"An agency built our website several years ago, and all we want to do is swap out a single announcement on the homepage. However, we can no longer reach that agency. The employee who served as the point of contact back then left the company, and nobody internally knows the login credentials for the admin dashboard." We recently received this exact consultation. It is a common story.
We call websites left neglected for years without updates "stagnant sites." When opened in a browser, they display normally and look fine, but in reality, their contents cannot be updated, and both their security and intellectual property rights are hanging in limbo. In this article, we write about what to verify and in what sequence to take over such websites and return them to a maintainable state, from our perspective of taking over projects for clients.
Deterioration progressing behind "it looks fine"
First, consider the unseen risks carried by a website that appears to be working. Behind its visible facade, various expirations quietly slip by.
If servers or CMS platforms (such as WordPress) have not been updated for years, known vulnerabilities remain unpatched, serving as gateways for unauthorized alterations or malware installation. Often, no one knows who manages SSL certificate or domain renewals, leading to situations where a site suddenly displays "Not Secure" or, in the worst case, the domain itself expires. It is also common for contact forms to remain outdated, silently failing to deliver inquiries. The assumption that "it looks fine, so it must be fine" does not apply to un-updatable websites.
Rights and keys to check first when taking over
When taking over a stagnant website, we do not jump straight into design discussions. What we secure first is identifying where the rights and keys required to access and modify the site reside.
Specifically, this includes domain administrative privileges (the registrar account), server contracts and logins, CMS administrator accounts, and the location of source code and design assets. When production was outsourced, these may remain registered under the agency's name, meaning the process begins with transfer negotiations. Skipping this step and diving into modifications leads to dead ends like being unable to point the domain or access the production server.
| Item to Check | Common Bottlenecks |
|---|---|
| Domain | Remains under the agency's name; transfer requires their cooperation |
| Server | Contractor/payer is unknown; cannot log in |
| CMS Admin Dashboard | Password unknown due to administrator departure; recovery required |
| Source and Data | Not available on hand; must be extracted and restored from live files |
Fixing vs. rebuilding
Once the keys are in hand, the next decision is whether to keep maintaining the current site or rebuild it. If the foundation is relatively recent and can be operated once update access is recovered, transitioning it into a maintenance contract is the most practical choice. On the other hand, if the CMS is outdated and ridden with vulnerabilities, page loading is excessively slow, or mobile responsiveness is broken, rebuilding from scratch may ultimately prove less expensive than attempting to prolong its life.
This decision aligns with general renewal strategy. If you are considering a rebuild, please refer to our corporate website renewal guide and article on avoiding pitfalls in website renewals. If you need to migrate domains, also see our article on domain migration without losing search rankings.
Case study: A company where no one knew the WordPress login credentials
Here is a specific example (the company name is withheld). A company consulted us regarding a WordPress site outsourced several years prior: the admin login information had been lost when the former point of contact resigned, making any updates impossible. The production agency had already closed down, leaving no contact information.
We traced the account holder through the server payment history to restore server login access, through which we recovered the WordPress administrator account. Concurrently, we backed up all live files and the database locally, ensuring they could be migrated to another server at any time. After cleaning up obsolete plugins, we placed the site under a maintenance contract. What resolved the issue was not building a new site, but tracking down what was located where one step at a time, and returning the keys to the company's hands.
Start by taking inventory of what exists and where
Pay attention to the sequence. When consulted about stagnant websites, there is a temptation to immediately generate estimates for a rebuild, but what must precede that is an inventory. Document on a single page who currently holds the domain, server, CMS, and source code. Once these return to your company's control, you can proceed with agency and autonomy, whether you choose to repair or rebuild.
If you have an abandoned website you cannot update, cannot contact your web production agency, or find yourself stuck without login credentials, please feel free to reach out through GleamHub's website production and renewal consultation. We will assist you within a realistic scope, from taking inventory of current rights to recovering logins and domains, transitioning to ongoing maintenance, and handling full renewals if necessary.








