Most of the sites we look after were built by someone else — another agency, a freelancer who has moved on, or the business itself years ago. That’s completely normal. It just means the first week is about understanding the site before changing it.
Here is the checklist we work through before a site joins a regular care routine.
Access, done properly
We ask for access only after agreeing the scope, and never by email. The aim is named accounts with the permissions the work needs — not a shared admin password that has been passed around for years.
- A personal WordPress administrator account for the person doing the work.
- Hosting access, ideally as a separate user or collaborator.
- Knowing who controls the domain and DNS, even if we don’t need to change them.
An honest inventory
Next, we write down what the site is made of. It sounds basic, but it is the part that most often turns up surprises:
- Theme and child theme — and whether the theme itself has been edited directly.
- Plugins: which are active, which are abandoned, which need a paid licence and who owns it.
- Custom code, snippets and anything added outside the usual places.
- Integrations: CRM, newsletter, payments, analytics and anything sending email.
- The PHP version and what the host supports — see which PHP version WordPress should use.
A baseline before any change
Before the first update, we record how the site looks and behaves today, so any change can be compared against it.
- A full backup, stored off-site, and a check that it can be restored.
- Uptime and SSL monitoring switched on.
- The key pages and the one form or journey we’ll watch, agreed and noted.
- A list of what is already broken or unusual, so it isn’t mistaken for something an update caused.
The quiet surprises
Inherited sites often carry a few things that work today but make every future update riskier:
- Plugins that haven’t been updated by their authors for a long time.
- Premium plugins with expired licences, which stop receiving updates.
- Copies of paid plugins from unofficial sources, which can hide malicious code.
- Plugin files edited directly, so an update would silently undo the changes.
- A large backlog of pending updates.
None of these mean a site can’t be looked after. They just need to be understood — and sometimes cleaned up — first.
Agreeing what happens next
At the end of the review we explain what we found in plain English. If anything needs cleanup before regular care makes sense, we describe the work and its cost separately, before the recurring service starts. Nothing is changed on the live site until access, backups and the baseline are in place.
It’s a slower first week than simply clicking “Update all”. It is also what makes every week after it calmer.
Frequently asked questions
What access do I need to take over a WordPress site?
A personal administrator account in WordPress, hosting access and knowledge of who controls the domain and DNS. Named accounts are safer than shared passwords.
Should I update everything straight away?
No. Take a backup, test a restore and record a baseline first. A large backlog of updates is safer applied in stages.
How do I spot nulled or pirated plugins?
Premium plugins without a valid licence, downloaded from unofficial sources or unable to update through the vendor, are warning signs. Replace them with licensed copies.
What if the previous developer isn’t available?
It’s common. Access can usually be recovered through the hosting account and domain registrar, and the site itself documents much of how it was built.