AI Summary
So the keys to a WordPress site are changing hands. Maybe you just bought a site (congrats!), or maybe you’re the one handing yours off to a new owner.
Either way, I have good news. Transferring a WordPress site to a new owner is really just a checklist, and the same checklist works from both sides of the handoff. The outgoing owner uses it to prep a clean transfer, and the new owner uses it to make sure nothing slipped through the cracks.
I’ll walk you through the whole thing, from backups and logins to licenses, forms, and SEO. None of these steps take long on their own, but skipping one can cost you a weekend of cleanup later.
How to Transfer a WordPress Site to a New Owner
Here’s the full transfer checklist, in the order I’d actually do it. If you’re taking over an existing WordPress website rather than handing one off, everything still applies. You’re just the person receiving each item instead of sending it.
In This Article
- 1. Make a Full Backup Before You Change Anything
- 2. Collect All Logins, Access, and License Keys
- 3. Transfer the Domain to Your Web Host (Optional)
- 4. Change All Passwords
- 5. Change the Admin Email Address
- 6. Transfer Plugin and Theme Licenses
- 7. Audit the Site’s Web Forms
- 8. Review Site SEO and Search Tool Access
- 9. Review User Roles and Activity
- 10. Run a Security Checkup
- 11. Plan a Full Site Audit
1. Make a Full Backup Before You Change Anything
Before a single password changes or a single DNS record moves, back up the entire site. Files and database, not just the content export.
Why first? Because a site handover involves a lot of people clicking around in settings they don’t normally touch. If something breaks mid-transfer (or an account gets locked), a fresh backup means you can restore the site instead of rebuilding it.
You have a couple of easy options here. Most hosts include one-click backups you can trigger from your hosting dashboard. If you want a backup that lives outside the hosting account entirely, a migration plugin like Duplicator packages the whole site into a single archive you can store anywhere and restore on any host.
If you’re the new owner, ask the previous owner for a copy of this backup. It doubles as your “day zero” snapshot of exactly what you received.
2. Collect All Logins, Access, and License Keys
Next, you need complete access to every service that keeps the website running. This includes:
- WordPress admin: You need an administrator-level account on the site’s WordPress dashboard. Without it, you can’t change anything on your new site.
- Hosting account: You’ll need access to the site’s web hosting, including cPanel and FTP. These are necessary for managing server files and domain-level settings like DNS records.
- Domain registrar: For most websites, the domain registrar and web hosting provider are one and the same. But if the site you’re taking over uses a separate registrar, make sure you have access to it.
- CDN: Many websites use a CDN (Content Delivery Network) to speed up the site for visitors around the world. If the site uses one, get the login.
- Email accounts: You’ll need access to any email accounts connected to the website. These handle password recovery, authentication, and other administrative messages, so the transfer stalls fast without them.
- Premium plugin and theme licenses: Ask for the license keys and the accounts they belong to. We’ll deal with actually moving these in step 6, but collect them now while the previous owner is still answering messages quickly.
- Google Search Console and Analytics: Confirm which Google account owns the site’s Search Console property and Analytics data. You’ll transfer these in step 8.
If the previous site owner uses a password manager, they can share every login in minutes without any hassle. I’d recommend setting one up for the new site too. It makes sharing credentials with your team painless, and you’ll never have passwords floating around in a spreadsheet somewhere.
3. Transfer the Domain to Your Web Host (Optional)
If you’re running multiple websites, you may want all of them connected to the same web hosting service. It’s a lot easier to manage your sites when their domain registration and web hosting live in the same account.
Besides, the previous owner may not want to share their hosting account if they still manage other sites with it.
In these scenarios, you’ll need to transfer the domain you’re acquiring to your own web host.
We recommend Bluehost because it provides the most affordable pricing for high-quality hosting services.


You can easily transfer a domain to your Bluehost account. Here’s how:
Update Registrant Contact Information
Before initiating the transfer, make sure the contact information on the domain record is up to date. You may have to contact the registrar to update details like your name, email address, and organization.
Change Nameservers to Bluehost
The nameserver settings at your domain registrar should point to Bluehost for a successful domain transfer. To change the nameservers, open your domain registration account and look for the DNS settings. This should have a section for Name Servers.
Bluehost’s nameservers are:
- ns1.Bluehost.com
- ns2.Bluehost.com
It may take up to 72 hours for the nameserver settings to update, so don’t panic if the change isn’t instant.
Get the EPP Code
The EPP code is an authorization code that’s unique to each domain. You’ll need this code to authorize the transfer request. The domain registrar provides the EPP code, so contact their support if you can’t find it in your account.
Transfer the Domain
You’re now ready to initiate the domain transfer to your Bluehost account. Log in to your Bluehost dashboard and select Domains » Transfer from the left-hand navigation bar.
On this page, enter the domain name that you want to transfer and click on Continue.


Then, enter the EPP code that you obtained in the previous step and press Continue.


You’ll now receive a verification code at the admin email address connected to the domain being transferred. Enter the verification code and click on Continue.
You can now select your domain renewal preference, change domain privacy settings, and update nameservers if needed.
Proceed to pay for the domain renewal to initiate the transfer process.
Good job! Your new website’s hosting and domain registration settings are now accessible from your main Bluehost account.
4. Change All Passwords
Now that you have all the accounts and the domain is connected to your hosting, change the password on every single account you collected in step 2.
This one is non-negotiable from a security standpoint. You don’t want anyone outside your team keeping access to the site’s WordPress backend, hosting, or branded email accounts, even accidentally.
While you’re in there, turn on two-factor authentication for the hosting account and any WordPress admin users that support it. A handover is the perfect moment to do this since you’re already logged into everything.
And once again, a password manager makes this step much faster. It also lets you securely share the new passwords with your team without saving them in plain text where anyone can see them.
5. Change the Admin Email Address
As the new owner, the WordPress admin email address should be connected to your email account.
To replace the admin email, go to Settings » General. Then, enter your current email address in the Administration Email Address field.


Scroll down to the bottom of the page and select Save Changes. You’ll receive an email from WordPress to authorize the email change. Open your inbox and click the link inside to confirm it.
Now, WordPress will send all administrative emails to your address. The exception is emails from plugins that use their own email settings, which we’ll handle in step 7.
6. Transfer Plugin and Theme Licenses
Premium plugins and themes are licensed to the previous owner’s account, and those licenses don’t move just because the site did. It’s also the step that gets skipped in almost every handover.
If licenses stay in the previous owner’s name, you’ll lose updates and support the moment they expire (or the moment the old owner deletes their account). Outdated premium plugins are one of the most common ways WordPress sites get hacked, so this matters more than it seems.
For each premium plugin and theme on the site, you have two options:
- Take over the account: For products the previous owner bought only for this site, the simplest fix is updating the email address on their account so it becomes yours.
- Move to your own license: If the previous owner uses the same license across other sites they’re keeping, buy your own license and swap the key on your new site.
The swap is usually quick. If the site runs WPForms, for example, this guide on how to transfer your WPForms license to another domain shows how to release a license from one site and activate it on another in just a few clicks.
Make a simple list of every premium product, who owns its license, and when it renews. Future you will be grateful at renewal time.
7. Audit the Site’s Web Forms
The WordPress site you’re taking over almost certainly has forms on different pages and widgets. You need to audit each form to make sure it works as intended and sends submissions to the right person (that’s you now, not the previous owner).
To perform an audit, you first need to know exactly which pages have a form. Scouring the site manually is needlessly time-consuming.
If the forms on the site were built using WPForms, you can use the form locator feature to find all the pages using a form. Our guide on how to find all pages with forms on your site walks through it.
You can also import forms built with other plugins (Contact Form 7, Ninja Forms, and Private Forms) into WPForms, then use the form locator to discover every page with a form on your site.
So if your new website doesn’t already have WPForms, one of the first things I’d do after the takeover is install WPForms. You’ll also get access to 2,100+ form templates, which helps when you start adding new forms of your own.


WPForms’ form locator counts the number of pages each form appears on and shows you the specific locations for every form.


When you’ve discovered where your forms live, you can launch the audit itself. This form testing checklist may help.
After checking each form for functionality, make sure the notifications point to the correct email address.
Change Form Notifications
WPForms gives you a lot of flexibility with form email notifications. You can change the notification recipients, email subject line, body text, and more.
To edit the notifications for any form, first navigate to WPForms » All Forms.


Now, hover your mouse over the form whose notifications you want to edit. Then, click on Edit.


This opens the form builder, where you can do all the editing. Click on Settings » Notifications on the left.
Notifications should already be enabled by default, but if they’re not, click the toggle next to Enable Notifications.


Here, make sure the Send To Email Address is set to your email address and not the previous owner’s.
If it uses the {admin_email} smart tag, notifications automatically go to the current admin email address (as long as you replaced the previous admin’s email with your own back in step 5).
You can also customize other sender details using the settings on this page.


If you’d like to set up a separate notification for your users, press the Add New Notification button in the top-right corner.


Now, you can use the same settings as above to create a notification that goes out to the people who fill out your form. For more details, see our doc on setting up form notifications.
Check That SMTP Email Is Configured
Problems with form notifications and other WordPress emails are fairly common. In most cases, they happen because the site isn’t configured to use SMTP for outgoing email.
In plain terms, SMTP is an email protocol that helps your messages get past spam filters and actually reach the inbox. Setting it up is easy with a plugin built for exactly this purpose, WP Mail SMTP.


WP Mail SMTP connects with popular SMTP email service providers like SendLayer, Brevo (formerly Sendinblue), and SparkPost. You can read this article on how to fix WordPress emails to learn more about using SMTP on your site.
One WP Mail SMTP feature that’s especially handy during a takeover audit is the email override.
Rather than checking every individual plugin to confirm its notifications use the correct from email, you can use WP Mail SMTP to override the From Email across the whole site.
After setting up WP Mail SMTP, go to WP Mail SMTP » Settings from your WordPress dashboard. Then, scroll down to the From Email setting and click the Force From Email checkbox.


Click the Save Settings button at the bottom of the page, and every plugin on your site now sends from the same address. It’s an easy way to make sure no plugin is still using the former admin’s email.
8. Review Site SEO and Search Tool Access
Every website deserves an SEO audit from time to time. But when you’re taking over a WordPress site, it’s especially important to review how well the site is optimized for search, since you’re inheriting every SEO decision the previous owner made.
The easy way to review the SEO status of your site is with a plugin called All in One SEO, or AIOSEO for short.


AIOSEO has a super handy SEO analysis tool that automatically performs an SEO check on your site. The results are summarized in a simple, actionable report.
On your dashboard, AIOSEO displays an SEO site score, which is a good way to measure how well your website’s homepage is optimized.


It’s recommended to aim for a score above 70 for the best results. But how do you know which changes will improve the score?
Well, right below the SEO Site Score, AIOSEO displays a list of issues on your site that you can fix to raise it.


And that’s not all. AIOSEO also has an awesome link assistant tool that analyzes links across your whole site. The link assistant makes it easy to find posts with no links yet (orphaned posts) and discover new linking opportunities.


Internal linking is an often ignored but hugely valuable part of SEO, and it can directly impact your rankings. With AIOSEO, you can quickly set your newly acquired site up for SEO success.
To learn more about AIOSEO and its capabilities, see our detailed AIOSEO review.
While you’re thinking about SEO, transfer the site’s search tools too. In Google Search Console, go to Settings » Users and permissions and add the new owner’s Google account as an owner. In Google Analytics, head to Admin » Account access management and do the same. Once the new owner confirms access, remove the previous owner’s accounts from both. Losing years of Search Console history because it lived in someone else’s Google account is a painful (and surprisingly common) takeover mistake.
9. Review User Roles and Activity
I strongly recommend reviewing the user roles on your new site. Only people on your team and connected to your project should have access to your WordPress backend (unless you deliberately want others in there too).
This is also a good opportunity to change the role of the previous site administrator or remove them entirely. To do that, click Users » All Users to see the list of all currently active users.
Then, hover your mouse over the user you want to delete or change. Use the Edit button to change their role or the Delete button to remove their account from the WordPress site.


If you simply want to change a user’s role and permissions, click on Edit. This takes you to a new screen. Scroll down to find the Role option and use the dropdown to select a role.


Press Save Changes at the bottom of the page to complete the role reassignment.
You may also want to review the activity logs of users on your site. There are various WordPress activity log plugins that let you track how users interact with your website.
Some plugins like WP Activity Log monitor all users with access to your WordPress backend and notify you if anyone changes your core WordPress files, plugins, themes, user profiles, or other settings.
By reviewing activity logs, you can make sure users on your site aren’t tampering with settings or changing parts of the site they shouldn’t touch.
10. Run a Security Checkup
You’ve changed the passwords and cleaned up user accounts, but you’re still trusting every security decision the previous owner made. A quick checkup tells you whether that trust is deserved.
Start with a free external scan like Sucuri SiteCheck. It checks the site for known malware, spam injections, and blocklist status in about a minute, no installation required.
Then take an honest look at the plugin list. Deactivate and delete anything the site isn’t actually using, and check when each remaining plugin was last updated. A plugin that hasn’t seen an update in over a year is a liability, so look for a maintained replacement.
Finally, consider adding a dedicated security plugin to handle monitoring going forward. Our roundup of the best WordPress security plugins compares the options, including several with solid free versions.
11. Plan a Full Site Audit
Finally, plan a complete audit to check the overall functionality and design of your site. This means testing menu items, CTA buttons, links, site performance, and other details a transfer can quietly break. Our guide on how to audit your WordPress site gives you a full checklist to work from.
You may want to delegate different audit tasks to your team to speed up the process and minimize human error.
Don’t forget to check your site’s functionality and appearance on desktop as well as mobile devices. The site may look completely fine on a desktop but have broken components on a mobile screen.
And that’s it! Whether you handed off the site or received it, the transfer is officially done, and the new owner can start growing the site from a clean foundation.
FAQs About Transferring a WordPress Site to a New Owner
Transferring ownership of a WordPress site raises the same questions for almost everyone. Here are quick answers to the ones I hear most often.
How long does it take to transfer a WordPress site to a new owner?
The site itself can change hands in an afternoon, since passwords, emails, and user roles only take minutes each. The domain is the slow part. Nameserver changes can take up to 72 hours, and a full registrar transfer can take several days to complete.
Do I have to move the site to a new host?
No. If the new owner is happy with the current host, you can transfer ownership of the hosting account itself, usually by updating the account’s name, email, and billing details. Moving the domain (step 3) is only necessary when the two parties want their accounts fully separated.
Is transferring a WordPress.com site different?
Yes. WordPress.com has a built-in ownership transfer tool that moves the site between accounts, so you don’t manage hosting or databases yourself. The checklist in this guide is written for self-hosted WordPress sites, where the pieces move separately.
What does it cost to transfer a WordPress site?
Often nothing beyond what you already pay. A domain registrar transfer typically includes a one-year renewal fee for the domain, and you may need to buy your own licenses for premium plugins or themes the previous owner keeps. There’s no fee for changing passwords, emails, or user roles.
Next, Keep Your New Site Running Smoothly
Now that the handover is complete, the real work is keeping the site healthy month after month. Our checklist of monthly WordPress maintenance tasks covers the routine that prevents small issues from becoming emergencies.
And since you’ll be making plenty of changes as you put your own stamp on the site, check out our post on undoing changes in WordPress for easy ways to fix common WordPress mistakes.
Create Your WordPress Form Now
Ready to build your form? Get started today with the easiest WordPress form builder plugin. WPForms Pro includes lots of free templates and offers a 14-day money-back guarantee.
If this article helped you out, please follow us on Facebook and Twitter for more free WordPress tutorials and guides.


