---
title: "A Paid Plugin Handoff Checklist for Client Sites"
date: 2026-06-21
author: "Imtiaz Rayhan"
featured_image: "https://wpblocksuite.com/wp-content/uploads/2026/08/featured-paid-plugin-handoff-client-sites.png"
categories:
  - name: "WordPress Plugins"
    url: "/blog/category/wordpress-plugins.md"
---

# A Paid Plugin Handoff Checklist for Client Sites

A paid plugin handoff must transfer control, not merely files. Assign ownership, billing, updates, support, access, and maintenance explicitly.

Inventory every commercial dependency first. Then verify the client’s account, site connection, recovery path, and acceptance evidence.

## What belongs in a paid plugin handoff?

Include each entitlement, owner, assigned site, renewal, support route, and update method. Add credentials, configuration, and maintenance responsibility.

The client needs an operable system after your access ends. A folder of plugin archives cannot provide that.

## Treat handoff as a controlled state change

Before handoff, the agency may control purchasing and deployment. Afterward, the agreed owner must control recovery and decisions.

Define the effective date and acceptance criteria. Keep current service stable until those criteria pass.

## Separate six kinds of control

- Commercial ownership of the entitlement.
- Billing and future renewal responsibility.
- Vendor account and recovery control.
- WordPress site administration.
- Plugin configuration and service connections.
- Ongoing testing, updates, and incident response.

One login rarely controls every layer. Transfer and verify each required layer separately.

## Choose the final ownership model first

- The client owns and pays directly.
- The agency owns under continuing service.
- The client owns while the agency collaborates.
- A host includes entitlement within hosting.
- Another provider owns a managed bundle.

Document which model applies to every paid plugin. Mixed models are common and need clear labels.

## Client ownership provides independent control

The client controls renewal, recovery, support, and future provider changes. This model reduces agency dependency after exit. We settle it in [should the client or agency own paid plugins](https://wpblocksuite.com/blog/client-vs-agency-own-paid-plugins/).

It also requires capable client administration. Provide training and named backup owners.

## Agency ownership can remain valid

An active maintenance agreement may include paid plugin access. State the included products, term, limits, and exit process.

Do not imply permanent client ownership when entitlement ends with service. Make replacement costs visible before agreement.

## Hosting-included licences need special labels

Some hosting plans include commercial extensions or services. Access may end when the site leaves that platform.

Record the provider, included capability, portability limit, and replacement route. Do not call it client-owned.

## Build the handoff inventory

- Plugin name and installed version.
- Vendor, marketplace, and product page.
- Commercial owner and billing owner.
- Order, plan, and renewal date.
- Site allowance and assigned environments.
- Vendor account and recovery owner.
- Local activation or connection status.
- Update source and support route.
- Configuration and external service dependencies.
- Maintenance owner after handoff.

Include inactive paid plugins when they remain installed. Their files, data, and renewals still require a decision.

## Discover plugins from the actual site

Do not rely only on invoices or project proposals. Compare the WordPress plugin list with commercial records. We answer that in [can you transfer a WordPress plugin licence](https://wpblocksuite.com/blog/transfer-wordpress-plugin-licence/).

Include [must-use plugins](https://wpblocksuite.com/blog/must-use-wordpress-plugins/) and network-active plugins where relevant. Note custom code that depends on commercial components.

## Identify hidden premium components

A free base plugin can rely on a paid add-on. A theme or bundle can also deliver extensions.

Trace update sources and vendor account pages. Ask the technical owner about manual package installations.

## Resolve unlicensed or unknown entries

Do not hand uncertainty to the client. Identify the purchaser, valid entitlement, origin, and current maintenance state.

Replace unauthorised packages through legitimate sources. Preserve recovery before changing production code.

## Confirm the exact site identities

Record production, staging, development, redirects, and former domains. Compare them with vendor portal assignments.

A migrated or cloned site can leave stale activations. Remove only verified obsolete records.

## Resolve entitlement capacity before handoff

The recipient needs enough valid site allowance for production and approved testing. Confirm product-specific staging treatment.

Do not borrow capacity from unrelated client sites. Purchase or transfer suitable entitlement.

## Decide transfer, sharing, or repurchase

A formal transfer changes ownership when the vendor permits it. Sharing grants access while another party remains owner.

A fresh client purchase creates clean separation. Choose the workflow matching the agreed final control.

## WooCommerce documents agency handoff options

Its [agency guidance](https://woocommerce.com/document/managing-woocommerce-com-subscriptions/managing-subscriptions-as-a-developer-or-agency/) covers transfer, sharing, client purchase, and collaboration. Each option assigns ownership differently.

Use product-specific vendor instructions for every other plugin. Do not generalise one marketplace’s workflow.

## Formal transfer requires acceptance

WooCommerce documents recipient acceptance for subscription transfer. Initiation alone does not complete commercial ownership.

Track pending invitations and confirm the final account. Cancel incorrect invitations through supported controls.

## Installed files do not prove completed transfer

The plugin may remain active while update or support access changes. Commercial control can move separately.

Verify the installed version, local status, update channel, and vendor portal after commercial handoff.

## Site connections may need separate work

WooCommerce says its site connection does not automatically move with subscription ownership. The recipient reconnects afterward.

Other plugins use keys, tokens, or account authorisation. Follow their exact reconnection instructions.

## Do not email raw licence keys casually

Email creates durable copies and forwarding risk. Use supported account controls or approved secret-sharing methods.

Never place keys in general handoff documents. Record where authorised users retrieve them.

## Rotate exposed credentials when supported

Project chat, tickets, repositories, or screenshots may contain old secrets. Search approved systems before closure.

Ask the vendor about replacement when exposure occurred. Verify every affected site after rotation.

## Prepare organisation-controlled client accounts

Use client-controlled addresses and recovery methods. Avoid tying entitlement to one employee or former contractor.

Enable supported multifactor protection. Assign a backup account owner and test recovery.

## Use collaborator access where supported

WooCommerce documents named collaborator permissions without password sharing. Permissions can cover subscriptions, sites, downloads, or support.

Grant only required capabilities. The client should perform owner-only actions when documentation requires them.

## Transfer vendor support context

List open cases, known defects, workarounds, and authorised support contacts. Include dates and current status.

Redact unrelated client information. Confirm the new owner can open and view relevant tickets.

## Transfer renewal responsibility

State the renewal date, current term, expected payer, and approval owner. Disable obsolete agency billing only after verification.

Do not promise unchanged future pricing. Link current vendor records and document existing terms.

## Transfer invoice and purchase evidence

Provide allowed order identifiers, receipts, and entitlement confirmations. Preserve tax records according to each organisation’s policy.

Remove unrelated purchases and payment details. Store evidence in a client-controlled approved system.

## Document update behaviour

- Where update notices appear.
- Whether authenticated updates require connection.
- Who reviews release notes.
- Which updates receive staging tests.
- Which changes use maintenance windows.
- How success is verified.
- Where rollback packages come from.
- Who handles failed updates.

WordPress recommends current backups before plugin updates. Its [plugin management guidance](https://wordpress.org/documentation/article/manage-plugins/) describes dashboard update controls.

## Provide a recoverable baseline

Take an approved backup before changing accounts or connections. Record versions, configuration, and health checks.

Test restoration according to site risk. A backup without a working recovery route is weak evidence.

## Document configuration ownership

Commercial plugins can control payments, forms, caching, security, redirects, or structured data. Name the responsible operator.

Explain settings that must not change casually. Link vendor documentation and internal decisions.

## Document external services

- API account and accountable owner.
- Billing plan and usage limit.
- Webhook destinations and secrets.
- Sender domains and mail services.
- Storage buckets and media services.
- Analytics, advertising, and consent systems.
- Payment and fulfilment connections.
- Monitoring and security portals.

A plugin handoff fails if its required service remains agency-controlled. Transfer or replace every dependency deliberately.

## Document plugin dependencies

List required base plugins, add-ons, themes, and custom integrations. Record supported versions and update order where needed.

A paid add-on without its parent is not a complete deliverable. Verify the whole operating chain.

## Document data and uninstall behaviour

Explain important tables, uploads, options, and retention settings. Identify data needed for legal or operational reasons.

Do not test uninstall on production during handoff. Use staging and verified backups.

## Document known exceptions

Record pinned versions, disabled [auto-updates](https://wpblocksuite.com/blog/which-wordpress-plugins-auto-update/), patches, incompatibilities, and temporary workarounds. Assign owners and review dates.

Unexplained exceptions become permanent risk. The client must understand their maintenance cost.

## Remove development-only components

Debugging, migration, import, and test plugins may no longer be needed. Confirm purpose before removal.

Delete unused plugins through a controlled change. Verify that required data and workflows remain intact.

## Resolve duplicate capabilities

Two plugins may perform overlapping caching, security, redirects, or schema work. Handoff should explain intentional overlap.

Do not redesign the stack during final transfer without scope. Create a separate approved cleanup plan.

## Perform a pre-handoff health check

- Front page and critical templates render.
- Forms submit through safe tests.
- Checkout and account paths work.
- Scheduled jobs show expected behaviour.
- Authenticated updates are visible.
- Logs show no new critical failures.
- Backups complete and can be accessed.
- Monitoring reaches the new owner.

Choose checks matching the site’s real purpose. Never send live payments or customer messages accidentally.

## Recheck after account changes

Repeat critical health checks after transfer, reconnection, rotation, or access removal. Compare against the baseline.

Capture observed results and timestamps. Escalate discrepancies before ending agency access.

## Train the client’s named operators

- How to access vendor accounts.
- How to review renewal notices.
- How to identify pending updates.
- How to request vendor support.
- How to access backups.
- How to report an incident.
- Which settings require approval.
- Who provides ongoing maintenance.

Training should use the client’s own access. Screen sharing with agency credentials proves little. The mechanics are in [how agencies should inventory licences](https://wpblocksuite.com/blog/agency-plugin-licence-inventory/).

## Use a client acceptance record

- Inventory received and reviewed.
- Ownership model accepted.
- Vendor accounts accessible.
- Billing responsibility understood.
- Site connections verified.
- Updates and support available.
- Backups and recovery understood.
- Known risks and exceptions accepted.
- Maintenance owner named.
- Effective handoff date confirmed.

Acceptance closes defined deliverables. It should not waive concealed defects or replace contractual obligations.

## Remove agency access in sequence

1. Confirm client owner access.
2. Confirm backup recovery access.
3. Confirm vendor entitlement control.
4. Confirm support and update capability.
5. Transfer required service accounts.
6. Remove shared secrets and sessions.
7. Remove obsolete vendor collaborators.
8. Remove obsolete WordPress users.
9. Remove hosting and deployment access.
10. Verify the site again.

Do not remove the only working recovery path. Independent verification must precede final offboarding.

## Keep agency records proportionate

Retain contracts, invoices, approvals, and completion evidence according to policy. Delete copied secrets and client data.

Record what access was removed and when. Avoid retaining hidden administrative accounts.

## Set a short post-handoff observation period

An agreed observation window can catch missed notices, access failures, or service interruptions. Define included support clearly.

Do not leave responsibility indefinite. State the final escalation date and future commercial terms.

## Schedule the first independent maintenance review

The new owner should complete one update review independently. Confirm notices, backups, approval, testing, deployment, and verification all work.

Record any missing permissions or documentation. Correct them before the observation window closes.

## Confirm future contact routes

Give the client current vendor, hosting, and emergency contacts. Remove personal addresses that no longer represent accountable support.

## Know the honest weak case

Retained agency ownership can be defensible under ongoing managed service. It may simplify purchasing and updates.

The agreement must explain termination, replacement cost, access, and continuity. Hidden dependency remains unacceptable.

## Use the paid plugin handoff checklist

1. Define the ownership model for every entitlement.
2. Inventory installed commercial plugins and add-ons.
3. Map vendors, accounts, plans, and renewals.
4. Map production and staging assignments.
5. Resolve unknown or unauthorised packages.
6. Choose transfer, sharing, or client purchase.
7. Create organisation-controlled client accounts.
8. Secure account recovery and authentication.
9. Transfer billing and invoice evidence.
10. Complete recipient acceptance where required.
11. Reconnect sites through supported controls.
12. Verify updates, support, and services.
13. Document configuration and dependencies.
14. Provide backups and tested recovery access.
15. Document exceptions and maintenance duties.
16. Train named client operators.
17. Capture client acceptance.
18. Remove agency access in sequence.
19. Repeat critical site checks.
20. Close with secret-free evidence.

## Frequently asked questions

Should clients own their paid WordPress plugins?



 

Often, yes. Retained agency ownership can also fit an explicit managed-service agreement.



 

Is sending the plugin files a complete handoff?



 

No. The client also needs entitlement, updates, support, recovery, and maintenance control.



 

Should licence keys go in the handoff document?



 

No. Use vendor account controls or an approved secure secret-sharing method.



 

Does transferring a subscription reconnect the site?



 

Not always. WooCommerce documents site reconnection as a separate recipient step.



 

When should agency access be removed?



 

After client control, recovery, updates, support, and critical site checks are verified.



 



## The verdict

Verdict

**Transfer operating control:** assign every entitlement, account, renewal, connection, and maintenance duty. **Verify independence:** prove client access, updates, support, recovery, and site health before removing agency access.

A complete handoff leaves no commercial or technical mystery. [Review WP Block Suite’s $299 lifetime licence](https://wpblocksuite.com/#pricing).