# My previous contractor has stopped answering

> When the person who built the site is no longer reachable, the first emergency is not technical: it is knowing what you actually own. A site can run perfectly for months while neither the domain, nor the hosting, nor the code is in your name. That is the point to establish first.

- Source canonique : [https://allaux.fr/en/problemes/prestataire-precedent-injoignable](https://allaux.fr/en/problemes/prestataire-precedent-injoignable)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Ask the host, as the account holder, to reopen the FTP or SSH access and the database credentials: it is the host, not the previous developer, who can hand them back. In parallel, check who owns the domain name in the Whois record. Then take a full copy, files and SQL dump, downloaded off the server, before touching anything.

## Establishing what you hold

1. **The domain name** — The most critical item and the most often wrongly held. The public domain registry shows the declared holder and the expiry date. A domain renewed by a third party who disappears is the costliest scenario.
2. **The hosting account** — Is it open in your name, or is your site lodged inside an agency account alongside other clients? In the second case you can neither reach the files nor request a backup without going through them.
3. **Administrator access to the site** — An account in your name, with full rights, not a shared login. Check which other accounts exist too: old access left active is a risk in itself.
4. **File and database access** — SFTP and the database. Without both, no complete backup is possible, and no serious diagnosis either.
5. **Third-party accounts** — Payment service, carriers, measurement tools, email sending service, any code repository. Each may be tied to an address you never read.

## Take a full backup before anything else

> Files and database, copied off the server, before even changing a password. Until that copy exists, every action is a gamble. It is the only step I consider genuinely urgent in this situation.

## What remains possible without the previous contractor

Far more than people expect. A live site holds all its code on the server: with file and database access you can read, understand, fix and extend, even with no documentation and no repository. What is genuinely missing is intent — why a change was made, which module was bought under which licence — and that can be reconstructed by reading.

Two situations do pose a real problem. A site built on a closed platform whose files are not accessible: recovery then depends on the exports the vendor offers. And a paid module or theme registered in the previous contractor’s name: it keeps working but will receive no more updates, which becomes a security issue in the medium term.

## Taking over properly, not in a rush

Change every password once the backup is done, including those that look unused.

Remove administrator accounts that match nobody identifiable today.

Inventory installed modules and plugins, with version and origin.

Check the CMS and PHP versions: a site left unattended is usually behind on both.

Document what was found, so the situation does not repeat at the next handover.

I work alone, which has a direct consequence here: you know who holds the access, and you can take it back at any time with no negotiation.

## Related pages

- **Passwords and shared access** — How to take back control of access without breaking what works. ([/securite/mots-de-passe-administration-acces-partages](/securite/mots-de-passe-administration-acces-partages))
- **Backing up before any work** — What a backup must contain to be genuinely usable. ([/guides/sauvegarder-boutique-avant-intervention](/guides/sauvegarder-boutique-avant-intervention))
- **Shop maintenance** — What regular upkeep covers, and what it does not. ([/services/maintenance](/services/maintenance))
- **Domain names** — If the domain is held by a third party, what can be done. ([/services/noms-de-domaine](/services/noms-de-domaine))

## FAQ

### My contractor refuses to hand over access. What can I do?

It depends on what your contract says and who holds each account. Technically, a site whose hosting you control remains workable without cooperation; a domain held by a third party requires a process with the registrar.

### Can I take over the site without the original source code?

Yes. The code being executed is on the server. A repository makes change tracking easier, but its absence blocks neither diagnosis nor further work.

### Does everything need rebuilding after a handover?

Rarely, and never as a reflex. I start with an inventory: many inherited sites are healthy and mainly need version and access housekeeping.

### How do I know whether access is still open to someone else?

By listing administrator accounts, third-party service keys and recent logins. An unknown account or a key you have never used deserves revoking.

### Could the site stop overnight?

Yes, if the domain or hosting is renewed by someone who has ceased trading. That is exactly why checking the holder comes before any technical consideration.
