Giving a developer access to your site without handing over your password

You do not need to give the password of your account to whoever builds your site. There are smaller accesses that are enough for the job, that you can switch off when they finish, and that keep your invoices, your domains and the rest of the account out of reach. The rule is to give the minimum needed, to each person, for a while.

What to give, by kind of job

The job is… Give them… Do not give…
Editing pages and posts in WordPress A WordPress user, with the Editor role if that is enough, or Administrator if they will install plugins and themes The Meu Interweb or cPanel password
Uploading files to the site Their own FTP (or SFTP) account, limited to one folder. See FTP accounts and connecting with FileZilla and SFTP instead of FTP. Access to the whole cPanel
Working with code and versions A Git repository connected to cPanel. See publishing your site from a repository. Access to the account to do it
Touching e-mail, databases, DNS or backups Only when it is really needed, and for a short while: either give the cPanel access, or you do the step they tell you Permanent access
Handling invoices or domains for you A Meu Interweb sub-account with only the permissions you choose. See how to manage sub-accounts. Your personal login

Before, during and after

1 Before: take a copy. Even from someone you trust. A copy of the files and the database, kept away from the site’s hosting, undoes any mistake. See making and keeping your own backup.
2 Before: say what they may and may not touch. In writing, on the ticket or in a message. “The new site in the test folder, not the one that is live” saves headaches.
3 Before: preferably on a test site. Handing over access is safer with a copy to experiment on, which is later moved live. See a test site before touching what is live.
4 During: named accesses. One user per person, in their name, never a password shared among several. That way you know who did what, and you can remove one without affecting the others.
5 After: remove everything. Delete the WordPress user, the FTP account and the sub-account, and change any password they got to see. Ask for a list of what was installed or changed.
Be wary of “give me the password and I will sort everything”. Whoever asks for the login of the account (and not only the site) can pay, delete, transfer and cancel. If a provider insists, ask which part of the work needs it: there is almost always a smaller access that will do.
Do not send passwords by e-mail or in an ordinary message. Use a password manager that can share an item, or agree one password by phone and send the other in writing. Our team will never ask you for yours; when we need to diagnose, we go in from the server side. See how far our support goes.

Want help deciding which access to give? Tell us what work is going to be done.

Open a support ticket

SEE ALSO

How to manage sub-accounts

FTP accounts and connecting with FileZilla

Git in cPanel: publishing your site from a repository

Making and keeping your own backup, and testing that it works

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $5.36/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?