The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Take control in a deliberate order: secure the accounts behind the website, document how it is set up, confirm you can restore it, and only then make changes. A WordPress administrator login does not automatically transfer ownership of the domain, hosting, business email, billing, analytics, payment services, or other connected accounts. Each provider may have its own transfer and recovery requirements.
1. Confirm ownership and recovery access
Start by identifying who controls every account the site depends on. Ask the previous owner, organization, or outgoing agency to help transfer ownership and confirm recovery access with each provider; there is no single universal transfer procedure.
- Domain registrar and DNS management
- Hosting account and server access
- WordPress administrator accounts
- Business email used for account recovery and site notifications
- Billing, analytics, payment or donation services, and other integrations
Make sure you can receive recovery messages and manage billing before relying on an account as yours. Keep a record of the account owner and recovery route for each service.
2. Inventory the site before editing
Record the current setup so you can distinguish a pre-existing condition from a change you make. In WordPress, open Tools > Site Health. The Status tab reports issues, while the Info tab exposes technical details about WordPress, themes, plugins, the server, database, and filesystem permissions. Info is for inspection, not configuration. See the WordPress Site Health documentation.
#1 Best Overall
- WordPress version and whether the site is a live or staging environment
- Number of WordPress users and their roles
- Active and inactive themes and plugins
- PHP and server details, database information, and filesystem permissions
Save the inventory somewhere accessible to the people responsible for the site, but do not publish sensitive configuration details.
3. Make sure you have a restorable backup
Confirm that a backup includes both the site files and its database, where the copy is stored, how often it is created, and who knows how to restore it. WordPress recommends backing up before updates; its maintenance guidance discusses retaining copies on the host and on a computer. A copy that nobody has restored is not a restore-tested backup. Read WordPress’s update guidance and site maintenance guidance.
A second copy on an external drive can be useful, but it does not by itself automate backups, capture the database, provide off-site redundancy, or prove restoration works. If the site handles frequent publishing or transactions, account for that activity when deciding how often to back up.
Rank #2
4. Review users and privileges
List the WordPress accounts and determine who still needs access. WordPress has six predefined roles with different capabilities; an Administrator can do more than an Editor, Author, Contributor, or Subscriber. Keep each person’s permissions aligned with their work, and remove or change access only after confirming that an account is no longer needed. The Roles and Capabilities documentation explains the distinctions.
Free tools Windows power users keep installed
One-click scans. No signup required.
Review access separately for the registrar, host, email, and connected services. Cleaning up WordPress users alone does not secure the other accounts behind the site.
5. Document what the site depends on
Record the theme, plugins, integrations, forms, analytics, backup arrangements, renewal dates, and important business workflows. Site Health can help inventory themes, plugins, and technical configuration, but it cannot reveal every contract, vendor arrangement, or external integration.
Rank #3
Before removing an unfamiliar plugin, theme, or integration, ask the previous owner, agency, or relevant vendor what it does. A component that appears unused in the dashboard may support a form, payment path, or other critical function.
6. Check Site Health and exposed problems
In Tools > Site Health, review critical issues and recommended improvements. Check the WordPress version, available updates, plugin and theme status, PHP version, server configuration, and permissions. The report can flag issues such as outdated PHP, pending plugin updates, or background updates that are not working as expected. Use the Site Health documentation to understand what its screens report.
WordPress’s supported versions page says the latest major release is the only version currently officially supported and does not guarantee security updates for older branches. Support status can change, so check the live page when assessing the site rather than treating an old version as supported by assumption.
Rank #4
7. Update WordPress, themes, and plugins carefully
Once you have confirmed a backup and know how to recover the site, update WordPress, themes, and plugins in a controlled way. WordPress recommends updating to the latest version and warns that updates affect installation files. After each update, check important pages and workflows before continuing.
If you use automatic plugin or theme updates, make sure a rollback-capable backup is available and understand how updates are scheduled. WordPress’s guidance notes that scheduled updates rely on WordPress Cron tasks. See Plugin and themes auto-updates.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.8. Coordinate PHP or server changes with the host
If Site Health indicates an old PHP version or another server configuration problem, do not change the server blindly. WordPress recommends backing up, updating WordPress, themes, and plugins, and checking compatibility before updating PHP. Some settings are controlled by the hosting provider, so coordinate the change with the host. Follow WordPress’s PHP update guidance alongside the Site Health report.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallBest Value
9. Test the public site and its important workflows
Visit the site as a regular visitor, not just as an administrator. Check the pages and actions that matter for this particular business or organization:
- Key pages, navigation, and internal and external links
- Forms and whether submissions reach the right people
- Checkout, donations, or other payment paths, if present
- Email delivery, analytics, and mobile presentation
WordPress maintenance guidance also recommends reviewing statistics and 404 errors and checking links. Prioritize the checks according to what the site actually does; a donation flow matters on a fundraising site, while another site may have different critical tasks. See WordPress site maintenance.
10. Set a maintenance routine and preserve handoff records
Keep a handoff record that identifies who owns each account, where backups are stored, how restoration works, which services renew, and whom to contact. Schedule backups and routine checks at a pace suited to how often the site’s content and transactions change. WordPress recommends regularly scheduled backups and routine maintenance checks, but does not prescribe one cadence for every site. Its maintenance guidance provides a starting point.
If you change hosts or bring in maintenance support, evaluate account ownership and portability, migration assistance, support coverage, backup retention and restoration, PHP and server support, staging options, and recurring cost before committing.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

