Ownership and access
What happens when a former developer controls your hosting?
When hosting, DNS, or admin logins stay with a past developer, renewals and emergencies become someone else's lever — how to regain control.
Josh
The relationship ended months ago. The site still loads. Then the SSL certificate expires, the host suspends the account for a billing issue you never saw, or you need to migrate before a price increase — and the only person who can log into cPanel, Cloudflare, or the managed host dashboard is not returning calls.
This is not a rare edge case. It is a predictable outcome when hosting, DNS, domain registration, and WordPress admin credentials live in a former developer’s personal accounts instead of the business’s. The site becomes hostage to goodwill, not contracts.
What “controls hosting” really includes
Hosting control is more than FTP. A past developer may still hold:
- Hosting panel login (cPanel, Plesk, Kinsta, WP Engine, SiteGround, etc.).
- Billing profile — card, invoice email, renewal on their personal Amex.
- DNS at Cloudflare, Route 53, or the registrar.
- Domain registration in their personal Namecheap or GoDaddy account — see who should own your domain name.
- WordPress admin as the only administrator, or admin tied to their email.
- Email hosting or Google Workspace super-admin.
- Third-party services — Stripe, Mailchimp, analytics — also on personal logins covered in accounts that should never use personal email.
Any one of these can block a migration. Several together can freeze the business for weeks.
How the lockout shows up in real incidents
Billing and renewals
The host sends renewal notices to the developer’s inbox. Their card is charged. When they stop paying — out of spite, forgetfulness, or because you stopped paying them — the account suspends. You discover this when the site goes offline or email bounces.
SSL and DNS changes
Let’s Encrypt or AutoSSL fails because DNS points elsewhere or the developer removed access. You need a new certificate or a DNS edit; only their Cloudflare login can fix it.
Emergency repair blocked
A technician asks for hosting access to restore files or run malware cleanup. You have WordPress editor access for blog posts, but no file manager, no database, no backups tab. Repair stalls while everyone hunts for a ghost.
Migration paralysis
You signed with a new host or a care plan that includes managed hosting, but the origin server credentials and DNS are opaque. Every day of delay is risk — and sometimes double billing if you provision new infrastructure you cannot cut over to.
Hostile or silent non-cooperation
Some former vendors cooperate for an hourly fee. Some go silent. Some change passwords. The business is left proving ownership to support teams without documentation.
What you can do before the relationship sours
If you still have a working relationship, fix this now:
- Move hosting billing to a business card and business email.
- Create a business-owned hosting login; add the developer as a secondary user with limited roles where the host supports it.
- Export a full backup you store outside their systems.
- Document DNS — screenshot or export zone file; note registrar and nameservers.
- Add a second WordPress administrator on a business email; never rely on a single external admin.
- Start a digital-asset inventory while answers are easy to get.
Treat a clean handoff as part of project closeout, not a favor.
How to regain control when access is already lost
Work from evidence upward. Hosts and registrars have verification processes — they are slow, but they exist.
Step 1: Gather proof of business ownership
Collect what support teams typically accept:
- Business registration, EIN letter, or operating agreement showing domain match.
- Invoices for hosting or domain in the business name (even old ones help).
- WHOIS history, marketing materials, or trademark registration using the domain.
- Contracts or statements of work naming the site as a deliverable to you, not to the developer personally.
Step 2: Identify every vendor in the chain
Write down: registrar, DNS provider, hosting company, email provider, CDN. Each has a separate support portal. “I forgot my password” tickets go faster when you can prove you are the business behind the domain.
Step 3: Contact hosting support as the account owner
Call or ticket with proof. Ask explicitly:
- Who is listed as the account owner and billing contact?
- What is required to reset the owner email or add you as authorized?
- Are there outstanding invoices or suspensions?
- Can they provide backup snapshots to a verified owner even if panel login is locked?
Policies vary. Managed WordPress hosts often help legitimate owners; resold accounts through an agency take longer.
Step 4: Recover domain and DNS in parallel
If the domain is also locked, start registrar recovery at the same time — DNS control without hosting access (or the reverse) still leaves you stuck. Domain ownership guidance is in who should own your domain name.
Step 5: Stabilize the live site
While ownership tickets process:
- Avoid destructive changes on production.
- If the site is compromised or down, say so upfront — some hosts prioritize security escalations.
- If you have any WordPress admin access, export content and verify what backups exist inside the dashboard.
- Consider whether emergency repair is needed to keep revenue flowing while access recovery runs — two tracks, one timeline.
Step 6: Migrate once you have a foothold
When you regain panel access or receive a backup from support:
- Pull a fresh full backup (files + database).
- Rebuild on business-owned hosting.
- Lower DNS TTL before cutover.
- Repoint DNS from an account the business controls.
- Revoke the former developer’s users everywhere.
Do not “share” the old host indefinitely out of convenience. Finish the divorce.
When legal pressure is appropriate
If the developer registered assets in their personal name but was paid to build your site, ownership disputes may need legal counsel. That is slower and costlier than prevention — but cheaper than losing a commerce domain during peak season.
Document every good-faith request for access. Avoid threats in writing you cannot back up. Focus support conversations on business continuity and verified identity.
What hosts cannot always fix
Support can reset emails for your account. They cannot merge two random personal accounts without proof. They will not override DNS at Cloudflare from a cPanel ticket. They cannot recover a domain registered to developer@gmail.com without registrar processes.
That is why inventory and business-owned logins matter before the crisis.
Preventing the next lockout
After recovery, institutionalize:
- Two admin paths — hosting panel and WordPress, both on business emails.
- Password manager with role-based entries, not one person’s memory.
- Quarterly access audit — can you log in without calling anyone?
- Vendor offboarding checklist — remove users within 48 hours of contract end.
- Care or maintenance only after ownership is clear — ongoing work assumes you can authorize changes.
The bottom line
When a former developer controls hosting, they control renewals, migrations, SSL, and your ability to respond to outages. The site may look fine until the moment you need leverage — and then you discover the leverage was never yours.
Regain control with proof, parallel registrar and host tickets, and a migration to infrastructure billed to the business. Do not wait for the next expired certificate or unpaid invoice to prove the arrangement was fragile. Build the inventory, move the billing, and keep the keys where the business can actually use them.
Related in Ownership and access
-
Ownership and access
Which website accounts should never use an employee's personal email?
Personal Gmail on domain, hosting, or payments creates silent lockouts when people leave. Which accounts need business-owned email.
-
Ownership and access
How to create a business digital-asset inventory
Build a living list of domains, hosting, DNS, email, analytics, and SaaS logins — owners, vendors, and recovery paths included.
-
Ownership and access
Who should own your domain name?
Domains should sit with the business — not a freelancer's personal account. How ownership, renewals, and DNS control protect you.