The Handover That Came With Zero Logins

Open empty wall lockbox on a brick wall by a shop door — metaphor for a site handover with no logins.

A new client emails me on a Tuesday. Their WooCommerce shop is live, orders are coming in, and the previous developer has gone quiet. Can I take over?

I say yes — then I ask for logins.

What arrives is a Google Doc with three bullet points and a lot of hope. WordPress admin: maybe. Hosting: “ask support?” Payment gateway: “the accountant might have that.” Domain: an email address nobody recognises, on a free mailbox that bounced last month.

Zero useful logins. A live till. And a client who just wants someone to “get in and fix things.”

I’ve seen this handover enough times that I no longer treat it as a surprise. I treat it as the real first job.

What usually went wrong before I arrived

Nobody meant to leave a mess. Credentials lived in one person’s head, or in a Slack DM that got archived, or in a 1Password vault nobody else was invited to. The previous developer used their personal email for the Stripe account. The domain was registered years ago with a forgotten Yahoo address. Hosting was set up under a company that no longer exists on Companies House in the same form.

Meanwhile the shop kept selling. Until something broke — a failed payment, a DNS hiccup, a plugin update — and suddenly “who owns this?” became an emergency, not a spreadsheet task.

That is the handover that comes with zero logins: the store works until it doesn’t, and then nobody can prove they own the keys.

What I ask for before day-one work

I don’t start changing checkout, themes, or plugins until we have a minimum access pack. I put it in writing so the client knows I’m not stalling — I’m protecting their orders.

Before I touch production, I want:

  • WordPress admin (or a clear path to reset it via hosting)
  • Hosting / cPanel / managed WordPress dashboard login
  • Domain registrar login (or WHOIS contact we can prove ownership of)
  • Payment gateway accounts (Stripe, PayPal, Klarna — whatever takes money)
  • Email / Google Workspace or Microsoft 365 for the shop addresses
  • Any CDN, DNS, or email deliverability tools in the path (Cloudflare, SMTP plugins, etc.)

I also ask who pays the invoices for hosting and domains. Billing emails are often the only reliable trail when passwords are gone.

If half of that list is missing, day one is recovery — not feature work. I quote that honestly. Clients who hear it early rarely argue later when the Stripe dashboard finally unlocks.

How I recover access without guessing passwords

I never “try a few passwords.” That wastes time and can lock accounts. Recovery is boring paperwork and official channels.

Hosting. We use the account-recovery flow with the host: proof of domain ownership, company letterhead, passport or directors ID if they ask, last four digits of the card on file. Most reputable UK hosts will move the account once ownership is clear. I sit with the client on that call if it helps.

WordPress. Once hosting is ours, I reset admin from the database or the host’s WP tools — then force a password change and remove unknown administrator users. I take a backup first.

Domain. Registrar recovery is slower. We prove the business owns the brand, chase the old email via WHOIS history if needed, and escalate support tickets with documentation. Until DNS is under our control, I treat every other fix as temporary.

Payments. Stripe and PayPal care about legal entity and bank details, not “the old developer’s Gmail.” We open support cases from the business, update owners, rotate API keys, and only then reconnect WooCommerce. I never paste old keys from a screenshot into a live site “just to get orders flowing.”

Email. If the mailbox that owns everything is gone, we rebuild from the domain up: MX records, new admin mailbox, then reclaim third-party accounts that used the dead address. This is often the longest thread.

Throughout, I keep a simple status note for the client: what we have, what we’re waiting on, what still blocks checkout changes. No mystery. No “I’ll just hack something overnight.”

How I document credentials for the next person

Once access is restored, the job isn’t finished until the next developer — or the client’s future self — isn’t starting from zero again.

I put every login into a shared password manager the client owns (not my personal vault). Roles matter: the client is the owner; I get access they can revoke. I label entries clearly — host, registrar, Stripe live, Stripe test, SMTP, analytics — and I note where 2FA lives (whose phone, which authenticator).

I also leave a one-page handover sheet in their Drive or Notion: stack summary, who bills what, renewal dates for domain and hosting, and “if X breaks, check Y first.” It takes an hour. It saves a week the next time someone leaves.

And I rotate anything that lived in the previous developer’s personal accounts. Shared logins that can’t be rotated are a debt. We pay that debt while the relationship is calm, not during a Black Friday outage.

Wrap Up

A live WooCommerce shop with missing logins isn’t a quick “jump in and tweak.” It’s a custody problem: who can prove they own the host, the domain, the payment keys, and the mailboxes?

Ask for the access pack before day-one work. Recover through official channels, not guesswork. Document everything in a vault the client controls.

If you’re about to change developers — or you already did and the passwords vanished with them — sort the keys before you sort the features.

Need a hand?

If you need a WooCommerce developer who will secure the handover properly before touching checkout, hire me — fixed-price quote, no obligation.

Written by Connie, an AI, from Neil Matthews’ notes, archive, and direction. Neil directed and edited this piece and chose to publish it. He did not write these words. Augmented publishing by Neil Matthews.

Get A No Obligation Quote

Do You Need Help With Your WooCommerce Site?

Click through to the next page and complete the form to get a free no obligation quote to fix any issue you are having with your WooCommerce site.