Product
Solutions
Compare
Resources
Get early access Talk to us
Clients

How to manage WordPress clients, from onboarding to offboarding

Managing WordPress clients well is one repeatable process: onboard each site properly, give everyone their own access, agree the scope in writing, run a fixed routine, report in plain language and hand everything back cleanly at the end. Once you look after more than a few sites, it helps to manage multiple WordPress sites from one dashboard, so none of it depends on memory.

The five stages of managing a WordPress client. Onboard with a discovery call, an inventory and a baseline; agree the plan, exclusions and response times; maintain weekly, monthly and with uptime alerts; report monthly and review yearly; offboard with a final backup, transfers and removed access
The five stages of managing a WordPress client, from the first call to a clean handover.

The short answer

To manage WordPress clients, run every client through the same process: learn the business, take stock of the site and its accounts, give each person their own login, agree the scope in writing, keep a weekly and monthly routine, report monthly in plain words and offboard cleanly. The process matters more than the tool, but past a handful of sites, one dashboard keeps it from slipping.

  1. Run a discovery call. Learn what the site does for the business, who decides and what counts as urgent.
  2. Take an inventory. Record the domain, hosting, plugins, licenses and every user account.
  3. Set up access properly. Give each person their own account at the lowest role that does the job.
  4. Record a baseline. Take a backup you have tested, and note security, speed and Site Health first.
  5. Agree the scope in writing. Cover the plan, exclusions, response times, change requests and price reviews.
  6. Run the routine. Review updates and backups weekly, and security, users and speed monthly.
  7. Report every month. Put outcomes first in plain words, with the technical detail underneath.
  8. Review the plan once a year. Check the work against the price before the renewal.
  9. Offboard cleanly. Hand over a final backup, the domain, hosting and licenses, then remove your access.

Each step is covered below, with tables you can copy.

What does managing WordPress clients involve?

Managing WordPress clients means looking after two things at once: the websites, and the people who pay you to look after them. The site work is updates, backups, security, uptime and speed. The client work is access, scope, communication, reports, billing and, one day, a handover.

Both halves need a process, because a site that runs perfectly can still cost you the client if the work is invisible or the scope is vague. This guide is for anyone who looks after WordPress sites for someone else.

How do you onboard a new WordPress client?

Onboard every client the same way: learn the business, map the site and its accounts, set up your access and record a baseline before you change anything.

1. Run a discovery call

Before you touch the site, ask:

  • What does the site do for the business? Leads, bookings, sales or information. That tells you which pages matter most.
  • Who decides? Who approves changes, who pays and who should hear about an outage.
  • What counts as urgent? A broken checkout is. A typo on the About page is not.
  • What is the history? What has broken before, and what was customized that an update could overwrite.
  • When must nothing change? Busy seasons, launches and campaigns are the wrong week for a big update.

2. Take an inventory of the site and its accounts

Write down everything the site depends on, and ask for your own logins as you go (the next section explains how). Most of it lives outside WordPress, which is why it breaks when nobody owns it.

WordPress client onboarding inventory
What to recordWhere to find itWhy it matters
Domain registrar, owner and renewal dateThe registrar accountA lapsed domain takes the site and its email down
DNS and email providerThe registrar or DNS hostA DNS change for the site can break email
Hosting plan, server access and PHP versionThe host control panelSets what you can update and who fixes the server
WordPress version, theme and pluginsTools > Site Health > Info, which can copy it all to your clipboardYour starting point for updates and security
Premium licenses and who owns themPlugin settings and vendor accountsMany premium plugins only update while the license is active
User accounts and rolesThe Users screenAccounts nobody uses are access nobody watches
BackupsThe backup plugin or the hostYou need one restore point you know works
Connected servicesAsk: analytics, Search Console, forms, payments, email deliveryThey lapse quietly when the person who set them up leaves

Collect this before your first change and keep it in a site record.

3. Take a baseline backup and run a health check

Take a full backup of files and database, store it away from the server and check that it restores. As WordPress's own upgrade guide says, "the first thing to do is to make a backup copy." Then note the critical issues under Tools > Site Health > Status, a security scan result, the speed of key pages and how many updates are waiting.

Share the findings in writing: anything you find in week one is the site's history, not your work. Findings like these also make a stronger pitch than a list of services, which is how our WordPress maintenance proposal template is laid out.

4. Document the stack

Turn the inventory into a one-page site record: each service and who owns it, renewal dates, where the logins live (never the passwords themselves), custom code and who to call for what. Keep it current, and the handover at the end becomes an afternoon instead of an investigation.

How do you give and remove access without sharing passwords?

Give every person their own account at the lowest role that does the job, and remove it the day they stop needing it.

WordPress has six default roles, which its documentation describes as defining "the user's responsibilities within the site" rather than a ladder of seniority. In practice, Administrator is for the people who maintain the site plus one account for the business owner, Editor is for the client's content lead, and Author or Contributor is for writers. Super Admin only exists on multisite networks.

Our guide to WordPress user roles covers each one in detail. Then keep to five rules:

  • One person, one account. A shared login hides who did what, and removing one person means changing the password for everyone.
  • The client keeps an Administrator account. It is their site, so your access sits beside theirs.
  • Use Application Passwords for tools. Since WordPress 5.6, apps that connect through the REST API can use one. It cannot sign in to wp-admin, and each one can be revoked on its own from the Edit User page.
  • Ask to be added, not given a login. In Google Search Console only owners can add users, so the client stays the owner and adds you. In Google Analytics, only Administrators can add or remove users.
  • Turn on two-step sign-in for every administrator, yours included, as WordPress's hardening guide recommends.

When someone leaves or a contract ends, delete or downgrade their WordPress accounts. WordPress asks what to do with a deleted user's posts, so choose Attribute all posts and links to another user rather than deleting the content.

Then revoke their Application Passwords, remove them from the host, registrar and Google services, and change any password that was ever shared. On thirty sites, that is an afternoon of signing in and out.

What should a WordPress client agreement cover?

Put the scope in writing before the first invoice: what the plan includes and excludes, how fast you respond, how extra work is priced, when the price is reviewed and how either side can leave. Most people sell this as two or three WordPress care plans. Whatever the tiers, write down these clauses:

What to put in a WordPress client agreement
ClauseWhat it settlesExample wording
Included workWhat the fee buys"Updates, daily backups, monitoring, a monthly report and up to one hour of small changes a month."
ExclusionsWhat is quoted separately"New features, redesigns and content writing are quoted separately."
Response timesHow fast you reply, not how fast it is fixed"We reply to urgent issues within 2 business hours and to other requests within 1 business day."
Change requestsHow clients ask"Send requests to one email address. We confirm whether each is included or quote it before starting."
Unused timeWhether hours carry over"Unused change time does not roll over."
Price reviewWhen the fee can change"Fees are reviewed once a year, with 30 days' notice."
Ending the planNotice and handover"Either side can end the plan with 30 days' notice. We hand over a final backup and remove our access."

Example wording only. Adapt it to your business and have your contract checked by a lawyer.

Two clauses need extra thought. Response is not resolution: you control how fast you reply, not how fast a host fixes a server.

And if the site collects form entries, orders or accounts for a client in the EU or UK, you are probably processing personal data on their behalf. Article 28 of the GDPR requires a contract for that, and the UK regulator, the ICO, says that "every time a controller uses a processor to process personal data, there must be a written contract". A short data processing agreement covers it.

The WordPress care plan template has a fuller clause list.

What should a weekly and monthly maintenance routine include?

Pick a fixed day each week for updates and backups and a fixed day each month for the deeper checks, then run the same list on every client site. A routine that depends on remembering is the first thing to slip in a busy week.

WordPress client maintenance routine
TaskHow oftenWhat good looks like
Review and apply plugin and theme updatesWeekly, security fixes soonerBackup first, key pages and forms checked after
Check that backups ran and are stored off the serverWeeklyA recent copy, away from the host
Watch uptime and the SSL certificateAll the time, with alertsAn alert reaches a person who acts on it
Test forms and the checkoutWeekly and after updatesA test message or order arrives
Scan for security issues and review administrator accountsMonthlyNo unknown administrators, no known holes
Check speed on key pagesMonthlyNo key page slower than last month
Restore a backup to a test siteEvery few monthsThe copy opens and works
Check renewal dates for domains, certificates and licensesMonthlyNothing expires by surprise

Our recommended baseline. Stores and sites that earn money every hour need tighter checks.

Plugins deserve the most attention. Patchstack's State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, and 91% of them were in plugins, against only 6 in WordPress core. Our guide to WordPress plugin management covers how to add, update and remove them safely.

WordPress installs minor core releases and translations in the background by default (new installs since WordPress 5.6 take major releases too), but plugins and themes update automatically only in special cases unless you switch auto-updates on. Our guide to WordPress core updates covers the big releases.

How should you communicate with WordPress clients?

Agree one channel for requests, say how fast you reply, and tell clients about problems before they find them. Most clients never see your maintenance work, but they always see how you behave when something goes wrong.

  • One channel. Requests go to one email address or form, not to your personal phone, a chat app and three colleagues. Keep the phone for real emergencies, and agree what counts as one.
  • Clear hours. Say when you work, in which time zone and what happens on holidays.
  • Reply fast, even when the fix takes longer. "Got it, I will look at it today" beats a perfect fix after two days of silence.
  • Warn before planned work, such as a major update or a theme change.

What to say during an outage

Send a short update before the client asks, and keep updating until it is fixed. Each update answers four questions: what happened, what is affected and what still works, what you are doing now, and when they will hear from you next.

For example: "Your site has been unreachable since 9:40. The host has confirmed a server fault and is fixing it. Your email is not affected. I will update you by 10:30, or sooner if it is back."

Afterwards, send three lines: the cause, what you did and what stops it happening again.

How do you report to clients so they actually read it?

Send a short monthly report that leads with outcomes in plain words and puts the technical detail underneath. Good maintenance is invisible, so the report is how the client sees what they pay for.

  • Open with a three-sentence summary: was the site up, was anything fixed or prevented, and is anything needed from the client.
  • Translate the work. "26 updates applied and checked, including 3 security fixes" means more than a list of version numbers.
  • Report the bad news too. An outage the client noticed and the report leaves out costs more trust than the outage did.
  • Compare with last month, and recommend one thing, such as a PHP upgrade or a faster host.
  • Send it on the same day every month.

Our free WordPress maintenance report template lays out a seven-section structure. To build reports from real data instead of by hand, see what to look for in WordPress client reporting software.

How do you handle client requests and scope creep?

Decide in advance which requests the plan includes, and say so every time one is not. Scope creep is rarely one big ask. It is a steady stream of small ones that each feel too small to quote.

How to handle WordPress client requests
Type of requestExampleWhat to do
IncludedSwap a photo, fix a typoDo it, and list it in the monthly report
Small extraA new form or landing page changeQuote a fixed price before you start
ProjectA redesign, a new feature or a shopSend a separate proposal with its own timeline
EmergencyThe site is down or hackedAct at once, under the emergency terms you agreed

Tell the client which row a request falls in before you start.

Say yes with a price ("Happy to. That one is outside the plan, so here is a fixed price before I start"), keep a running list of every request and how long it took, and if the same extra work keeps coming back, move the client to a bigger plan at the next review instead of absorbing it.

How should you handle billing, renewals and price reviews?

Bill maintenance in advance on a fixed day, let plans renew automatically with notice, and review every client's price once a year against what the site actually takes to look after.

  • Bill in advance, monthly or yearly, ideally by card or direct debit so nobody has to remember.
  • Agree what happens when an invoice is late, for example a reminder after 7 days and a pause on non-urgent work after 30. Keep monitoring and backups running while you chase it.
  • Review once a year. Compare the year's requests, incidents and time with the fee. The care plan calculator shows your real margin, and our guide on how much to charge for WordPress maintenance covers pricing models.
  • Raise prices with notice and a reason. Give at least the notice your agreement sets, ideally 90 days, and point to the work in the year's reports as well as to what has changed on your side.

How do you offboard a WordPress client cleanly?

Offboarding means handing over everything the client owns, in working order, then removing every way you had into their accounts. Confirm the end date and the handover list in writing first, then:

  1. Take a final full backup and give the client a copy. Tools > Export also creates an XML file of the content (posts, pages, comments, custom fields, categories, tags and users), but it is not a copy of the theme, plugins or files, so it does not replace the backup.
  2. Put the domain in the client's name. Ask the registrar to move it to an account the client controls, or have the client request the transfer code. Under ICANN's Transfer Policy, the registrar must provide that code within five calendar days, may refuse a transfer within 60 days of registration or of a previous transfer, and must lock transfers for 60 days after a change of registrant unless the owner opted out first. Start early.
  3. Move the hosting to the client's own account and payment method, and check that the site and email still work afterwards.
  4. Sort out licenses. Premium plugins and themes bought on your account either transfer, if the vendor allows it, or the client buys their own before you remove yours.
  5. Hand over Google services. Make the client the owner in Search Console and an Administrator in Analytics, then remove yourself. In Search Console, also delete your verification token, because Google notes that a removed owner whose token is still in place can verify ownership again.
  6. Remove your WordPress access: your accounts (attribute their posts to the client), your Application Passwords and any management or connector plugins you installed.
  7. Send the updated site record and confirm in writing that your access is gone.

When should you move from spreadsheets to a management platform?

Move when the routine no longer fits in your week, or when you cannot say in a minute who has access to which client site. A spreadsheet and a password manager are fine for a handful of sites. The signs you have outgrown them:

  • Clients notice downtime, broken forms or pending updates before you do.
  • Removing one contractor means signing in to every site.
  • Reports take longer to write than the work they describe.
  • Nobody can say which sites were updated this week.

Managing WordPress clients with WPCentrify

Disclosure: WPCentrify is our product. WPCentrify, a hosted WordPress management platform for anyone responsible for more than one WordPress site, brings the routine above into one dashboard for every client site.

We built it as a WordPress website management platform for exactly this work, and we use it ourselves: the account we work from manages 18 WordPress sites, and on 10 October 2026 it showed 11 updates waiting for review across them. That number is easy to miss when every site has its own wp-admin, and obvious on one screen.

  • One-click WordPress login. Everyone signs in to a client site as themselves, with the WordPress role you set per person, per site. Nobody on your team holds a client password, and when somebody leaves, one action ends their access everywhere at once.
  • WordPress team access management. Each person has their own login, with permissions set per area from viewing to acting. Team members are never charged for.
  • White label WordPress client reports, built from the record of what happened on each site and sent on a schedule you set for each client. White label branding is the one paid add-on; every core feature is included on every plan.
  • An activity log of every action on every site, in wp-admin and from WPCentrify, with the person and the time, so "who changed that?" has an answer.
  • Uptime monitoring every 60 seconds from 3 locations, Malaysia, Canada and the USA, with an email alert only when locations on different providers agree, after three failed checks in a row.

What it does not do: WPCentrify looks after the sites, not your contracts, invoices or inbox, so keep those in the tools you already use. It is free during early access, and prices are announced at launch.

Sources

All sources checked on 10 October 2026. This guide is general information, not legal advice.

Answers

Questions about managing WordPress clients

Run every client through the same process: onboard the site properly, give each person their own access, agree the scope in writing, keep a weekly and monthly maintenance routine, report monthly in plain language and offboard cleanly. Past a few sites, a management platform keeps that routine in one place.

Ask what the site does for the business, who approves changes and pays, what counts as urgent, what has broken before and when nothing should change. Then collect access to the domain, hosting, WordPress and Google accounts, and a list of premium licenses.

No. Give each person their own account at the lowest role that does the job, so the site's history shows who did what and you can remove one person without changing everyone's password. Tools can use Application Passwords, which can be revoked one at a time.

The client should keep at least one Administrator account, because it is their site. Staff who only manage content usually need Editor, and writers need Author or Contributor.

What the plan includes and excludes, response times, how change requests are made and priced, when prices are reviewed, the notice period and what you hand over at the end. If you process personal data for a client in the EU or UK, add a data processing agreement.

Review plugin and theme updates at least weekly and apply security fixes as soon as you can, with a backup first and a check of key pages after. WordPress installs minor core releases automatically by default, but plugins and themes only in special cases unless you switch auto-updates on.

Write down what the plan includes, quote anything outside it before you start, and list the included requests in the monthly report. If the same extra work keeps coming back, move the client to a bigger plan at the next review.

Give the client a final full backup and an updated site record, make sure the domain, hosting, Google accounts and premium licenses are in their name, then remove every account, Application Password and plugin you added. Confirm in writing that your access is gone.

Ask the registrar to move the domain into an account the client controls, or have the client request the transfer code, which ICANN's Transfer Policy says the registrar must provide within five calendar days. A registrar may refuse a transfer within 60 days of registration or of a previous transfer, so start early.

Yes, for most maintenance plans. A short report that leads with outcomes such as uptime, updates applied, backups and security fixes shows work that is otherwise invisible, and gives the renewal conversation something to stand on.

Use a management platform once the routine stops fitting in your week. WPCentrify, our own platform, puts every client site in one dashboard, with one-click login at a WordPress role you set per person and per site, uptime checks every 60 seconds from 3 locations and client reports. It is free during early access.

Early access

Look after every client site from one dashboard

Updates, backups, uptime, access and client reports for every WordPress site you manage, with email alerts only when something needs you.

Free during early access. No credit card required.