How to manage WordPress clients, from onboarding to offboarding
Managing WordPress clients well is one repeatable process: onboard each site properly, give everyone their own access, agree the scope in writing, run a fixed routine, report in plain language and hand everything back cleanly at the end. Once you look after more than a few sites, it helps to manage multiple WordPress sites from one dashboard, so none of it depends on memory.

The short answer
To manage WordPress clients, run every client through the same process: learn the business, take stock of the site and its accounts, give each person their own login, agree the scope in writing, keep a weekly and monthly routine, report monthly in plain words and offboard cleanly. The process matters more than the tool, but past a handful of sites, one dashboard keeps it from slipping.
- Run a discovery call. Learn what the site does for the business, who decides and what counts as urgent.
- Take an inventory. Record the domain, hosting, plugins, licenses and every user account.
- Set up access properly. Give each person their own account at the lowest role that does the job.
- Record a baseline. Take a backup you have tested, and note security, speed and Site Health first.
- Agree the scope in writing. Cover the plan, exclusions, response times, change requests and price reviews.
- Run the routine. Review updates and backups weekly, and security, users and speed monthly.
- Report every month. Put outcomes first in plain words, with the technical detail underneath.
- Review the plan once a year. Check the work against the price before the renewal.
- Offboard cleanly. Hand over a final backup, the domain, hosting and licenses, then remove your access.
Each step is covered below, with tables you can copy.
What does managing WordPress clients involve?
Managing WordPress clients means looking after two things at once: the websites, and the people who pay you to look after them. The site work is updates, backups, security, uptime and speed. The client work is access, scope, communication, reports, billing and, one day, a handover.
Both halves need a process, because a site that runs perfectly can still cost you the client if the work is invisible or the scope is vague. This guide is for anyone who looks after WordPress sites for someone else.
How do you onboard a new WordPress client?
Onboard every client the same way: learn the business, map the site and its accounts, set up your access and record a baseline before you change anything.
1. Run a discovery call
Before you touch the site, ask:
- What does the site do for the business? Leads, bookings, sales or information. That tells you which pages matter most.
- Who decides? Who approves changes, who pays and who should hear about an outage.
- What counts as urgent? A broken checkout is. A typo on the About page is not.
- What is the history? What has broken before, and what was customized that an update could overwrite.
- When must nothing change? Busy seasons, launches and campaigns are the wrong week for a big update.
2. Take an inventory of the site and its accounts
Write down everything the site depends on, and ask for your own logins as you go (the next section explains how). Most of it lives outside WordPress, which is why it breaks when nobody owns it.
| What to record | Where to find it | Why it matters |
|---|---|---|
| Domain registrar, owner and renewal date | The registrar account | A lapsed domain takes the site and its email down |
| DNS and email provider | The registrar or DNS host | A DNS change for the site can break email |
| Hosting plan, server access and PHP version | The host control panel | Sets what you can update and who fixes the server |
| WordPress version, theme and plugins | Tools > Site Health > Info, which can copy it all to your clipboard | Your starting point for updates and security |
| Premium licenses and who owns them | Plugin settings and vendor accounts | Many premium plugins only update while the license is active |
| User accounts and roles | The Users screen | Accounts nobody uses are access nobody watches |
| Backups | The backup plugin or the host | You need one restore point you know works |
| Connected services | Ask: analytics, Search Console, forms, payments, email delivery | They lapse quietly when the person who set them up leaves |
Collect this before your first change and keep it in a site record.
3. Take a baseline backup and run a health check
Take a full backup of files and database, store it away from the server and check that it restores. As WordPress's own upgrade guide says, "the first thing to do is to make a backup copy." Then note the critical issues under Tools > Site Health > Status, a security scan result, the speed of key pages and how many updates are waiting.
Share the findings in writing: anything you find in week one is the site's history, not your work. Findings like these also make a stronger pitch than a list of services, which is how our WordPress maintenance proposal template is laid out.
4. Document the stack
Turn the inventory into a one-page site record: each service and who owns it, renewal dates, where the logins live (never the passwords themselves), custom code and who to call for what. Keep it current, and the handover at the end becomes an afternoon instead of an investigation.
How do you give and remove access without sharing passwords?
Give every person their own account at the lowest role that does the job, and remove it the day they stop needing it.
WordPress has six default roles, which its documentation describes as defining "the user's responsibilities within the site" rather than a ladder of seniority. In practice, Administrator is for the people who maintain the site plus one account for the business owner, Editor is for the client's content lead, and Author or Contributor is for writers. Super Admin only exists on multisite networks.
Our guide to WordPress user roles covers each one in detail. Then keep to five rules:
- One person, one account. A shared login hides who did what, and removing one person means changing the password for everyone.
- The client keeps an Administrator account. It is their site, so your access sits beside theirs.
- Use Application Passwords for tools. Since WordPress 5.6, apps that connect through the REST API can use one. It cannot sign in to wp-admin, and each one can be revoked on its own from the Edit User page.
- Ask to be added, not given a login. In Google Search Console only owners can add users, so the client stays the owner and adds you. In Google Analytics, only Administrators can add or remove users.
- Turn on two-step sign-in for every administrator, yours included, as WordPress's hardening guide recommends.
When someone leaves or a contract ends, delete or downgrade their WordPress accounts. WordPress asks what to do with a deleted user's posts, so choose Attribute all posts and links to another user rather than deleting the content.
Then revoke their Application Passwords, remove them from the host, registrar and Google services, and change any password that was ever shared. On thirty sites, that is an afternoon of signing in and out.
What should a WordPress client agreement cover?
Put the scope in writing before the first invoice: what the plan includes and excludes, how fast you respond, how extra work is priced, when the price is reviewed and how either side can leave. Most people sell this as two or three WordPress care plans. Whatever the tiers, write down these clauses:
| Clause | What it settles | Example wording |
|---|---|---|
| Included work | What the fee buys | "Updates, daily backups, monitoring, a monthly report and up to one hour of small changes a month." |
| Exclusions | What is quoted separately | "New features, redesigns and content writing are quoted separately." |
| Response times | How fast you reply, not how fast it is fixed | "We reply to urgent issues within 2 business hours and to other requests within 1 business day." |
| Change requests | How clients ask | "Send requests to one email address. We confirm whether each is included or quote it before starting." |
| Unused time | Whether hours carry over | "Unused change time does not roll over." |
| Price review | When the fee can change | "Fees are reviewed once a year, with 30 days' notice." |
| Ending the plan | Notice and handover | "Either side can end the plan with 30 days' notice. We hand over a final backup and remove our access." |
Example wording only. Adapt it to your business and have your contract checked by a lawyer.
Two clauses need extra thought. Response is not resolution: you control how fast you reply, not how fast a host fixes a server.
And if the site collects form entries, orders or accounts for a client in the EU or UK, you are probably processing personal data on their behalf. Article 28 of the GDPR requires a contract for that, and the UK regulator, the ICO, says that "every time a controller uses a processor to process personal data, there must be a written contract". A short data processing agreement covers it.
The WordPress care plan template has a fuller clause list.
What should a weekly and monthly maintenance routine include?
Pick a fixed day each week for updates and backups and a fixed day each month for the deeper checks, then run the same list on every client site. A routine that depends on remembering is the first thing to slip in a busy week.
| Task | How often | What good looks like |
|---|---|---|
| Review and apply plugin and theme updates | Weekly, security fixes sooner | Backup first, key pages and forms checked after |
| Check that backups ran and are stored off the server | Weekly | A recent copy, away from the host |
| Watch uptime and the SSL certificate | All the time, with alerts | An alert reaches a person who acts on it |
| Test forms and the checkout | Weekly and after updates | A test message or order arrives |
| Scan for security issues and review administrator accounts | Monthly | No unknown administrators, no known holes |
| Check speed on key pages | Monthly | No key page slower than last month |
| Restore a backup to a test site | Every few months | The copy opens and works |
| Check renewal dates for domains, certificates and licenses | Monthly | Nothing expires by surprise |
Our recommended baseline. Stores and sites that earn money every hour need tighter checks.
Plugins deserve the most attention. Patchstack's State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, and 91% of them were in plugins, against only 6 in WordPress core. Our guide to WordPress plugin management covers how to add, update and remove them safely.
WordPress installs minor core releases and translations in the background by default (new installs since WordPress 5.6 take major releases too), but plugins and themes update automatically only in special cases unless you switch auto-updates on. Our guide to WordPress core updates covers the big releases.
How should you communicate with WordPress clients?
Agree one channel for requests, say how fast you reply, and tell clients about problems before they find them. Most clients never see your maintenance work, but they always see how you behave when something goes wrong.
- One channel. Requests go to one email address or form, not to your personal phone, a chat app and three colleagues. Keep the phone for real emergencies, and agree what counts as one.
- Clear hours. Say when you work, in which time zone and what happens on holidays.
- Reply fast, even when the fix takes longer. "Got it, I will look at it today" beats a perfect fix after two days of silence.
- Warn before planned work, such as a major update or a theme change.
What to say during an outage
Send a short update before the client asks, and keep updating until it is fixed. Each update answers four questions: what happened, what is affected and what still works, what you are doing now, and when they will hear from you next.
For example: "Your site has been unreachable since 9:40. The host has confirmed a server fault and is fixing it. Your email is not affected. I will update you by 10:30, or sooner if it is back."
Afterwards, send three lines: the cause, what you did and what stops it happening again.
How do you report to clients so they actually read it?
Send a short monthly report that leads with outcomes in plain words and puts the technical detail underneath. Good maintenance is invisible, so the report is how the client sees what they pay for.
- Open with a three-sentence summary: was the site up, was anything fixed or prevented, and is anything needed from the client.
- Translate the work. "26 updates applied and checked, including 3 security fixes" means more than a list of version numbers.
- Report the bad news too. An outage the client noticed and the report leaves out costs more trust than the outage did.
- Compare with last month, and recommend one thing, such as a PHP upgrade or a faster host.
- Send it on the same day every month.
Our free WordPress maintenance report template lays out a seven-section structure. To build reports from real data instead of by hand, see what to look for in WordPress client reporting software.
How do you handle client requests and scope creep?
Decide in advance which requests the plan includes, and say so every time one is not. Scope creep is rarely one big ask. It is a steady stream of small ones that each feel too small to quote.
| Type of request | Example | What to do |
|---|---|---|
| Included | Swap a photo, fix a typo | Do it, and list it in the monthly report |
| Small extra | A new form or landing page change | Quote a fixed price before you start |
| Project | A redesign, a new feature or a shop | Send a separate proposal with its own timeline |
| Emergency | The site is down or hacked | Act at once, under the emergency terms you agreed |
Tell the client which row a request falls in before you start.
Say yes with a price ("Happy to. That one is outside the plan, so here is a fixed price before I start"), keep a running list of every request and how long it took, and if the same extra work keeps coming back, move the client to a bigger plan at the next review instead of absorbing it.
How should you handle billing, renewals and price reviews?
Bill maintenance in advance on a fixed day, let plans renew automatically with notice, and review every client's price once a year against what the site actually takes to look after.
- Bill in advance, monthly or yearly, ideally by card or direct debit so nobody has to remember.
- Agree what happens when an invoice is late, for example a reminder after 7 days and a pause on non-urgent work after 30. Keep monitoring and backups running while you chase it.
- Review once a year. Compare the year's requests, incidents and time with the fee. The care plan calculator shows your real margin, and our guide on how much to charge for WordPress maintenance covers pricing models.
- Raise prices with notice and a reason. Give at least the notice your agreement sets, ideally 90 days, and point to the work in the year's reports as well as to what has changed on your side.
How do you offboard a WordPress client cleanly?
Offboarding means handing over everything the client owns, in working order, then removing every way you had into their accounts. Confirm the end date and the handover list in writing first, then:
- Take a final full backup and give the client a copy. Tools > Export also creates an XML file of the content (posts, pages, comments, custom fields, categories, tags and users), but it is not a copy of the theme, plugins or files, so it does not replace the backup.
- Put the domain in the client's name. Ask the registrar to move it to an account the client controls, or have the client request the transfer code. Under ICANN's Transfer Policy, the registrar must provide that code within five calendar days, may refuse a transfer within 60 days of registration or of a previous transfer, and must lock transfers for 60 days after a change of registrant unless the owner opted out first. Start early.
- Move the hosting to the client's own account and payment method, and check that the site and email still work afterwards.
- Sort out licenses. Premium plugins and themes bought on your account either transfer, if the vendor allows it, or the client buys their own before you remove yours.
- Hand over Google services. Make the client the owner in Search Console and an Administrator in Analytics, then remove yourself. In Search Console, also delete your verification token, because Google notes that a removed owner whose token is still in place can verify ownership again.
- Remove your WordPress access: your accounts (attribute their posts to the client), your Application Passwords and any management or connector plugins you installed.
- Send the updated site record and confirm in writing that your access is gone.
When should you move from spreadsheets to a management platform?
Move when the routine no longer fits in your week, or when you cannot say in a minute who has access to which client site. A spreadsheet and a password manager are fine for a handful of sites. The signs you have outgrown them:
- Clients notice downtime, broken forms or pending updates before you do.
- Removing one contractor means signing in to every site.
- Reports take longer to write than the work they describe.
- Nobody can say which sites were updated this week.
Managing WordPress clients with WPCentrify
Disclosure: WPCentrify is our product. WPCentrify, a hosted WordPress management platform for anyone responsible for more than one WordPress site, brings the routine above into one dashboard for every client site.
We built it as a WordPress website management platform for exactly this work, and we use it ourselves: the account we work from manages 18 WordPress sites, and on 10 October 2026 it showed 11 updates waiting for review across them. That number is easy to miss when every site has its own wp-admin, and obvious on one screen.
- One-click WordPress login. Everyone signs in to a client site as themselves, with the WordPress role you set per person, per site. Nobody on your team holds a client password, and when somebody leaves, one action ends their access everywhere at once.
- WordPress team access management. Each person has their own login, with permissions set per area from viewing to acting. Team members are never charged for.
- White label WordPress client reports, built from the record of what happened on each site and sent on a schedule you set for each client. White label branding is the one paid add-on; every core feature is included on every plan.
- An activity log of every action on every site, in wp-admin and from WPCentrify, with the person and the time, so "who changed that?" has an answer.
- Uptime monitoring every 60 seconds from 3 locations, Malaysia, Canada and the USA, with an email alert only when locations on different providers agree, after three failed checks in a row.
What it does not do: WPCentrify looks after the sites, not your contracts, invoices or inbox, so keep those in the tools you already use. It is free during early access, and prices are announced at launch.
Sources
- Roles and Capabilities, Users screen, Site Health screen and Tools Export screen, WordPress.org documentation
- Application Passwords: Integration Guide, Make WordPress Core
- Upgrading WordPress and Hardening WordPress, WordPress Advanced Administration Handbook
- State of WordPress Security in 2026, Patchstack
- Transfer Policy (updated 21 February 2024), ICANN
- Managing owners, users, and permissions, Search Console Help, and Access and data-restriction management, Analytics Help
- General Data Protection Regulation, Article 28, EUR-Lex, and When is a contract needed and why is it important?, ICO
All sources checked on 10 October 2026. This guide is general information, not legal advice.
Questions about managing WordPress clients
Run every client through the same process: onboard the site properly, give each person their own access, agree the scope in writing, keep a weekly and monthly maintenance routine, report monthly in plain language and offboard cleanly. Past a few sites, a management platform keeps that routine in one place.
Ask what the site does for the business, who approves changes and pays, what counts as urgent, what has broken before and when nothing should change. Then collect access to the domain, hosting, WordPress and Google accounts, and a list of premium licenses.
No. Give each person their own account at the lowest role that does the job, so the site's history shows who did what and you can remove one person without changing everyone's password. Tools can use Application Passwords, which can be revoked one at a time.
The client should keep at least one Administrator account, because it is their site. Staff who only manage content usually need Editor, and writers need Author or Contributor.
What the plan includes and excludes, response times, how change requests are made and priced, when prices are reviewed, the notice period and what you hand over at the end. If you process personal data for a client in the EU or UK, add a data processing agreement.
Review plugin and theme updates at least weekly and apply security fixes as soon as you can, with a backup first and a check of key pages after. WordPress installs minor core releases automatically by default, but plugins and themes only in special cases unless you switch auto-updates on.
Write down what the plan includes, quote anything outside it before you start, and list the included requests in the monthly report. If the same extra work keeps coming back, move the client to a bigger plan at the next review.
Give the client a final full backup and an updated site record, make sure the domain, hosting, Google accounts and premium licenses are in their name, then remove every account, Application Password and plugin you added. Confirm in writing that your access is gone.
Ask the registrar to move the domain into an account the client controls, or have the client request the transfer code, which ICANN's Transfer Policy says the registrar must provide within five calendar days. A registrar may refuse a transfer within 60 days of registration or of a previous transfer, so start early.
Yes, for most maintenance plans. A short report that leads with outcomes such as uptime, updates applied, backups and security fixes shows work that is otherwise invisible, and gives the renewal conversation something to stand on.
Use a management platform once the routine stops fitting in your week. WPCentrify, our own platform, puts every client site in one dashboard, with one-click login at a WordPress role you set per person and per site, uptime checks every 60 seconds from 3 locations and client reports. It is free during early access.
Related reading
WordPress care plans
What to include at each tier, what to exclude and how to price it.
Read the guideMaintenance report template
A seven-section monthly report that clients actually read.
Get the templateOne-click WordPress login
Sign in to any client site as yourself, with no shared passwords.
See the featureMore on this topic: how much to charge for WordPress maintenance and WordPress agency management software.
Look after every client site from one dashboard
Updates, backups, uptime, access and client reports for every WordPress site you manage, with email alerts only when something needs you.
Free during early access. No credit card required.