all low priority | WordPress itself is rarely the weak point |
| High severity (mass-attack risk) | 1,966 (17%) | Someone must watch for urgent alerts after handover |
| No fix available at public disclosure | 46% | Updating alone is not enough; backups and access control matter |
| Weighted median time to mass exploitation | 5 hours | A site with no named owner for updates is exposed within a day |
Aggregated by IZI Digital Marketing from the Patchstack State of WordPress Security in 2026 report (2025 vulnerability data, published February 2026). Handover implications by IZI Digital Marketing.
The same report found that 76% of vulnerabilities in premium plugins and themes were exploitable in real attacks. That matters at handover because premium add-ons are the ones most often left on the builder’s licence. If the licence lapses, the updates stop, and the site keeps running an old version nobody is patching.
PART 2 · DESIGN
The Website Handover Checklist, Step by Step
IN BRIEFWork through the website handover checklist in order: domain first, then hosting, then the CMS, then everything that connects to it. Each step depends on the one before. For bigger projects, list these ten items in your digital marketing RFP so every bidder prices the same handover.
- Confirm the domain registrant. The domain should be registered to your company, with a company email as the contact. Check the renewal date and switch on auto-renew.
- Move hosting billing to you. Hosting should sit in an account you pay for. If the builder hosts many clients on one reseller account, plan a move to your own plan.
- Create your own CMS administrator. Add a named administrator for a person in your team. Never rely on one shared “admin” login.
- Downgrade or remove old accounts. Delete accounts you do not recognise. If the builder stays on for support, change their role to the lowest level that still lets them do the work.
- Turn on two-factor authentication. Switch on 2FA for every administrator and store passwords in a company password manager, not in email threads.
- Transfer plugin and theme licences. Move each premium licence to your company account with the vendor, or buy your own. Record every renewal date.
- Set up off-site backups and test one. Schedule daily backups to storage you own. Then restore one to a test copy. A backup you have never restored is only a hope.
- Check email and forms. Send a test enquiry from every form. Confirm it reaches the right inbox and that your domain’s SPF, DKIM and DMARC records are set.
- Take owner access to data tools. Make your company account the owner of Google Analytics, Tag Manager, Search Console and any ad pixels.
- Collect the documentation. Ask for a plugin list, an account register and a one-page editing guide, and a short training session for your team.
Two steps need a little more detail. On email, Google’s email sender guidelines require every sender to Gmail to set up SPF or DKIM, and bulk senders to set up SPF, DKIM and DMARC. Website form emails that fail these checks often end up in spam, so a “working” contact form can still lose leads. On Search Console, Google’s guide to owners, users and permissions explains that a delegated owner can be removed by any owner, so you want to be a verified owner yourself.
DECISION BOX · WHO KEEPS ADMIN ACCESS AFTER HANDOVER
| Set-up | How it works | Right for |
|---|---|---|
| Clean break | You hold all admin access; the builder’s accounts are deleted | Teams with an in-house web person or a new maintenance provider |
| Owner plus support admin | You hold the top-level accounts; the builder keeps a separate, named admin for maintenance | Most SMEs on a maintenance retainer |
| Builder holds everything | You get an editor login; the builder owns domain, hosting and admin | Only fully managed subscription sites, with exit terms in writing |
Verdict: Choose “owner plus support admin” by default. It keeps your support simple and still lets you remove the builder in minutes. Accept “builder holds everything” only if you have compared a website subscription vs a one-off build and the contract spells out how you leave.
BENCHMARK BRIEFING 2 OF 4
Is Plugin and Theme Risk Getting Worse?
IN BRIEFYes. More vulnerabilities were found in 2025 than in 2024, and a bigger share had no fix when they went public. That makes the plugin list a core handover document, and a reason to question heavy add-on use when you compare web design quotations.
| Measure | 2024 | 2025 | Change |
|---|---|---|---|
| New vulnerabilities | 7,966 | 11,334 | +42% |
| Share in plugins | 96% | 91% | Still the vast majority |
| Share in themes | 4% | 9% | More than doubled |
| Vulnerabilities in core | 7 | 6 | Stable and low |
| Not patched by public disclosure | 33% | 46% | +13 points |
Aggregated by IZI Digital Marketing from the Patchstack State of WordPress Security in 2025 report (2024 data) and the State of WordPress Security in 2026 report (2025 data).
The Patchstack 2025 report also noted that 1,614 plugins and themes were removed from the WordPress repository in 2024 for unpatched security issues, and that abandoned plugins are not flagged to site owners. An old plugin can sit on your site for years without a warning. At handover, ask the builder to confirm each plugin is still maintained, and replace any that are not.
PART 3 · DEPLOY
How to Run Handover Day Without Breaking the Site
IN BRIEFPlan handover as a short, scheduled session with the builder, not an email of passwords. Take a full backup first, change one thing at a time and test after each change. Book it into the project plan, because a rushed handover is one of the quiet reasons website projects get delayed.
Most breakages happen when too many changes land on the same day. Moving hosting, changing DNS and removing the builder’s access all at once leaves nobody able to tell what went wrong. A calmer sequence looks like this:
- Before the session: take a full backup and download it to your own storage. Agree a quiet time slot, outside campaign launches and sales periods.
- During the session: create your admin account, switch on 2FA, update recovery emails and transfer licences while the builder is on the call to answer questions.
- Test straight away: submit every form, place a test order if you sell online, and check the site on mobile. Do this again after each change.
- Only then remove access: downgrade or delete the builder’s accounts once you have confirmed everything works without them.
If you are also moving to new hosting, treat that as a separate project with its own checks. Our website migration guide covers how to move without losing rankings. If the site has more than one language, check that every version, redirect and language switcher survived; our guide to multilingual websites in English, BM and Chinese explains what to look for.
BENCHMARK BRIEFING 3 OF 4
What Website Incidents Are Reported in Malaysia?
IN BRIEFDefacements, compromised accounts and login attacks show up every quarter in Malaysia’s national incident figures. Most of them trace back to weak access control, which is exactly what a handover fixes. Make access part of the scope when you check what a website design package includes.
| Incident sub-category | Handover item that reduces it | Incidents, Q1 2025 |
|---|---|---|
| Website defacement | Updates owner, tested backups |
68 |
| Account compromise | Named accounts, 2FA, recovery emails |
64 |
| Vulnerability probes | Plugin list, remove unused add-ons |
61 |
| Login brute force | No shared “admin” login, 2FA |
40 |
| Misconfiguration disclosure | Hosting review, remove old test files |
22 |
| Web vulnerability reports | Maintained plugins and theme |
11 |
Aggregated by IZI Digital Marketing from the MyCERT Cyber Incident Quarterly Summary Report Q1 2025 (Cyber999 Incident Response Centre, CyberSecurity Malaysia; January to March 2025 monthly sub-category totals). Handover mapping by IZI Digital Marketing.
According to the MyCERT Q1 2025 summary report, intrusion incidents rose 76% from Q4 2024, from 75 to 132 cases. These are only reported incidents, so the real number is higher. Most of these categories are access problems: old accounts, shared passwords and plugins nobody updates.
Taking over a site and unsure who still has access?
Tell us what you received at handover and we will point out the accounts and settings still worth checking. Ask for a handover review
PART 4 · DRIVE
Your First 90 Days After Taking Over the CMS
IN BRIEFAfter handover, somebody must own updates, backups and access reviews, or the site slowly drifts back to risk. Set a simple routine for the first 90 days and keep it. Our guide to what website maintenance should cover shows how to turn it into an ongoing plan.
| When | What to do |
|---|---|
| Week 1 | Check backups are running, forms are arriving and Search Console shows no new errors |
| Every week | Apply plugin, theme and core updates on a copy first, or with a backup taken just before |
| Day 30 | Remove plugins you do not use and check page speed has not dropped |
| Day 60 | Review user accounts and roles; confirm privacy notice and consent forms still match how you collect data |
| Day 90 | Do a second test restore and update your account register with every renewal date |
The Day 60 check links to your legal duties too. Contact forms collect personal data, so our note on PDPA and your website is worth reading once you own the forms. Keep an eye on accessibility as your team adds content; our guide on whether your designer covers website accessibility lists simple content rules. For admin roles, the official WordPress roles and capabilities documentation explains what each level can do.
BENCHMARK BRIEFING 4 OF 4
How Long Does a Proper CMS Takeover Take?
IN BRIEFPlan for a working day on a simple brochure site and two to three days on an online store or custom build. The platform choice drives most of the effort, which is worth weighing when you compare WordPress, Webflow and custom builds.
| Site type | Access transfer + audit and clean-up + backup testing (hours) | Total hours |
|---|---|---|
| Hosted site builder |
2 + 1 + 1 |
4 |
| Brochure WordPress site |
3 + 3 + 2 |
8 |
| WooCommerce store |
5 + 8 + 4 |
17 |
| Custom-coded site |
6 + 10 + 6 |
22 |
Illustrative model by IZI Digital Marketing, built on the Patchstack 2025 and 2026 WordPress security reports and typical handover workflows for Malaysian SME websites, 2026. Dark = access transfer; orange = audit and clean-up; light = backup and restore testing. Hours are planning estimates, not quotes or measured client data.
Hosted builders are quick because the platform handles hosting, updates and backups; you mainly transfer the account. Stores and custom builds take longer because there is more to check: payment gateways, order emails, stock sync and code only the original developer understands. For a custom build, insist on access to the code repository and a written deployment guide, or the takeover is never truly finished.
THE VERDICT
Take Control Before You Make the Final Payment
A website handover checklist is only useful if you run it while you still have leverage. Write the ten items into the contract, schedule a handover session, test every form and restore one backup before the last invoice is paid.
The builder can stay on as your support partner; that is often the sensible choice. What changes is who holds the keys. When you brief a website designer, ask how they hand over a CMS. A clear, confident answer tells you a lot about how they will manage the rest of your website design project, and a clean handover also protects the SEO work you build on top of it.
FAQ
Frequently Asked Questions
1. What should I receive when a website is handed over?
You should receive working control, not just a password. It depends on the platform, but for most sites that means the domain, hosting, your own CMS administrator account, plugin licences, off-site backups, form and email settings, owner access to analytics and Search Console, and basic documentation.
2. Should my web designer keep admin access after handover?
Yes, if they still maintain the site, but on a separate named account. It depends on your support arrangement. You should hold the top-level accounts, and the designer’s access should be removable by you in minutes without breaking anything.
3. How do I know if my website backups actually work?
Restore one. It depends on your host and backup tool, but the only real proof is a successful restore to a test copy of the site. Store backups off the main server, in storage your company controls, and repeat the test every few months.
4. What if my previous developer will not hand over the website?
Start with what you can prove you own. It depends on whose name the domain and hosting are in. If they are in your company’s name, you can regain control through the registrar and host. If not, check your contract and seek legal advice before the next renewal date.
5. Do I need to change passwords after a website handover?
Yes, for every account the builder knew. It depends on how access was shared, but you should also change recovery emails, switch on two-factor authentication and remove any unused accounts. Store the new passwords in a company password manager.
About to take over your website and want a second opinion first?
Book a free Blueprint consultation. We will help you decide what to demand at handover, who should keep access and what your team needs to run the site with confidence.