Skip to content

How to take over a WordPress site when your web developer has disappeared

A website is three things with three owners of record. They are the domain name, the hosting account and the WordPress administrator account. Recover them in that order, through the registrar, the host and WordPress's documented reset methods, because each one unlocks the next.

By
WP Ministry
Updated

In short

  • Recover the domain first, then the hosting, then WordPress. Each one unlocks the next.
  • Look the domain up today. The lookup shows the registrar and the expiry date. Renewal reminders may be going to an address that is not yours.
  • If the developer is the registrant of record, the registrar decides. ICANN says you may need proof that you paid for the domain.
  • You can move a site to new hosting without transferring the domain, by changing its name servers.
  • With hosting access, one WP-CLI command makes you an administrator. Without the command line, WordPress documents a password reset in the database.
  • Once you are in, take a full backup you hold yourself, then change every password and the salts.

Your website is three separate things, each with its own owner of record: the domain name, the hosting account and the WordPress administrator account. Recover them in that order. The domain decides where visitors and email are sent, the hosting holds the files and the database, and with the hosting you can let yourself into WordPress.

None of it needs the developer's passwords. It needs the registrar, the host and the reset methods WordPress documents. Parts of this page touch on who holds a domain and what a contract says. It reports what ICANN and each provider publish, and it is not legal advice.

Find out what you have

Before you write to anyone, collect the evidence. An invoice or a card statement with a company's name on it is the kind of proof ICANN says a registrar may ask for, and it is the first thing to send a host.

What to findWhere the evidence usually is
The domain registrarA lookup of the domain, which names the registrar. Renewal invoices and card statements.
DNS, which sends the domain to the website and the emailThe name servers in the same lookup. Search for their names to find the company that runs them.
The hosting accountInvoices and card statements. Old emails with a control panel address or a welcome message.
WordPress administrator accountsYour inbox, searched for the site's name and "password". Your password manager.
Email accounts on the domainThe company your mail program connects to. It can be the host, the registrar or a separate mail service.
Paid plugin and theme licensesReceipts from each vendor, in your inbox or on the developer's invoices.
Analytics and Search ConsoleThe Google account you sign in with. Check whether it lists the site at all.
Payment gateway accountsThe payouts on your bank statement, and the legal name on the gateway's account.

Start with the lookup. Enter the domain at ICANN's lookup tool. ICANN says the "Registrar" field shows who your registrar is. The result also lists the name servers and the date the registration expires. The registrant's own details may be redacted for privacy, so a blank there says nothing about who the registrant is.

Then see what the site is made of. The platform and theme detector reads the site from outside and reports the theme's folder, the page builder and the plugins that show. It is a first list of what you may need licenses for.

Domain first

ICANN compares a domain name to a street address. The building it leads to is the hosting, and the two can come from different companies. Whoever controls the address decides where visitors and mail arrive. That is why the domain comes first.

Find the registrar of record

The company you paid may not be the registrar. ICANN describes resellers as companies contracted by registrars to register names on their behalf. It also says the registrar remains "the responsible and accountable party" for names its resellers handle. If the developer or a reseller has gone quiet or closed, write to the registrar named in the lookup.

Find out who the registrant is

ICANN's definition is short: the registrant, also called the Registered Name Holder, "is the person or entity that holds the rights to a domain name." It tells you to check with your registrar who the registrant of record is. Paying the bills does not settle it. ICANN notes that a developer hired to manage a domain may have registered it with their own contact details, and may be listed as the official registrant even though you paid.

What you do next depends on the answer.

Where you standWhat to do
You are the registrant and the registrar account is yours, but the login is lostUse the registrar's account recovery. ICANN lists access to information about a registrar's processes for managing, transferring and restoring a registration among a registrant's rights.
You are the registrant, but the domain sits in the developer's registrar accountTell the registrar you are the Registered Name Holder and ask for the domain to be moved to an account of yours, or for the transfer code.
The developer is the registrant of recordAsk the developer for a change of registrant. If they do not answer, take your proof of payment to the registrar.

Under ICANN's Transfer Policy, the Registered Name Holder and the Administrative Contact are the only parties who can approve a move to another registrar, and in a dispute the holder's authority comes first. The move needs a code, which ICANN's pages call an Auth-Code or AuthInfo code. Where a registrar gives you no way to generate it yourself, it must provide the code within five calendar days of the holder's request.

A change of registrant is different. The policy has the registrar obtain explicit consent from both the prior registrant and the new one. If the developer still answers email, that confirmation is the one thing to ask them for.

If the developer does not answer, ICANN's guidance is this: "You may need to provide proof of your payment to the third-party/developer to prove to your registrar that you are the rightful holder." The registrar decides. ICANN states that it "does not get involved in disputes regarding domain ownership or registration." For a name registered to someone else, the options it lists include an agreement with the current registrant, a lawsuit in court and, for abusive registrations, a proceeding under its dispute resolution policy. A lawyer can tell you which of those fits your case.

Mind the lock

After a change to the registrant's name, organization or email address, registrars must block a move to another registrar for 60 days. Some let the prior registrant opt out before the change is made. ICANN's advice is to request the transfer first and change the details afterward. It also points out that you may not need a transfer at all: you can change the domain's name servers where it is and leave the registration in place.

Country-code domains have their own rules

Everything above is ICANN policy for generic domains such as .com and .org. Two-letter country-code domains such as .uk, .ca and .au are administered by country-code managers with their own requirements. IANA's root zone database names the manager for each one. Start with your registrar, then read the manager's own rules.

Then hosting

There are two situations, and the invoices tell you which one you are in.

If you pay the hosting company yourself

The account is yours. Reset the password with the email address on the invoices. If that address was the developer's, write to the host's support as the customer who pays, send the invoices, and ask what it needs to change the address on the account.

Once you are in, change the control panel password, then the passwords for file access and for the database. Remove any extra panel users and access keys that are not yours. WordPress's hardening guide says to connect with SFTP where the host offers it, so that the password is encrypted on the way.

If the site sits on the developer's hosting

On a reseller plan or the developer's own server, the hosting company's customer is the developer, not you. Do not count on the host to give you a login. What you need from this hosting is a full copy of the site. Then you leave.

WordPress's documentation is clear about what a full copy is: the files and the database. Copying the files does not copy the database, because it lives outside them. How you get both depends on the access you have.

The access you haveHow to take the copy
A control panel login for your own siteThe panel's backup feature, or its file manager for the files and phpMyAdmin for a database export
SFTP or SSHDownload the whole WordPress folder. Export the database with wp db export ~/database.sql, which writes it to an SQL file in your home folder. Do not leave an export in the site's own folder, where anyone who guesses its name can download it.
A WordPress administrator login onlyA backup plugin that packs files and database into a download
No access at allAsk the developer in writing for a full backup, and write to the hosting company with what you can prove

The dashboard's own export, under Tools, is not a full copy. WordPress's documentation lists what its file holds: posts, pages, custom post types, comments, custom fields, categories, tags, custom taxonomies and users. No theme, plugin or media file is on that list. Use it when nothing else is open to you.

With a copy in hand, open hosting in your own name, restore the copy there, check it, and only then change the name servers or the DNS records. The website migration checklist has the order. Find out where your email is hosted before you change anything in DNS, because the same records send your mail. Our WordPress migration service moves one WordPress site from one host to another and tests the copy on the new host before the DNS is changed.

Then WordPress

You now control the hosting and still have no administrator login. Try the login page first: select "Lost your password?" and enter your email address. If any account uses an address you can read, that is all you need.

If not, let yourself in from the server. This is hosting you control, and these are the methods WordPress documents for it.

With WP-CLI

WP-CLI is the command line tool for WordPress. How to use WP-CLI to manage a WordPress site covers connecting over SSH and checking that it is installed. Run these from the folder that holds wp-config.php.

  1. Step 1: List the administrators

    This prints every account with full control, with its email address and the date it was created. One of them may already be yours under an old address.

    bash
    wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
  2. Step 2: Create an administrator of your own

    Give a login name and your email address. With no password in the command, WP-CLI makes one up and prints it once, on a line that begins "Password:". Save it in your password manager, log in, and leave the developer's account alone for now.

    bash
    wp user create your-login you@example.com --role=administrator
  3. Step 3: Or reset the password on an account that is yours

    Name the user by login, email or ID. Keep the single quotes around the password. Without them the shell reads a $ and the letters after it as a variable and drops them, and the command can answer "Success" while the old password stays in place. The answer is "Success: Updated user" and the ID. --skip-email stops the notice WordPress would otherwise send to the address on the account.

    bash
    wp user update your-login --user_pass='a-long-new-password' --skip-email

Without the command line

WordPress's page on resetting a password gives a method for phpMyAdmin, a database tool that its backup guide shows how to open from several hosting control panels. The page carries a warning: use phpMyAdmin at your own risk. Export the database before you edit it.

  1. Step 1: Open the users table

    In phpMyAdmin, select the site's database. Its name is the DB_NAME value in wp-config.php. Find the table whose name ends in users. It is wp_users unless $table_prefix in the same file says otherwise. Browse it and find the row for an administrator.

  2. Step 2: Set a new password

    Edit the row. Clear the user_pass field and type the new password. In the function menu beside it, select MD5, then select "Go". The line below does the same from phpMyAdmin's SQL tab. Use your own table name and the ID of the row.

    sql
    UPDATE wp_users SET user_pass = MD5('a-long-new-password') WHERE ID = 1;
  3. Step 3: Change the email address in the same row

    Put your own address in user_email. Password resets for this account then come to you.

  4. Step 4: Log in and change the password again

    WordPress still accepts a password stored as an MD5 hash, and stores it again in its current, stronger format once you log in with it. Change it once more from your profile screen all the same: the one you typed into the database tool may have been seen or logged on the way.

The same page lists two further methods: a line added to the theme's functions.php, and an emergency script. Both must be removed straight after use. Leave them for when the two above are closed to you.

If the password works and something else stops you, such as a security plugin that wants a code from the developer's phone, see how to deactivate plugins when you are locked out.

Make it yours and make it safe

Being logged in is not the same as being in control. Work through these in order.

  1. Step 1: Take a full backup you hold yourself

    Files and database, downloaded to a place that is not the server. Do it before you change anything else, so there is a way back. How to schedule automatic WordPress backups then puts it on a schedule and shows how to prove that a copy restores.

  2. Step 2: Change every password

    The registrar, the DNS provider, the hosting panel, file access, the database user, every WordPress administrator and the mailboxes. The database password is also written in wp-config.php as DB_PASSWORD, so change it in both places or the site will lose its database connection.

  3. Step 3: Change the salts

    WordPress keeps eight keys and salts in wp-config.php. Its documentation says you can change them at any time to invalidate all existing cookies, and that all users will then have to log in again. That ends any session still open on someone else's computer. The command below replaces them. Without the command line, make a new set with the salt generator and paste it over the old lines.

    bash
    wp config shuffle-salts
  4. Step 4: Go through the user accounts

    Open the Users screen and select the Administrator link above the table. For the developer's account, lower its role or delete it. When you delete a user, WordPress asks what to do with the content that user owns. Choose to attribute it to another user, then select "Confirm Deletion". The other choice deletes that content along with the account. An administrator that neither you nor the developer can explain is a different matter: leave it in place and read how to check whether your site has been hacked.

  5. Step 5: Check where the site sends its mail

    Under Settings, on the General screen, "Administration Email Address" is where WordPress sends notices about updates, fatal errors and recovery mode. WordPress's documentation says outright that if a developer or agency set the site up, you should make sure it points to an address your organization can read. A new address becomes active only after you select the link in the confirmation email sent to it. Check the email address on your own user profile too.

  6. Step 6: List what is installed

    Record every plugin and theme with its version. The Plugins screen shows the same list. How to audit a WordPress site for security weaknesses turns that list into findings with dates.

    bash
    wp plugin list
    wp theme list

Move the outside accounts into your name

AccountHow it changes hands
The domainOnce it is in your account, put your organization's legal name in the Registrant Organization field and a role-based name in Registrant Name. ICANN describes that as good practice, and advises against listing a designer or host as registrant.
Paid plugins and themesFind out whose account at each vendor holds the license. Ask the vendor whether it can be moved to an account of yours. Otherwise buy your own and enter the new key.
Search ConsoleVerify ownership yourself. Then remove the previous owner and their verification tokens. Google lists leftover ones under "Unused ownership tokens", and warns that an owner whose token remains can verify again.
Google AnalyticsAsk any remaining administrator to add you. If there is none, Google has a recovery process: you prove you control the site by uploading an analytics.txt file to it, then submit a form.
The payment gatewayCheck whose legal name and bank account it is under. Stripe, for one, lets the owner transfer ownership. If the owner is gone, its support verifies your identity and your relationship with the business.

What you may not do

Do not sign in to an account that is not yours. That covers the developer's registrar login, their reseller panel, their mailbox, and any password of theirs you happen to know or could guess. It also covers paying someone to get in for you.

The line is whose account it is. Resetting a WordPress password in a database on hosting you hold is a documented recovery method. Doing the same through the developer's hosting login is not yours to do, even when the site is.

Where the two of you disagree about the domain, the design or what is still owed, the registrar's process and your contract decide it. Keep your requests in writing and keep the invoices.

When to get help

  • The domain is in the developer's name and the registrar has asked for documents you are not sure how to assemble. That is a question for a lawyer.
  • You have a copy of the site and nobody to move it.
  • You are in, and the site is broken, out of date or behaving oddly.

For the last one, our WordPress support works like this: you describe the problem, and we find the cause and fix it.

Common questions

Do I own my website if someone else built it?

There is no single answer, because the site is several things. The rights to the domain are held by whoever the registrar lists as registrant. The hosting is the account holder's. Who owns the design and the code depends on your contract with the developer, and that is a question for a lawyer.

The developer registered my domain in their own name. What can I do?

Ask them to approve a change of registrant, which needs confirmation from both of you. If they do not answer, ICANN says you may need to give the registrar proof that you paid the developer for the domain. The registrar decides, and ICANN does not step into ownership disputes.

Can I move the site without the developer's help?

Yes, if you have a full copy of the files and the database and you control the domain's DNS. Restore the copy on hosting in your own name, check it, then point the domain at the new host. ICANN notes that changing name servers does not require moving the domain to another registrar.

My domain ends in a country code. Do the same rules apply?

Not necessarily. ICANN's transfer rules are for generic domains such as .com. A country-code domain is administered by its own manager, which sets its own requirements. IANA's root zone database names the manager for each one.

What should I ask the next developer for?

Nothing that makes them the owner of record. The domain, the hosting, the licenses and the payment account stay in your organization's name, and the developer gets a login of their own on each. ICANN advises against listing a web designer or a hosting provider as the registrant of your domain.

More on this subject

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.