wordpress website handoff checklist for clients and developers — this guide shows what a safe, practical handoff looks like, what to check, and when to stop DIY troubleshooting. If your project includes custom WordPress development or advanced integrations and you'd rather not handle the transfer yourself, Request a WordPress website quote and we can handle the full handoff and support.
Table of contents
- What This Handoff Covers And Who Should Use It
- Pre-Handoff Requirements: Backups, Access, And Staging
- Core Deliverables Every Handoff Should Include
- Staging, Testing, And Quality Assurance
- Technical Handoff Steps For Developers
- Maintainability: Documentation, Training, And Routine Tasks
- Custom Work, Known Limitations, And When To Hire An Experienced Developer
- Final Quick Handoff Checklist (Printable)
- Rollback, Emergency Steps, And Troubleshooting Guidance
- Appendix: Handoff Templates And Resources
- FAQ
- Next steps
What This Handoff Covers And Who Should Use It
Who This Checklist Is For
This checklist is for business owners, content editors, project managers, and developers involved in a WordPress project transfer. Use it when a developer is delivering a site to a client, when you move a site between hosts, or when responsibility shifts to a different developer or agency.
What You Will Be Able To Do After Handoff
After a successful handoff you should be able to:
- Access and update content from the WordPress admin safely.
- Manage routine maintenance (backups, updates) or know who is responsible.
- Understand where files, database, credentials, and licenses live.
- Rollback quickly if a change breaks the site.
Risk Level And When To Stop DIY Troubleshooting
Handoffs involve medium risk: database changes, DNS, SSL, email, and payment integrations. Back up first and use staging where possible. If the project includes custom PHP, REST endpoints, or server tweaks, stop DIY and contact an experienced developer.
For broader context on the handoff within the development lifecycle, see the practical guide to the overall development process: the development lifecycle.
Pre-Handoff Requirements: Backups, Access, And Staging
Create And Verify Full Backups
Both parties should take independent backups before any transfer or DNS change. Backups must include:
- Complete site files (wp-content, wp-config.php, uploads).
- Full database export (SQL).
- Exported XML content for posts/pages if needed.
Test a restore on a staging environment when possible. Don’t assume a backup plugin completed successfully—verify file sizes and test import if time allows.
Confirm A Working Staging Site
Use a staging site for the final acceptance tests and a dry-run of the switch. If you need guidance on setting up and using a staging site, read why staging is essential: staging benefits and setup.
Document User Accounts And Permissions
Prepare a list of admin, editor, and developer accounts. Replace shared personal accounts with role-based accounts where practical. Agree on which developer accounts will be removed after handoff.
Agree On Rollback And Emergency Contacts
Before the go-live, both parties should agree on a rollback procedure and emergency contact details for the host and the developer. Keep phone and email contacts for quick escalation.
Core Deliverables Every Handoff Should Include
Site Files And Theme/Child Theme Source
Deliver the active theme folder and any child theme source. If custom WordPress development was done, include the original source files, build instructions, and a note on any build tools used (for example, asset compilers).
Database Export And Import Instructions
Include a timestamped SQL export and clear import instructions. If serialized data or custom tables exist, document how to update URLs or run search‑and‑replace safely during migration.
Plugin List And License Keys
Provide a complete list of plugins with versions and any license or purchase keys. Note which plugins require transfer of ownership and which remain tied to the developer’s account.
Hosting, Domain, And SSL Details
Document the hosting provider, control panel access, DNS provider credentials, and SSL details. Note any managed services (server-side caching, CDN, email routing) and where to change relevant settings.
Admin And FTP/SFTP Credentials (Secure Transfer)
Share credentials securely using a password manager or an agreed secure channel. Do not email passwords in plain text. After handoff, rotate keys and change passwords that were used during development.
SEO And Analytics Access
Transfer ownership or add the client’s accounts to Google Search Console and analytics platforms. Provide instructions for verifying ownership and reassigning access to avoid losing tracking data.
Staging, Testing, And Quality Assurance
Why A Staging Site Is Essential
Testing on staging prevents surprises on the live site. Reproduce typical user journeys and run acceptance tests on the staging URL before the move.
Design QA Across Desktop, Tablet, And Mobile
Check layout, typography, and images at common breakpoints. Use the design QA checklist to run consistent cross-device checks: design QA checklist.
Functional Tests: Forms, Payments, Integrations
Test every form and integration. Confirm form emails are delivered (see common email issues and prevention tips: contact form email guide), test payment flows in sandbox and live modes, and validate CRM or marketing integrations.
Performance Smoke Tests And Known Limitations
Run basic performance tests (page load times, TTFB) and note any expected limitations such as large image libraries or external API latency. Document which optimizations are left for a later phase.
Search Console And Indexing Checks
Verify robots.txt, sitemap availability, and Search Console property ownership. If the staging site was indexed, ensure canonical and noindex tags are correct before switching live DNS.
Technical Handoff Steps For Developers
Prepare A Clear Deployment Plan
Share a step-by-step deployment plan with timestamps, responsibilities, and contact details. Include a dry-run on staging so everyone knows the expected downtime and DNS TTL settings.
Switching From Staging To Production Safely
- Put the live site into maintenance mode if necessary.
- Take a final staging backup and a fresh live backup.
- Export the staging database and run safe search-and-replace for URLs.
- Upload files and import the database to production.
- Update wp-config.php settings (DB credentials, environment flags).
- Clear caches (server, CDN, plugin caches).
- Run acceptance tests on the live site and roll back if critical issues occur.
Update Site URLs, Permalinks, And Canonical Settings
After migration, verify WordPress Address and Site Address, regenerate permalinks, and confirm canonical URLs. If the site changed domains, check redirects and update internal links where needed.
Verify PHP Version, File Permissions, And Error Logs
Confirm the production PHP version matches tested environments. Check file permissions for uploads and themes, and review server error logs for hidden issues. If you need guidance on PHP compatibility testing, treat changes as higher risk and test on staging first.
Secure Transfer Of Credentials And Removal Of Developer Access
Provide credentials via a secure password manager, then remove or rotate developer accounts after signoff. Document any long-term service accounts left in place and who controls them.
When integrations are involved, document how they were configured; see the guide on adding third-party integrations for best practices and documentation tips: integration guidance.
Maintainability: Documentation, Training, And Routine Tasks
Provide A Simple Admin Guide And Editor Instructions
Deliver a short guide that covers logging in, editing pages, adding media, and using any custom blocks or fields. If custom fields were used to structure content, include examples and link to tips on using custom fields effectively: custom fields guide.
List Routine Maintenance Tasks And Frequencies
At minimum, document:
- Daily/weekly backups and verification.
- Monthly plugin and theme updates (with staging first).
- Quarterly performance and security reviews.
Plugin And Theme Update Policy
Explain which updates are automatic, which require staging tests, and which must be run by a developer. For decisions between plugin or custom code, see the safer option discussion: plugin vs custom code.
How To Request Changes And Developer Handoff Support
Include contact details, typical response times, and an agreed scope for post-handoff support. If a retainer is appropriate, outline what it covers and when a developer should be retained for ongoing custom work.
Custom Work, Known Limitations, And When To Hire An Experienced Developer
Safe Customization Examples (Content, Styles)
Clients can safely edit content, adjust images, and make basic style changes through a visual editor or theme customizer. Training should show how to make these edits without changing theme files.
Higher-Risk Customizations (Custom PHP, REST Endpoints)
Custom PHP, REST endpoints, database schema changes, or server config are higher risk. These require careful documentation, tests, and usually an experienced developer to maintain. If your site includes these, consider keeping a developer on retainer.
When To Keep A Developer On Retainer
Keep a developer on retainer if you have frequent custom features, critical integrations, or strict uptime requirements. A retainer speeds fixes and reduces the risk of introducing technical debt.
How To Document Custom Code For Future Developers
Provide inline comments, a README for custom plugins/themes, and deployment notes. Include versioning information, where code is hosted (Git repo), and how to build or deploy assets.
For tradeoffs between custom themes and off-the-shelf options, the custom theme guide explains costs and when custom work needs more experienced developers: custom theme tradeoffs.
Final Quick Handoff Checklist (Printable)
Pre-Deployment Quick Checks
- Full backups taken and verified (files + DB).
- Staging acceptance tests completed and signed off.
- Credentials prepared and secure transfer method agreed.
- Rollback plan and emergency contacts documented.
Day-Of-Switch Checklist
- Notify stakeholders and set maintenance mode if needed.
- Final staging backup and fresh live backup taken.
- Deploy files and import database with correct search-and-replace.
- Update wp-config, clear caches, and check SSL.
- Run smoke tests for key forms, payments, and pages.
Post-Deployment Acceptance Checks
- Confirm DNS propagation and HTTPS working.
- Verify Google Search Console and analytics ownership.
- Test email delivery for contact forms.
- Rotate or remove development accounts and keys.
- Deliver documentation and schedule the first maintenance window.
Rollback, Emergency Steps, And Troubleshooting Guidance
How To Restore From Backup
To restore:
- Put site in maintenance mode.
- Restore files from the backup archive.
- Import the SQL file to the database (consider temporarily disabling wp-cron).
- Verify wp-config.php points to correct DB credentials.
- Clear all caches and test critical pages.
Common Problems After Handoff And Quick Fixes
- White screen or PHP error: check error logs and revert the last change.
- Missing images: verify uploads folder permissions and file paths.
- Emails not sending: configure SMTP or transactional email provider and test; see email deliverability guide earlier for prevention tips.
- Broken integrations: check API keys and webhooks, then reauthorize if needed.
When To Contact A Developer Or Host
Contact the developer for bugs related to custom code, theme functions, or integrations. Contact the host for server-level issues such as downtime, SSL provisioning, or DNS configuration problems.
Appendix: Handoff Templates And Resources
Credentials And Handoff Template
Include a table with account name, URL, username, notes (owner), and a reminder to transfer ownership where appropriate. Use a password manager rather than plain text for sharing secrets.
Deployment Plan Template
Prepare a checklist with timestamps, responsible person, backup locations, and verification steps. Keep it short and specific to avoid confusion during the switch.
Further Reading And Official Docs
Refer to WordPress.org documentation on migration and wp-config, hosting docs for DNS and SSL, and plugin/theme docs for license transfers. These vendor documents vary by host and plugin, so always confirm details before a live switch.
FAQ
What should be backed up before a WordPress handoff?
Back up all site files, the database (SQL), and any configuration or environment files. Verify backups by inspecting file sizes and, when possible, testing a restore on staging.
Why is a staging site important for handoff and how do I test it?
Staging lets you test changes without affecting live users. Test key pages, forms, payments, integrations, and mobile layouts. Review the staging best practices linked earlier for setup tips.
Which credentials should developers hand over and how should they be transferred securely?
Hand over admin accounts, FTP/SFTP, hosting panel, DNS provider, SSL manager, and analytics/Search Console access. Transfer via a password manager or secure portal and rotate passwords after transfer.
How do I verify plugins, themes, and license keys after handoff?
Log into plugin/theme accounts and confirm licenses are active. Note which licenses require ownership transfer and follow vendor procedures to reassign them.
What basic tests should I run on day one after the site goes live?
Test homepage and key pages, forms, login, payment flow (if applicable), mobile responsiveness, SSL, and analytics events. Confirm Search Console and sitemap submission.
How do I roll back to a previous version if something breaks?
Follow the restore procedure: enable maintenance mode, restore files, import the backup DB, update wp-config if necessary, and clear caches. Keep communication open with stakeholders during rollback.
When does custom code require an experienced developer to maintain?
If the site uses custom PHP, REST API endpoints, custom database tables, or server-level configurations, an experienced developer should handle updates and troubleshooting.
What documentation should a developer provide at handoff?
Provide a README, deployment steps, credentials list, plugin/theme list with licenses, maintenance schedule, and basic admin training notes.
How should SEO, Google Search Console, and analytics be handled during handoff?
Verify ownership, add the client's accounts, confirm sitemap and robots settings, and avoid accidentally indexing staging. Update any URL changes and submit sitemaps after go-live.
Who is responsible for ongoing security updates and plugin maintenance after handoff?
Responsibility should be defined in your contract. If the client takes over, provide a maintenance checklist; otherwise, keep agreed retainer terms for updates and monitoring.
Can I safely change the site's PHP version after handoff?
Only change PHP versions after testing on staging. Some plugins or themes may be incompatible; treat PHP upgrades as higher risk and schedule them with a developer if custom code exists.
How do I avoid losing email deliverability after migration?
Keep DNS MX records, SPF, DKIM, and DMARC configured correctly. If you move mail hosting or change sending systems, test with a transactional email provider and update form settings to use SMTP if necessary.
Next steps
If the handoff includes custom WordPress development, complex integrations, or you're not confident running the migration yourself, Request a WordPress website quote and we can take care of the full transfer, testing, and post-handoff support.