My previous contractor has stopped answering
When the person who built the site is no longer reachable, the first emergency is not technical: it is knowing what you actually own. A site can run perfectly for months while neither the domain, nor the hosting, nor the code is in your name. That is the point to establish first.
Establishing what you hold
-
The domain name
The most critical item and the most often wrongly held. The public domain registry shows the declared holder and the expiry date. A domain renewed by a third party who disappears is the costliest scenario.
-
The hosting account
Is it open in your name, or is your site lodged inside an agency account alongside other clients? In the second case you can neither reach the files nor request a backup without going through them.
-
Administrator access to the site
An account in your name, with full rights, not a shared login. Check which other accounts exist too: old access left active is a risk in itself.
-
File and database access
SFTP and the database. Without both, no complete backup is possible, and no serious diagnosis either.
-
Third-party accounts
Payment service, carriers, measurement tools, email sending service, any code repository. Each may be tied to an address you never read.
What remains possible without the previous contractor
Far more than people expect. A live site holds all its code on the server: with file and database access you can read, understand, fix and extend, even with no documentation and no repository. What is genuinely missing is intent — why a change was made, which module was bought under which licence — and that can be reconstructed by reading.
Two situations do pose a real problem. A site built on a closed platform whose files are not accessible: recovery then depends on the exports the vendor offers. And a paid module or theme registered in the previous contractor’s name: it keeps working but will receive no more updates, which becomes a security issue in the medium term.
Taking over properly, not in a rush
- Change every password once the backup is done, including those that look unused.
- Remove administrator accounts that match nobody identifiable today.
- Inventory installed modules and plugins, with version and origin.
- Check the CMS and PHP versions: a site left unattended is usually behind on both.
- Document what was found, so the situation does not repeat at the next handover.
I work alone, which has a direct consequence here: you know who holds the access, and you can take it back at any time with no negotiation.
Related pages
-
Passwords and shared access
How to take back control of access without breaking what works.
-
Backing up before any work
What a backup must contain to be genuinely usable.
-
Shop maintenance
What regular upkeep covers, and what it does not.
-
Domain names
If the domain is held by a third party, what can be done.
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.