A custom-code handoff needs more than the installed files
The next maintainer needs a traceable connection between the installed customization and the delivered source, together with the actual dependencies, build or deployment steps and change notes needed to maintain it. Record what an authorized person can retrieve and what evidence links it to the installed release. A folder copy or repository link alone does not establish that connection. Keep missing steps and unverified reproducibility explicit, and handle credentials through an authorized secure route rather than in the handoff worksheet.
For: A research-only merchant handing an existing store customization to the next authorized maintainer.
Name the installed customization and the behavior it supplies
Start with the store function the code actually changes and the installed location identified by the current maintainer. Record the plugin, theme override or other named customization and the version or release reference available for it. Avoid describing the handoff as the entire website when the deliverable is one checkout behavior.
WooCommerce’s system status report lists platform versions, active plugins, theme details and template overrides. Use those entries to establish the installation being discussed. The report is a snapshot: it cannot supply the source history, explain every private change or establish which delivery package produced the installed code.
Ask for a concrete link between the delivered source and installed release. This might be a recorded commit or release reference tied to the deployment record, with any changes made directly on the site listed separately. Use the evidence that actually exists. A matching label is useful identification, but if nobody can show how the source relates to the installed files, record that relationship as unverified.
Check the package an authorized maintainer can actually use
Locate the editable source and confirm that the next maintainer can retrieve it through authorized access. Record the repository or archive reference, the relevant revision and the delivery date. Where the installed output was generated from other files, request those source files and the existing instructions used to produce it. Do not assume the installed output alone is the agreed source delivery.
Read the instructions for the specific customization. They should identify the required tools and versions, dependency records, configuration prerequisites, actual build steps if there is a build, generated output location and deployment destination. If the delivered code is edited and deployed directly without a build step, document that actual process instead of inventing one. The objective is to let the next maintainer identify the next real action and what it depends on.
Check which dependencies can be retrieved by the merchant or its authorized maintainer. If a private package, paid extension or agency-controlled service is required, record its legitimate access owner and where its entitlement is documented. Possession of custom source does not establish rights to every dependency. Refer unresolved extension entitlement to the vendor-specific license record.
Separate a maintenance package from a recovery set
WordPress’s backup guidance says a typical complete restore needs both files and database from a consistent set. Downloading the WordPress directory ordinarily does not copy the database. A source repository therefore cannot, by itself, establish recovery of the store’s configuration, orders or other database contents.
Keep the code handoff and recovery record connected but distinct. The code handoff identifies how the customization can be understood, changed and delivered. The recovery record identifies the actual consistent backup set, its age, scope and authorized restore owner. A host’s backup offering does not establish the retention, retrieval time or recoverability of this particular account.
Ask the outgoing maintainer to identify any configuration or data change required by the delivered release and where that change is documented. Preserve the existing change notes and any genuine build or deployment evidence. Do not label the package reproducible because instructions exist. If no authorized maintainer has verified those instructions against the corresponding source and output, write that verification is outstanding. Reading the package does not authorize a production build, deployment or restoration.
Convert missing material into a precise handoff decision
Classify each item as received and accessible, received but not yet verified, or missing. A source reference that the next maintainer cannot open belongs in the unresolved access record. Instructions referring to an absent dependency belong in the missing dependency record. Code that cannot be linked to the installed release needs that association clarified before it can support a confident maintenance decision.
Compare those gaps with the actual delivery agreement and the next change the merchant intends to authorize. Name the missing item, who can supply it and which maintenance action remains blocked. Do not turn an unknown contractual obligation into an assertion that all source must be transferred. The practical outcome is a usable inventory of what is available and an exact request for what is needed.
For a Prism checkout-review consultation, describe the public site, research-only products, affected customization and missing handoff item. Request the specific review or coordination assistance required. Prism’s published work includes storefront review and help with provider website questions; scope, responsibilities, fees and terms are confirmed before work. The public inquiry is not a place to upload the code archive, database or credentials, and it does not buy an implementation or submit a processing application.
Custom-code delivery record
Complete one record for each installed customization. Use genuine source, release and access records. Distinguish a delivered document from verified ability to use it; leave missing evidence visible. Record secure-storage references and responsible roles, never secret values or customer data.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Custom-code delivery record. The last column is for temporary notes.
Delivery item
Evidence the handoff should identify
How to judge the record
Your finding
Installed customization
Evidence the handoff should identifyAffected store behavior, installed location and available version or release reference.
How to judge the recordNames the actual code to maintain rather than a generic website folder.
Source reference
Evidence the handoff should identifyAuthorized repository or archive location, exact revision and whether the next maintainer can retrieve it.
How to judge the recordA link without usable authorized access is an unresolved delivery item.
Connection to installed release
Evidence the handoff should identifyExisting deployment reference and any separately recorded direct edits.
How to judge the recordUnmatched source and installed output leave the delivery relationship unverified.
Build or deployment instructions
Evidence the handoff should identifyRequired tools, actual steps, output location and destination; note when no build is used.
How to judge the recordThe instructions should describe the delivered customization’s real process.
Dependency record
Evidence the handoff should identifyVersions and existing dependency files, plus legitimate access owners for private or licensed inputs.
How to judge the recordAn unavailable dependency can prevent using otherwise delivered source.
Configuration and change notes
Evidence the handoff should identifyRequired setting names, data changes and secure credential-storage owner, without values.
How to judge the recordDistinguishes documented prerequisites from undocumented setup knowledge.
Recovery reference
Evidence the handoff should identifyConsistent files-and-database backup reference, scope, age and authorized restore owner.
How to judge the recordSource delivery alone does not establish recovery of the operating store.
Existing verification evidence
Evidence the handoff should identifyGenuine build or deployment record tied to the source revision, or verification outstanding.
How to judge the recordWritten steps do not by themselves establish reproducibility.
Missing handoff item
Evidence the handoff should identifySpecific absent material, person able to supply it and maintenance action awaiting it.
How to judge the recordSupports a bounded request without declaring an incomplete package maintainable.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
This record does not establish intellectual-property ownership, contractual delivery rights or permission to deploy; use the actual agreement and authorized access.
Source, backup and existing deployment records establish different facts. No reproducibility or recoverability is promised without corresponding evidence.
Keep API secrets, passwords, private tokens, customer records and database contents out of the worksheet and public inquiry.
WooCommerce system status report — checked 2026-09-21. The report lists installed platform and plugin versions, theme details, template overrides and assigned store pages, providing an installation snapshot for the customization inventory.
WordPress backups — checked 2026-09-29. A typical complete restore needs a consistent database-and-files set; downloading the WordPress directory ordinarily does not include the database. A host backup offering does not establish account-specific retention or recoverability.
Prism solutions — checked 2026-09-21. Public support includes storefront review, processing preparation and help with provider website questions. Requested scope, fees and terms are discussed before work.
Prism contact — checked 2026-09-21. The form requests the website, products and question and excludes passwords and customer records. Email follow-up does not make the inquiry an appointment, service purchase or processing application.