First, do nothing destructive
Do not cancel hosting, change DNS or delete anything yet. The first goal is to find out what exists and who controls each piece, not to change it. The 30-minute account audit is the same mindset applied to every service, not only WordPress.
Step 1: Find out what you have
A WordPress site is four separate things, and they may each be controlled by a different party:
- The domain name (registrar account)
- The hosting (server or managed host)
- The files (WordPress core, theme, plugins, uploads)
- The database (pages, posts, settings, users, orders)
Check each one separately.
Domain: do a WHOIS lookup to see the registrar and the registrant. Look through your email for old registrar invoices or renewal notices. If the domain is registered under the agency's name, contact the registrar: most have a procedure for proving you are the legitimate business user, though it takes time and paperwork.
Hosting: look at your DNS records to see where the site points, and check your accounting for hosting invoices. Your card statements often show the provider's name even when you never had a login.
Admin access to WordPress: try the lost password function on /wp-login.php with every email address that might be registered. Old emails of staff, the agency's contact address and your generic contact address are worth trying.
Step 2: Get access, in order of ease
If you can log into the hosting account: you can reset the WordPress admin password from there. Most hosts offer a database tool (usually phpMyAdmin) where an administrator's password can be reset, or a one-click WordPress manager. Some hosts also have a built-in staging or backup feature that is useful right now.
If you cannot log in anywhere but the host is a known company: contact the host's support. Explain the situation, and be ready to prove that you are the business behind the domain and the invoices (company registration, ID, proof of payment). Hosts differ on how strict they are, and some will refuse without the account holder's consent.
If the host account belongs to the agency and they are unreachable: the practical route is often to rebuild a copy of the site on new hosting and switch the domain. For that, you need the files and the database. If you cannot get them, you can still recover a lot (see Step 3).
Step 3: When you cannot get the original files
You are not always starting from zero. Options, from best to worst:
- A backup you or someone else made at any point (plugin backups, host backups, a developer's export)
- The WordPress export tool (Tools → Export), if you can get any admin login: it saves pages, posts and media references
- A public copy of the site: the Internet Archive's Wayback Machine keeps copies of many pages. It is not a clean copy, but it preserves your text and structure, which is often the most valuable part
- Rebuilding on a fresh WordPress using your texts, images and structure, if the design is simple
A rebuild is sometimes the better answer even when you do have the files, especially if the old site relies on an outdated theme or plugins nobody maintains.
Stuck on hosting or backups?
We help map what exists, recover what is recoverable, and move the site to accounts you control.
Step 4: Audit what you recovered
Before you move anything, check:
- WordPress version and PHP version. Old versions are a security risk and may not run on modern hosting.
- The plugin list. For each plugin: is it free, paid, or custom? Is it still maintained?
- Licences. Premium plugins and themes are often licensed to the agency, not to you. Without a valid licence, you may lose updates and support, and in some cases features. Check the licence terms and ask the vendor how to transfer or repurchase.
- The theme. Is it a standard one, or a custom or child theme? A custom theme with no source code is much harder to maintain.
- Users. Delete accounts you do not recognise, after confirming who they belong to.
- Hidden extras. Look for code that sends data to third parties, backdoors in old sites, or analytics under accounts you do not own.
If the site has been neglected for years, treat it as possibly compromised and scan it for malware before restoring it anywhere.
Step 5: Move it under your control
- Create hosting in your company's name, with your billing details.
- Restore the site there (files + database) and test it on a temporary address.
- Fix what is broken (PHP version, plugins, URLs inside the database).
- Secure it: new admin accounts, strong passwords, two-factor authentication, updates, a backup plugin or host backups.
- Switch the domain's DNS to the new host once everything works. Run the new copy in parallel first, and cut DNS only after you have verified pages, forms and email. See switching hosting without downtime for TTL, email and rollback.
- Move the domain registration to a registrar account you own.
Step 6: Put the safeguards in place
- Admin accounts for you, with the developer as a separate limited user
- All premium licences registered to your company email
- Automatic backups stored somewhere other than the same server
- A short document listing hosting, domain, licences and who can do what. Start from the exit plan template and keep it updated.
Mistakes to avoid
- Changing DNS before the new site is ready
- Deleting the old hosting too early, which may be your only copy
- Paying for cracked premium plugins found online: they often contain malware
- Assuming the agency owes you nothing. Check your contract: it may state that you own the code and content, which gives you leverage if they reappear
Should you rebuild instead?
Consider a rebuild if: the site is more than five years old, the theme is heavily customised and undocumented, plugins are abandoned, or the design needs updating anyway. Consider a recovery if the site is functional, recent, and mostly needs a change of ownership.
Need a second pair of eyes?
Send what you know about domain, host and access. We will tell you the sensible next step.
D'abord, ne rien casser
Ne résiliez pas l'hébergement, ne touchez pas au DNS et ne supprimez rien pour l'instant. Le premier objectif est de savoir ce qui existe et qui contrôle chaque brique, pas de tout changer. L'audit de comptes en 30 minutes repose sur la même logique, pour tous les services, pas seulement WordPress.
Étape 1: Faire l'inventaire
Un site WordPress, ce sont quatre éléments distincts, parfois chez quatre interlocuteurs différents:
- Le nom de domaine (compte registrar)
- L'hébergement (serveur ou hébergeur managé)
- Les fichiers (cœur WordPress, thème, extensions, médias)
- La base de données (pages, articles, réglages, utilisateurs, commandes)
Vérifiez chaque brique séparément.
Domaine: faites un WHOIS pour voir le registrar et le titulaire. Fouillez vos emails (factures, renouvellements). Si le domaine est au nom de l'agence, contactez le registrar: la plupart ont une procédure pour prouver que vous êtes l'usage légitime de l'entreprise, avec délais et paperasse.
Hébergement: regardez les enregistrements DNS pour voir où pointe le site, et votre comptabilité pour les factures d'hébergement. Les relevés bancaires affichent souvent le nom du prestataire même sans accès au compte.
Accès admin WordPress: testez « mot de passe oublié » sur /wp-login.php avec toutes les adresses email plausibles: anciens collaborateurs, contact agence, adresse générique de l'entreprise.
Étape 2: Récupérer les accès, du plus simple au plus dur
Si vous avez l'hébergement: vous pouvez réinitialiser le mot de passe admin WordPress depuis le panneau. La plupart des hébergeurs proposent phpMyAdmin ou un gestionnaire WordPress en un clic. Certains ont aussi une sauvegarde ou un staging utile tout de suite.
Si vous n'avez aucun login mais l'hébergeur est identifiable: contactez le support. Expliquez la situation et préparez des preuves que vous êtes l'entreprise derrière le domaine et les factures (Kbis, pièce d'identité, preuve de paiement). Les règles varient, et certains refuseront sans accord du titulaire du compte.
Si le compte hébergeur est à l'agence et qu'elle est injoignable: la voie pratique est souvent de reconstruire une copie sur un nouvel hébergement puis basculer le domaine. Il vous faut fichiers et base. Sinon, voir l'étape 3.
Étape 3: Quand vous n'avez pas les fichiers d'origine
Vous n'êtes pas toujours à zéro. Du meilleur au pire:
- Une sauvegarde à un moment donné (extension, hébergeur, export d'un développeur)
- L'export WordPress (Outils → Exporter) si vous obtenez un accès admin: pages, articles et références médias
- Une copie publique via la Wayback Machine: ce n'est pas propre, mais le texte et la structure sont souvent la partie la plus précieuse
- Reconstruction sur un WordPress neuf avec vos textes, visuels et structure, si le design est simple
Reconstruire vaut parfois mieux même avec les fichiers, surtout si le thème ou les extensions ne sont plus maintenus.
Bloqué sur l'hébergement ou les sauvegardes ?
On cartographie l'existant, on récupère ce qui l'est, on bascule vers des comptes à votre nom.
Étape 4: Auditer ce que vous avez récupéré
Avant de déplacer quoi que ce soit, vérifiez:
- Versions WordPress et PHP. Un stack ancien est un risque sécurité et peut ne plus tourner chez un hébergeur récent.
- Liste des extensions. Gratuite, payante ou sur mesure ? Encore maintenue ?
- Licences. Thèmes et extensions premium sont souvent licenciés à l'agence. Sans licence valide, plus de mises à jour ni de support, parfois plus de fonctionnalités. Lisez les conditions et demandez à l'éditeur comment transférer ou racheter.
- Thème. Standard, enfant ou sur mesure sans sources ?
- Utilisateurs. Supprimez les comptes inconnus après avoir identifié à qui ils appartiennent.
- Extras cachés. Code qui envoie des données ailleurs, portes dérobées, analytics sous des comptes que vous ne possédez pas.
Si le site est abandonné depuis des années, considérez qu'il peut être compromis et scannez-le avant toute restauration.
Étape 5: Remettre sous votre contrôle
- Ouvrir un hébergement au nom de votre société, avec votre facturation.
- Restaurer fichiers + base, tester sur une URL temporaire.
- Corriger ce qui casse (PHP, extensions, URLs en base).
- Sécuriser: comptes admin neufs, mots de passe solides, double authentification, mises à jour, sauvegardes hors serveur.
- Basculer le DNS vers le nouvel hébergeur une fois tout validé. Faites tourner la copie en parallèle et ne coupez le DNS qu'après avoir vérifié pages, formulaires et email. Voir changer d'hébergeur sans interruption pour TTL, email et retour arrière.
- Transférer l'enregistrement du domaine vers un registrar que vous possédez.
Étape 6: Mettre les garde-fous
- Comptes admin pour vous, développeur en utilisateur limité séparé
- Licences premium enregistrées sur l'email de votre société
- Sauvegardes automatiques ailleurs que sur le même serveur
- Un court document: hébergement, domaine, licences, qui fait quoi. Partez du modèle de plan de sortie et mettez-le à jour.
Erreurs à éviter
- Changer le DNS avant que le nouveau site soit prêt
- Supprimer l'ancien hébergement trop tôt, parfois seule copie restante
- Acheter des extensions premium « crackées » en ligne: souvent infestées
- Penser que l'agence ne vous doit rien. Relisez le contrat: propriété du code et du contenu, ça peut servir de levier s'ils réapparaissent
Reconstruire plutôt que récupérer ?
Envisagez une reconstruction si: le site a plus de cinq ans, le thème est sur mesure sans doc, les extensions sont mortes, ou le design doit être refait. Envisagez la récupération si le site fonctionne, est récent, et surtout manque de propriété claire.
Besoin d'un regard extérieur ?
Envoyez ce que vous savez sur domaine, hébergeur et accès. On vous dira la prochaine étape raisonnable.