Articles · WordPress

2026-10-23 12 min EN / FR

Taking back a WordPress site from an agency that vanished

The agency stopped answering emails, or it closed, or the freelancer who built the site is gone. The site still runs, for now, but you cannot log in, update it or move it. This is fixable in most cases. The order of operations matters, because the wrong first move can take the site offline.

First, do nothing destructive

Do not cancel hosting, change DNS or delete anything yet. The first goal is to find out what exists and who controls each piece, not to change it. The 30-minute account audit is the same mindset applied to every service, not only WordPress.

Step 1: Find out what you have

A WordPress site is four separate things, and they may each be controlled by a different party:

  • The domain name (registrar account)
  • The hosting (server or managed host)
  • The files (WordPress core, theme, plugins, uploads)
  • The database (pages, posts, settings, users, orders)

Check each one separately.

Domain: do a WHOIS lookup to see the registrar and the registrant. Look through your email for old registrar invoices or renewal notices. If the domain is registered under the agency's name, contact the registrar: most have a procedure for proving you are the legitimate business user, though it takes time and paperwork.

Hosting: look at your DNS records to see where the site points, and check your accounting for hosting invoices. Your card statements often show the provider's name even when you never had a login.

Admin access to WordPress: try the lost password function on /wp-login.php with every email address that might be registered. Old emails of staff, the agency's contact address and your generic contact address are worth trying.

Step 2: Get access, in order of ease

If you can log into the hosting account: you can reset the WordPress admin password from there. Most hosts offer a database tool (usually phpMyAdmin) where an administrator's password can be reset, or a one-click WordPress manager. Some hosts also have a built-in staging or backup feature that is useful right now.

If you cannot log in anywhere but the host is a known company: contact the host's support. Explain the situation, and be ready to prove that you are the business behind the domain and the invoices (company registration, ID, proof of payment). Hosts differ on how strict they are, and some will refuse without the account holder's consent.

If the host account belongs to the agency and they are unreachable: the practical route is often to rebuild a copy of the site on new hosting and switch the domain. For that, you need the files and the database. If you cannot get them, you can still recover a lot (see Step 3).

Step 3: When you cannot get the original files

You are not always starting from zero. Options, from best to worst:

  1. A backup you or someone else made at any point (plugin backups, host backups, a developer's export)
  2. The WordPress export tool (Tools → Export), if you can get any admin login: it saves pages, posts and media references
  3. A public copy of the site: the Internet Archive's Wayback Machine keeps copies of many pages. It is not a clean copy, but it preserves your text and structure, which is often the most valuable part
  4. Rebuilding on a fresh WordPress using your texts, images and structure, if the design is simple

A rebuild is sometimes the better answer even when you do have the files, especially if the old site relies on an outdated theme or plugins nobody maintains.

Stuck on hosting or backups?

We help map what exists, recover what is recoverable, and move the site to accounts you control.

Step 4: Audit what you recovered

Before you move anything, check:

  • WordPress version and PHP version. Old versions are a security risk and may not run on modern hosting.
  • The plugin list. For each plugin: is it free, paid, or custom? Is it still maintained?
  • Licences. Premium plugins and themes are often licensed to the agency, not to you. Without a valid licence, you may lose updates and support, and in some cases features. Check the licence terms and ask the vendor how to transfer or repurchase.
  • The theme. Is it a standard one, or a custom or child theme? A custom theme with no source code is much harder to maintain.
  • Users. Delete accounts you do not recognise, after confirming who they belong to.
  • Hidden extras. Look for code that sends data to third parties, backdoors in old sites, or analytics under accounts you do not own.

If the site has been neglected for years, treat it as possibly compromised and scan it for malware before restoring it anywhere.

Step 5: Move it under your control

  1. Create hosting in your company's name, with your billing details.
  2. Restore the site there (files + database) and test it on a temporary address.
  3. Fix what is broken (PHP version, plugins, URLs inside the database).
  4. Secure it: new admin accounts, strong passwords, two-factor authentication, updates, a backup plugin or host backups.
  5. Switch the domain's DNS to the new host once everything works. Run the new copy in parallel first, and cut DNS only after you have verified pages, forms and email. See switching hosting without downtime for TTL, email and rollback.
  6. Move the domain registration to a registrar account you own.

Step 6: Put the safeguards in place

  • Admin accounts for you, with the developer as a separate limited user
  • All premium licences registered to your company email
  • Automatic backups stored somewhere other than the same server
  • A short document listing hosting, domain, licences and who can do what. Start from the exit plan template and keep it updated.

Mistakes to avoid

  • Changing DNS before the new site is ready
  • Deleting the old hosting too early, which may be your only copy
  • Paying for cracked premium plugins found online: they often contain malware
  • Assuming the agency owes you nothing. Check your contract: it may state that you own the code and content, which gives you leverage if they reappear

Should you rebuild instead?

Consider a rebuild if: the site is more than five years old, the theme is heavily customised and undocumented, plugins are abandoned, or the design needs updating anyway. Consider a recovery if the site is functional, recent, and mostly needs a change of ownership.

Related

Need a second pair of eyes?

Send what you know about domain, host and access. We will tell you the sensible next step.