WordPress Development & Customization

WordPress Website Handoff Checklist for Clients and Developers

A practical, step-by-step checklist to ensure a safe, complete WordPress handoff — for both clients and developers. Includes deployment, testing, and maintainability tips.

Ask ChatGPT Ask Claude Ask Gemini Ask Perplexity

wordpress website handoff checklist for clients and developers — this guide shows what a safe, practical handoff looks like, what to check, and when to stop DIY troubleshooting. If your project includes custom WordPress development or advanced integrations and you'd rather not handle the transfer yourself, Request a WordPress website quote and we can handle the full handoff and support.

Table of contents

What This Handoff Covers And Who Should Use It

Who This Checklist Is For

This checklist is for business owners, content editors, project managers, and developers involved in a WordPress project transfer. Use it when a developer is delivering a site to a client, when you move a site between hosts, or when responsibility shifts to a different developer or agency.

What You Will Be Able To Do After Handoff

After a successful handoff you should be able to:

  • Access and update content from the WordPress admin safely.
  • Manage routine maintenance (backups, updates) or know who is responsible.
  • Understand where files, database, credentials, and licenses live.
  • Rollback quickly if a change breaks the site.

Risk Level And When To Stop DIY Troubleshooting

Handoffs involve medium risk: database changes, DNS, SSL, email, and payment integrations. Back up first and use staging where possible. If the project includes custom PHP, REST endpoints, or server tweaks, stop DIY and contact an experienced developer.

For broader context on the handoff within the development lifecycle, see the practical guide to the overall development process: the development lifecycle.

Pre-Handoff Requirements: Backups, Access, And Staging

Create And Verify Full Backups

Both parties should take independent backups before any transfer or DNS change. Backups must include:

  • Complete site files (wp-content, wp-config.php, uploads).
  • Full database export (SQL).
  • Exported XML content for posts/pages if needed.

Test a restore on a staging environment when possible. Don’t assume a backup plugin completed successfully—verify file sizes and test import if time allows.

Confirm A Working Staging Site

Use a staging site for the final acceptance tests and a dry-run of the switch. If you need guidance on setting up and using a staging site, read why staging is essential: staging benefits and setup.

Document User Accounts And Permissions

Prepare a list of admin, editor, and developer accounts. Replace shared personal accounts with role-based accounts where practical. Agree on which developer accounts will be removed after handoff.

Agree On Rollback And Emergency Contacts

Before the go-live, both parties should agree on a rollback procedure and emergency contact details for the host and the developer. Keep phone and email contacts for quick escalation.

Core Deliverables Every Handoff Should Include

Site Files And Theme/Child Theme Source

Deliver the active theme folder and any child theme source. If custom WordPress development was done, include the original source files, build instructions, and a note on any build tools used (for example, asset compilers).

Database Export And Import Instructions

Include a timestamped SQL export and clear import instructions. If serialized data or custom tables exist, document how to update URLs or run search‑and‑replace safely during migration.

Plugin List And License Keys

Provide a complete list of plugins with versions and any license or purchase keys. Note which plugins require transfer of ownership and which remain tied to the developer’s account.

Hosting, Domain, And SSL Details

Document the hosting provider, control panel access, DNS provider credentials, and SSL details. Note any managed services (server-side caching, CDN, email routing) and where to change relevant settings.

Admin And FTP/SFTP Credentials (Secure Transfer)

Share credentials securely using a password manager or an agreed secure channel. Do not email passwords in plain text. After handoff, rotate keys and change passwords that were used during development.

SEO And Analytics Access

Transfer ownership or add the client’s accounts to Google Search Console and analytics platforms. Provide instructions for verifying ownership and reassigning access to avoid losing tracking data.

Staging, Testing, And Quality Assurance

Why A Staging Site Is Essential

Testing on staging prevents surprises on the live site. Reproduce typical user journeys and run acceptance tests on the staging URL before the move.

Design QA Across Desktop, Tablet, And Mobile

Check layout, typography, and images at common breakpoints. Use the design QA checklist to run consistent cross-device checks: design QA checklist.

Functional Tests: Forms, Payments, Integrations

Test every form and integration. Confirm form emails are delivered (see common email issues and prevention tips: contact form email guide), test payment flows in sandbox and live modes, and validate CRM or marketing integrations.

Performance Smoke Tests And Known Limitations

Run basic performance tests (page load times, TTFB) and note any expected limitations such as large image libraries or external API latency. Document which optimizations are left for a later phase.

Search Console And Indexing Checks

Verify robots.txt, sitemap availability, and Search Console property ownership. If the staging site was indexed, ensure canonical and noindex tags are correct before switching live DNS.

Technical Handoff Steps For Developers

Prepare A Clear Deployment Plan

Share a step-by-step deployment plan with timestamps, responsibilities, and contact details. Include a dry-run on staging so everyone knows the expected downtime and DNS TTL settings.

Switching From Staging To Production Safely

  1. Put the live site into maintenance mode if necessary.
  2. Take a final staging backup and a fresh live backup.
  3. Export the staging database and run safe search-and-replace for URLs.
  4. Upload files and import the database to production.
  5. Update wp-config.php settings (DB credentials, environment flags).
  6. Clear caches (server, CDN, plugin caches).
  7. Run acceptance tests on the live site and roll back if critical issues occur.

Update Site URLs, Permalinks, And Canonical Settings

After migration, verify WordPress Address and Site Address, regenerate permalinks, and confirm canonical URLs. If the site changed domains, check redirects and update internal links where needed.

Verify PHP Version, File Permissions, And Error Logs

Confirm the production PHP version matches tested environments. Check file permissions for uploads and themes, and review server error logs for hidden issues. If you need guidance on PHP compatibility testing, treat changes as higher risk and test on staging first.

Secure Transfer Of Credentials And Removal Of Developer Access

Provide credentials via a secure password manager, then remove or rotate developer accounts after signoff. Document any long-term service accounts left in place and who controls them.

When integrations are involved, document how they were configured; see the guide on adding third-party integrations for best practices and documentation tips: integration guidance.

Maintainability: Documentation, Training, And Routine Tasks

Provide A Simple Admin Guide And Editor Instructions

Deliver a short guide that covers logging in, editing pages, adding media, and using any custom blocks or fields. If custom fields were used to structure content, include examples and link to tips on using custom fields effectively: custom fields guide.

List Routine Maintenance Tasks And Frequencies

At minimum, document:

  • Daily/weekly backups and verification.
  • Monthly plugin and theme updates (with staging first).
  • Quarterly performance and security reviews.

Plugin And Theme Update Policy

Explain which updates are automatic, which require staging tests, and which must be run by a developer. For decisions between plugin or custom code, see the safer option discussion: plugin vs custom code.

How To Request Changes And Developer Handoff Support

Include contact details, typical response times, and an agreed scope for post-handoff support. If a retainer is appropriate, outline what it covers and when a developer should be retained for ongoing custom work.

Custom Work, Known Limitations, And When To Hire An Experienced Developer

Safe Customization Examples (Content, Styles)

Clients can safely edit content, adjust images, and make basic style changes through a visual editor or theme customizer. Training should show how to make these edits without changing theme files.

Higher-Risk Customizations (Custom PHP, REST Endpoints)

Custom PHP, REST endpoints, database schema changes, or server config are higher risk. These require careful documentation, tests, and usually an experienced developer to maintain. If your site includes these, consider keeping a developer on retainer.

When To Keep A Developer On Retainer

Keep a developer on retainer if you have frequent custom features, critical integrations, or strict uptime requirements. A retainer speeds fixes and reduces the risk of introducing technical debt.

How To Document Custom Code For Future Developers

Provide inline comments, a README for custom plugins/themes, and deployment notes. Include versioning information, where code is hosted (Git repo), and how to build or deploy assets.

For tradeoffs between custom themes and off-the-shelf options, the custom theme guide explains costs and when custom work needs more experienced developers: custom theme tradeoffs.

Final Quick Handoff Checklist (Printable)

Pre-Deployment Quick Checks

  • Full backups taken and verified (files + DB).
  • Staging acceptance tests completed and signed off.
  • Credentials prepared and secure transfer method agreed.
  • Rollback plan and emergency contacts documented.

Day-Of-Switch Checklist

  • Notify stakeholders and set maintenance mode if needed.
  • Final staging backup and fresh live backup taken.
  • Deploy files and import database with correct search-and-replace.
  • Update wp-config, clear caches, and check SSL.
  • Run smoke tests for key forms, payments, and pages.

Post-Deployment Acceptance Checks

  • Confirm DNS propagation and HTTPS working.
  • Verify Google Search Console and analytics ownership.
  • Test email delivery for contact forms.
  • Rotate or remove development accounts and keys.
  • Deliver documentation and schedule the first maintenance window.

Rollback, Emergency Steps, And Troubleshooting Guidance

How To Restore From Backup

To restore:

  1. Put site in maintenance mode.
  2. Restore files from the backup archive.
  3. Import the SQL file to the database (consider temporarily disabling wp-cron).
  4. Verify wp-config.php points to correct DB credentials.
  5. Clear all caches and test critical pages.

Common Problems After Handoff And Quick Fixes

  • White screen or PHP error: check error logs and revert the last change.
  • Missing images: verify uploads folder permissions and file paths.
  • Emails not sending: configure SMTP or transactional email provider and test; see email deliverability guide earlier for prevention tips.
  • Broken integrations: check API keys and webhooks, then reauthorize if needed.

When To Contact A Developer Or Host

Contact the developer for bugs related to custom code, theme functions, or integrations. Contact the host for server-level issues such as downtime, SSL provisioning, or DNS configuration problems.

Appendix: Handoff Templates And Resources

Credentials And Handoff Template

Include a table with account name, URL, username, notes (owner), and a reminder to transfer ownership where appropriate. Use a password manager rather than plain text for sharing secrets.

Deployment Plan Template

Prepare a checklist with timestamps, responsible person, backup locations, and verification steps. Keep it short and specific to avoid confusion during the switch.

Further Reading And Official Docs

Refer to WordPress.org documentation on migration and wp-config, hosting docs for DNS and SSL, and plugin/theme docs for license transfers. These vendor documents vary by host and plugin, so always confirm details before a live switch.

FAQ

What should be backed up before a WordPress handoff?

Back up all site files, the database (SQL), and any configuration or environment files. Verify backups by inspecting file sizes and, when possible, testing a restore on staging.

Why is a staging site important for handoff and how do I test it?

Staging lets you test changes without affecting live users. Test key pages, forms, payments, integrations, and mobile layouts. Review the staging best practices linked earlier for setup tips.

Which credentials should developers hand over and how should they be transferred securely?

Hand over admin accounts, FTP/SFTP, hosting panel, DNS provider, SSL manager, and analytics/Search Console access. Transfer via a password manager or secure portal and rotate passwords after transfer.

How do I verify plugins, themes, and license keys after handoff?

Log into plugin/theme accounts and confirm licenses are active. Note which licenses require ownership transfer and follow vendor procedures to reassign them.

What basic tests should I run on day one after the site goes live?

Test homepage and key pages, forms, login, payment flow (if applicable), mobile responsiveness, SSL, and analytics events. Confirm Search Console and sitemap submission.

How do I roll back to a previous version if something breaks?

Follow the restore procedure: enable maintenance mode, restore files, import the backup DB, update wp-config if necessary, and clear caches. Keep communication open with stakeholders during rollback.

When does custom code require an experienced developer to maintain?

If the site uses custom PHP, REST API endpoints, custom database tables, or server-level configurations, an experienced developer should handle updates and troubleshooting.

What documentation should a developer provide at handoff?

Provide a README, deployment steps, credentials list, plugin/theme list with licenses, maintenance schedule, and basic admin training notes.

How should SEO, Google Search Console, and analytics be handled during handoff?

Verify ownership, add the client's accounts, confirm sitemap and robots settings, and avoid accidentally indexing staging. Update any URL changes and submit sitemaps after go-live.

Who is responsible for ongoing security updates and plugin maintenance after handoff?

Responsibility should be defined in your contract. If the client takes over, provide a maintenance checklist; otherwise, keep agreed retainer terms for updates and monitoring.

Can I safely change the site's PHP version after handoff?

Only change PHP versions after testing on staging. Some plugins or themes may be incompatible; treat PHP upgrades as higher risk and schedule them with a developer if custom code exists.

How do I avoid losing email deliverability after migration?

Keep DNS MX records, SPF, DKIM, and DMARC configured correctly. If you move mail hosting or change sending systems, test with a transactional email provider and update form settings to use SMTP if necessary.

Next steps

If the handoff includes custom WordPress development, complex integrations, or you're not confident running the migration yourself, Request a WordPress website quote and we can take care of the full transfer, testing, and post-handoff support.