Agency operations guide
Inventory SEO Risk When You Inherit a Client's WordPress Site
Before changing an inherited site, record who owns each account, what produces the search output, which paid services renew, and which settings nobody can explain yet.
On this page
When you take over a client’s WordPress site, make an intake register before you change anything. It has four parts: who owns and can reach each account, what produces the site’s search output, which paid services and licenses the site depends on, and which settings nobody can yet explain. Mark anything you cannot confirm as unknown. An undocumented setting is a question for the client, not automatically a mistake.
The register gives you a record of the site as you found it. Once you change a setting, that starting state is gone unless someone recorded it, and so is your ability to show what was there before you arrived.
Gather access and ownership facts
Start with the accounts, because a site you cannot fully control is a risk no SEO work can fix. For each one, record the owner of record, who else has access, and how you confirmed it.
| Asset | Owner of record | Who else has access | How confirmed | Renewal or expiry |
|---|---|---|---|---|
| Domain registration | Registrar account seen | |||
| DNS hosting | ||||
| Web hosting | ||||
| WordPress administrators | Users screen reviewed | |||
| Google Search Console | Users and permissions screen | |||
| Bing Webmaster Tools | ||||
| Analytics | ||||
| Plugin and theme licenses | Vendor account seen |
WordPress administrators have access to all the administration features within a single site. WordPress’s roles and capabilities documentation, checked September 27, 2026. List every administrator by name and ask the client which accounts are still needed. Accounts for former contractors can remain.
Check Application Passwords on each administrator’s profile too. WordPress shows each password by name with its last used time and IP address, and each can be revoked individually without changing the user’s main password. WordPress’s Application Passwords documentation, checked September 27, 2026. Record them; do not revoke them until you know what they connect.
In Search Console, owners have full control of a property, and a removed owner can re-verify unless their verification tokens are also deleted. Google’s help on managing owners, users, and permissions, checked September 27, 2026. Note which verification method each owner used: an HTML tag printed by an SEO plugin disappears when that plugin is removed, unless the replacement prints the same tag, and Search Console periodically checks that the tag is still there. Google’s help on HTML tag verification, checked September 27, 2026.
Record what produces the search output
Next, find out which software prints each part of the page head and handles each rule. Open the homepage, one post, one page, and one category in a private window, view the source, and record:
- How many
<title>tags, meta descriptions, canonical links, and robots meta tags appear. More than one of any often means two plugins, or a plugin and the theme, are printing the same tag. - Which plugin or theme prints the structured data, and how many separate JSON-LD blocks exist.
- The sitemap address, and whether
/robots.txtpoints to it. - Where redirects run: an SEO plugin, a dedicated redirect plugin, the host, a CDN, or server configuration. Several can be active at once.
- Whether the site is multilingual, a store, or uses custom post types, since each changes how templates behave.
Also record the WordPress and PHP versions from Tools → Site Health → Info: the WordPress section shows the core version and the Server section shows PHP. WordPress’s Site Health screen documentation and the WP_Debug_Data reference, checked September 27, 2026. These versions limit which plugins the site can run, since a plugin can declare the lowest WordPress and PHP versions it works on. WordPress’s plugin header requirements, checked September 27, 2026.
Record paid services and their terms
List every paid plugin, theme, and service the site depends on, with the account holder, the renewal date, and what the vendor says happens if it lapses. Vendors answer that last question differently, so read each one’s terms rather than assuming. A premium SEO plugin, a redirect service, a CDN, and a backup service can all affect search output or recovery.
If a license belongs to a previous agency, its renewal is in that agency’s hands, not the client’s. Put the question of who owns each license on the list for the client; deciding who owns the plugin license covers the options.
Treat unexplained settings as open questions
Inherited sites carry decisions nobody wrote down. A noindexed category, a canonical pointing to another domain, or a redirect that sends an old service page to the homepage might be a mistake. It might also be deliberate: a category kept out of search on purpose, an article syndicated from a partner’s original, a service the business stopped offering.
Give each finding one of three statuses:
| Status | Meaning | What you do |
|---|---|---|
| Confirmed intentional | The client or previous team explained it | Record the reason; leave it |
| Confirmed error | Evidence shows it is wrong and nobody wants it | Queue a fix with the client’s approval |
| Unknown | No explanation yet | Ask; do not change it yet |
Below is an illustrative intake extract for a fictional site, garden.example. It shows the format, not real findings.
| Finding | Evidence | Status | Next step |
|---|---|---|---|
| Two title tags on posts | View source on three posts | Confirmed error | Identify which plugin prints the second |
| Category “Clearance” is noindexed | SEO plugin setting | Unknown | Ask the client |
| Canonical on one article points to a partner site | View source | Unknown | Ask whether the article was syndicated |
| Former designer still an administrator | Users screen | Unknown | Ask whether access is still needed |
| Premium SEO plugin license on previous agency account | Vendor license screen | Unknown | Ask who pays and who holds the account |
Prioritize the unknowns before intervening
Work through the register in order of what could do the most damage if left alone, not in order of what is easiest to fix:
- Anything that can take the site out of search or stop it being crawled. Settings → Reading discouraging search engines, which prints a noindex robots meta tag; noindex applied to a whole post type; or a blanket
Disallowin robots.txt, which blocks crawling, though the URLs can still appear in Google without a description. WordPress’s Reading settings documentation and Google’s introduction to robots.txt, checked September 27, 2026. - Access you cannot recover. A domain or DNS account only a departed person can reach.
- Renewals about to lapse. Domain, hosting, and licenses with near expiry dates.
- Conflicting output. Duplicate head tags, competing sitemaps, and redirects handled in two places.
- Everything else, once the client has answered the unknowns.
The register also answers whether to change the site’s tooling at all. If the current SEO plugin does a job the client depends on, keeping it may be the right call. WP Visibility, for example, requires WordPress 7.0 and PHP 8.1 or newer, per its install documentation, so a site on older versions rules it out until those are upgraded. If a switch does make sense, switching SEO plugins with a verification plan covers that project, and the onboarding register becomes its baseline.
Intake checklist
- Every account has an owner of record, or is marked unknown.
- Administrators and Application Passwords are listed, not yet removed.
- Search Console owners and verification methods are recorded.
- Head tags, sitemap, robots.txt, and redirect layers are recorded for four sample URLs.
- WordPress and PHP versions are noted.
- Paid services have an account holder, renewal date, and lapse terms.
- Every unexplained setting has a status, and unknowns are with the client.
