Skip to content
Custom websites

Web Developer Disappeared? How to Take Back Your Website, Domain and Code

You paid for the website. But only your developer has the admin password, the domain is registered in their name, and they haven’t answered an email in a month. It’s a common situation, and it can be fixed. Here’s what to take back first, what the rules allow, how to find out what your site is built on, and what to do the moment you have access.

Website takeover cover: registrars must release the transfer code within 5 days, 37.6% of WordPress sites run unsupported PHP, 71.9% of EU firms with 10+ staff use external ICT suppliers

According to Eurostat, 79% of EU businesses with at least ten employees have a website, and 71.9% relied on external suppliers for ICT work in 2024. In 2018, the last time Eurostat asked, half of all EU businesses of that size had their website developed mainly by external suppliers. For many companies, someone else holds the keys to their website.

That’s fine while the developer answers the phone. It becomes a problem when a freelancer vanishes, an agency goes under, or the relationship turns sour. Almost every one of these situations can be solved, as long as you do things in the right order.

01Start with an inventory of everything your website depends on

A website isn’t a single file. It’s a domain, DNS records, a server, a database, code, an admin panel and a handful of accounts with other services. Each part can be registered to someone else, and each one has to be taken over separately. Before you contact anyone, make a list.

WhatHow to find out who controls itWho it should belong to
DomainA lookup on ICANN Lookup or your country’s registry, registrant fieldYour company, as the registrant
DNSName servers in the domain record, then the account that manages themYour account with the registrar or DNS provider
Hosting and serverInvoices, emails with logins, the site’s IP addressContract and payments in your company’s name
Source codeA repository (GitHub, GitLab, Bitbucket) or just files on the serverA repository in your own account
Admin panelThe site’s login page, the list of usersYour own administrator account, not a shared one
Company emailMX records in DNS, the email providerYour company, or you risk losing email
Analytics and Google accountsGoogle Analytics, Tag Manager, Search ConsoleOwned by your Google account
Payments and integrationsPayment gateway, CRM, API keys, email marketing toolAccounts and keys in your company’s name
Print the table and write down who has access to each item today. You’ll often find you already control half of it.

The first row matters most. Whoever controls the domain controls the website and the email. That’s why we start there.

02The domain: transferring to a new registrar or a new owner

Look the domain up and check the registrant, also called the registered name holder. For .com, .net and other generic domains, the rules come from ICANN. Country domains such as .uk, .de or .cz have their own registries and rules, so check with yours. The two situations below cover most cases.

You are the registrant: just switch registrars

If your company is the registrant, you’re in a strong position. Under the ICANN Transfer Policy, the registered name holder is the only party that can approve or deny a transfer. The admin contact, which is often the developer, no longer has that right. Ask the current registrar for the AuthInfo code (also called an EPP or transfer code) and give it to your new registrar. The registrar has to provide it within 5 calendar days of your request and can’t refuse just because of a payment dispute between you and the registrar.

Note that a registrar may deny a transfer within 60 days of the domain’s registration or its last transfer.

The developer is the registrant: change of registrant

This is harder. ICANN itself warns that a developer “may have registered the domain name using their own contact details (even if you have paid them to register and manage the domain name)”. In that case, ICANN suggests giving the registrar proof of your payment to the developer to show that you should be the registrant. Collect invoices, bank statements and the contract before you contact the registrar.

Two things to know before you start:

  • After a change of registrant, a 60-day transfer lock applies, unless the registrar offered an opt-out and the registrant used it beforehand. If you also want to move to a new registrar, ICANN suggests considering completing the transfer first and changing the contact details after.
  • UDRP won’t help with a contract dispute. The UDRP is for trademark holders facing a bad-faith registration. All other disputes are resolved “through any court, arbitration or other proceeding that may be available”.

Before you escalate, try asking nicely. Often the developer registered the domain in their own name simply out of convenience and will sign it over once they get a clear request with the forms ready.

Keep an eye on the expiry date

Under ICANN’s expired registration rules, the registrar has to send reminders about a month and about a week before expiry, and one more within five days after. After that it may delete the domain at any time. A deleted generic domain then enters a 30-day Redemption Grace Period, when only the registrar that deleted it can restore it. Only the registrant at expiry can renew. If that’s your developer and they’ve gone quiet, nobody else can renew it.

Timeline of an expiring generic domain under ICANN rules: reminders about a month and a week before expiry, the expiry date, one more notice within 5 days, the registrar may delete it at any time, then a 30-day Redemption Grace Period with no transfers
What happens to a .com or other generic domain that nobody renews, under ICANN’s Expired Registration Recovery Policy. Country domains follow their own rules.

03Hosting, database and email

Hosting is the second most common problem. If the developer pays for it and you pay the developer, your site runs on their account. Find out where the server is (a DNS lookup shows the site’s IP address, and an IP lookup shows which hosting company it belongs to) and ask for a complete backup: the site files and a database export.

If your business is in the EU or the UK and the site collects personal data, say through a contact form or a shop, a developer who handles that data on your behalf is a processor under GDPR (in the UK, UK GDPR). Article 28(3)(g) says the processor must, at your choice, delete or return all personal data after the service ends and delete existing copies, unless the law requires them to keep it. Quote this article in your request.

Email deserves its own plan. If your mailboxes are hosted by the same developer and you point the domain elsewhere, mail can stop arriving. Set up the new mailboxes first, move your mail, and only then change the MX records.

04Who owns the website code?

Paying for a website doesn’t automatically make you the owner of its code. The answer depends on your contract and on copyright law in your country, and the rules differ a lot.

  • United States. A commissioned work only counts as a “work made for hire” if it falls into one of nine listed categories and both sides sign a written agreement saying so (U.S. Copyright Office, Circular 30). Software isn’t named on that list, so for code written by an outside developer you generally need a signed assignment of copyright.
  • European Union. The Software Directive (Article 5) lets the lawful acquirer of a program fix errors in it without the rightholder’s permission where this is necessary to use the program for its intended purpose, unless the contract has specific provisions on it, and a contract can’t stop you making a necessary backup copy. Wider changes need a licence that allows them.
  • Some countries lean towards the client. The Czech and Slovak copyright acts, for example, treat software created to order as employee work, so unless the contract says otherwise, the client exercises the economic rights. Lawyers still disagree on how this applies when the code was written by an agency’s staff.

Don’t count on a legal right to receive the source code. Only the contract reliably guarantees it. Make it the first item you check in any new contract.

This section is an overview, not legal advice. If the developer refuses to release the code or the domain and a lot is at stake, take your contract, invoices and emails to a lawyer who specialises in IT law.

05What your site is built on: a short history of web technology

How hard a takeover will be depends a lot on how the site was built. A PHP site a friend made twenty years ago is a different job from a shop on a website builder or a React app. Several generations of technology have come and gone in the past 35 years, and business websites still run on all of them.

Timeline of web technologies: 1991 the web at CERN, 1995 PHP, 1996 Flash, 2002 ASP.NET, 2003 WordPress, 2006 jQuery, Wix and Shopify, 2008 Nette, 2009 Node.js, 2013 React, 2016 Next.js
When the technologies you’ll find behind business websites appeared. Years from CERN and the projects’ own sites; Flash, ASP.NET, Node.js and React from Wikipedia.

PHP still dominates. According to W3Techs, it powers 69.8% of websites whose server-side language can be detected. JavaScript (Node.js) is second, having overtaken Ruby in July 2026.

Server-side languages of websites (%)
  • PHP69.8%
  • JavaScript (Node.js)7.5%
  • Ruby7.1%
  • Java5.5%
  • Scala5.1%
  • ASP.NET4.2%
  • Static files2.1%
  • Python1.1%

Share of websites whose server-side language W3Techs can detect. Source: W3Techs, as of 27 September 2026.

How do you tell what you have? Open the site, right-click and choose View Page Source. File paths and cookie names give a lot away. Here’s a quick guide.

TechnologySinceHow to spot itWhat to watch out for
Static HTML1991Pages end in .html, no admin panelEasy to take over, the files are all you need
Custom PHP, no framework1995URLs end in .php, a home-made CMSWithout documentation, only the author knows the code
Flash1996.swf filesHasn’t played since 12 January 2021, needs replacing
ASP and ASP.NET1996 and 2002.asp or .aspx URLs, ASP.NET_SessionId cookieNeeds Windows hosting and a .NET developer
Java1996.jsp or .do URLs, JSESSIONID cookieHeavier to run, fewer agencies to choose from
WordPress2003/wp-content/ and /wp-includes/ paths in the sourceOld plugins and PHP versions
Joomla and Drupal2005 and 2001/administrator/ path or a Drupal generator tagJoomla 3 and Drupal 7 no longer get security fixes
Laravel, Symfony, Nette2011, 2005, 2008.twig or .latte templates on the server, laravel_session cookieA solid base, but you need the source code
Ruby on Rails, Django2004 and 2005csrftoken cookie for Django, a Gemfile or manage.py on the serverSmaller pool of developers in many markets
React, Vue, Next.js2013, 2014, 2016/_next/ (Next.js) or /_nuxt/ (Nuxt) paths in the sourceHard to change without the repository and deployment setup
Website builders (Wix, Shopify, Webflow)2006 onwardsThe footer or image URLs on the builder’s domainThe site is tied to an account; you won’t get the code
Years from the projects’ own sites: PHP (php.net), WordPress, Drupal, Django, Wix, Shopify, Nette, Webflow and Next.js. Other years from Wikipedia. Flash end of life per Adobe.

WordPress is by far the most common CMS. W3Techs puts it on 40.2% of all websites, which is 58.7% of sites that use a content management system it tracks.

CMS market share (%)
  • WordPress58.7%
  • Shopify7.8%
  • Wix6.2%
  • Squarespace3.6%
  • Joomla1.6%
  • Webflow1.2%
  • Drupal0.9%

Share among websites that use a content management system W3Techs tracks. Source: W3Techs, as of 27 September 2026.

06Five situations you may be in, and what to do

1. The freelancer vanished, but you have the logins

The best case. Change every password straight away, remove their accounts from the admin panel, hosting and Google services, and download a backup. Then get an audit so you know what’s in the code.

2. The developer won’t reply and only they have access

Send a written request with a specific list of what you want handed over and a reasonable deadline. Use a method that gives you proof of delivery, such as recorded delivery, or an email followed by a letter, and keep copies of everything. If this ever goes to court, a clear request and a documented silence will count in your favour.

3. The developer is holding the site hostage

They want an extra payment you don’t agree with and won’t release anything until then. Keep the money dispute separate from keeping the site running. If the domain is in your name, you can move it to another registrar without them. For the code, point to your contract; for personal data in the EU or UK, also point to GDPR. If the disputed amount is small, paying and then disputing it can cost less than weeks of downtime.

4. The agency has closed down or gone bankrupt

Check your country’s company register and insolvency register. If insolvency proceedings are running, an administrator or trustee usually controls the company’s assets, so send your request to them. If the company was dissolved, try to find the developer who actually wrote the site.

5. The site runs on the agency’s own system or a website builder

Some agencies have their own CMS and only rent it to clients. Sites on Wix, Squarespace or Shopify likewise exist only inside an account. You won’t get the code in these cases, only the account and the content. Check whose name the account is in, and export your text, images, products and orders. This is often the moment when rebuilding the site makes sense.

Overview of five website takeover situations and the first step in each: change passwords, send a written request with proof of delivery, move a domain registered to you, contact the insolvency administrator, take over the account and export content
The five most common situations and the first step to take in each.

07Website handover checklist, step by step

  1. Back up what you can from outside. Wget with the --mirror option downloads the public part of the site: HTML, images and styles, but not the database or server code. You can also save individual pages to the Internet Archive.
  2. Take inventory using the table above and find out who the domain registrant is.
  3. Write and send a formal request with proof of delivery. List the logins and materials you need and give a deadline, such as 14 days.
  4. Take back the domain, either by switching registrars or through a change of registrant.
  5. Move hosting and email into your company’s account. New mailboxes first, then the DNS change.
  6. Put the code in your own repository and get written instructions for running and deploying the site.
  7. Change every password and key the developer knew, and remove their access.
  8. Get a technical audit: language and CMS versions, plugins, backups, security.
  9. Decide what’s next: maintain, fix step by step, or rebuild.

The request doesn’t have to be complicated. It just needs to be specific and have a deadline. Something like this:

text
Subject: Request to hand over our website and access

Hello [name],

Under our agreement dated [date], you built and maintained our website [address]. We are ending the arrangement and ask you to hand over:

1. the transfer (AuthInfo) code for [domain], or your signature on the change of registrant form,
2. hosting access and a full backup of the files and database,
3. the source code, with instructions for running and deploying it,
4. administrator access to the website,
5. any personal data you process on our behalf, under Article 28(3)(g) GDPR (if applicable).

Please send everything by [date, e.g. 14 days from receipt]. Thank you.

[name, role, company]

You can see how we take over a site on our how we work page. We usually secure it first and then decide on next steps together.

08Right after the takeover: security and outdated software

A site nobody has looked after is often stuck on an old version of PHP. WordPress’s own statistics show 37.6% of WordPress sites on PHP 8.1 or older. According to php.net, those versions no longer get security fixes. PHP 7.4 alone, unsupported since November 2022, still runs 16.7% of WordPress sites. And PHP 8.2 reaches end of life on 31 December 2026.

WordPress sites by PHP version (%)
  • PHP 7.3 and older5.8%
  • PHP 7.4 (unsupported since 2022)16.7%
  • PHP 8.0 (unsupported since 2023)4.0%
  • PHP 8.1 (unsupported since end of 2025)11.1%
  • PHP 8.2 (supported until 31 Dec 2026)24.5%
  • PHP 8.325.7%
  • PHP 8.48.8%
  • PHP 8.53.3%

Source: WordPress.org statistics, downloaded 27 September 2026; end of life dates from php.net. Highlighted versions no longer receive security fixes.

With WordPress, the biggest risk is plugins. Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, 91% of them in plugins. For 46% of them, no fix was available when the flaw was made public. WordPress core had only six.

After the takeover, go through this list:

  • Change passwords for the admin panel, hosting, database, FTP and SSH, and rotate every API key (payment gateway, email marketing, maps).
  • Delete the developer’s accounts everywhere. The UK’s NCSC advises that you should be able to revoke third-party access whenever necessary.
  • Check the versions of PHP, your CMS and plugins against what’s currently supported.
  • Make sure backups run and that you can actually restore one.
  • Review the libraries in the code. Outdated and unmaintained components fall under A03 Software Supply Chain Failures in the OWASP Top 10:2025.

For a full checklist, see our web app security checklist. How attackers abuse libraries and leaked keys is covered in npm supply chain attacks and API keys.

09Fix it or rebuild it?

After the audit you’ll know what you have. The decision is usually simpler than it looks.

SituationSensible choiceWhy
Modern framework, you have the code, only docs are missingMaintain and developA new developer can get up to speed quickly
WordPress with dozens of plugins on old PHPUpdate or rebuildDepends on how many plugins can be replaced and what upkeep costs
Custom PHP, no framework, no documentationProbably rebuildEvery change is expensive and risky
Flash, Joomla 3, Drupal 7, AngularJSRebuildNo security support for the technology
Agency’s rented CMS or a website builderTake the content and rebuild on your own codeYou won’t get the code and the dependency would remain
End of support: Flash per Adobe (31 Dec 2020), Joomla 3 per Joomla (17 Aug 2023), Drupal 7 per Drupal (5 Jan 2025), AngularJS per docs.angularjs.org (January 2022).

If you go for a new site, check first whether it’s built on a template, and read about why WordPress templates become a trap for growing businesses. When you switch, set up redirects from the old URLs, or you risk losing your search rankings.

10How to avoid this next time

Most problems in this article could have been prevented by the contract and a few minutes of attention at launch. Next time, insist that:

  • the domain, hosting, email and Google accounts are in your company’s name from day one,
  • the contract includes a licence or assignment that lets you modify the site and hand it to another developer, with no time or territory limits,
  • the handover includes the source code in a repository in your account, plus instructions for running it,
  • the developer has their own logins that you can revoke at any time, not your passwords,
  • the contract covers the end of the relationship: what gets handed over, how fast and at what cost.

For larger systems, you can also agree on source code escrow. As EscrowTech describes it, a neutral third party holds the code and releases it when a condition in the agreement is met, for example when the vendor goes out of business or stops supporting the software. For the full list of contract points, see custom website development, step by step.

EU businesses with 10+ staff: websites and outside suppliers (%)
  • Have a website (2025)79.0%
  • ICT done by external suppliers (2024)71.9%
  • Website built mainly externally (2018)50.3%

Source: Eurostat datasets isoc_ciweb and isoc_ske_fct, EU 27. Eurostat last measured outsourced website development in 2018.

11Frequently asked questions

Can my web developer refuse to give me the domain transfer code?

Not if you’re the registrant of a generic domain such as .com. Under ICANN’s Transfer Policy, the registrar must give the registered name holder the AuthInfo code within 5 calendar days of the request. Ask the registrar directly; you don’t need the developer. Country domains have their own rules.

What if the domain is registered in the developer’s name?

Then you need a change of registrant. ICANN suggests showing the registrar proof that you paid the developer for the domain. If that doesn’t work, the remaining routes are agreement, court or arbitration. UDRP only covers trademark cases involving bad faith.

Do I own the source code if I paid for the website?

Not automatically. It depends on your contract and your country’s copyright law. In the US, code written by an outside developer usually needs a signed assignment of copyright. Always put ownership or a licence, plus handover of the source code, in writing.

Can another developer work on code someone else wrote?

In the EU, the Software Directive lets the lawful acquirer of a program fix errors needed to use it, unless the contract has specific provisions on this. Whether an outside developer you hire can do that work for you, and any bigger changes, depends on your licence. If your contract doesn’t grant one, talk to a lawyer.

How long do I have when a domain expires?

For generic domains, the registrar may delete it at any time after expiry. After deletion there’s a 30-day Redemption Grace Period, during which only the registrar that deleted it can restore it. Country domains have their own timelines.

How do I find out what my website is built on?

View the page source in your browser. /wp-content/ paths mean WordPress, /_next/ means Next.js, .aspx means ASP.NET. For exact PHP and CMS versions you’ll need server or admin access.

How much does a website takeover cost?

It depends on the state of the site. A domain transfer usually costs no more than the registrar’s fee, while an audit and security work are billed by the hour. If the site runs on unsupported technology, rebuilding is often better value. See our pricing for guide prices.

12Sources

LISTIFY teamWebsites, apps and marketing from Prague since 2008

More articles

All articles →
Custom websitesSeptember 27, 2026 · 17 min read

Custom website development: benefits, costs and a 9-step guide

Custom websitesSeptember 27, 2026 · 15 min read

Why WordPress template websites become a trap for growing businesses

Online marketingSeptember 28, 2026 · 14 min read

How Much Should a Small Business Spend on Marketing? Work Out Your Budget in 10 Minutes

Share this page

By email

Got an idea? In 15 minutes, you'll know how to make it happen.

A short call, no sales pitch. We'll tell you what makes sense, what it will cost and how fast we can deliver it.

+420 771 166 199Mon to Fri, 8:30 a.m. to 4:00 p.m. (Prague time) · info@listify.cool

When should we call you?

Pick a day and a time window. We'll call you, and it takes about 15 minutes.

Day