Find out what is inside the system you depend on.
A senior read, in one week. A one-week read of the code, hosting and data behind a system you already run. You keep a written report: what is broken, fragile or fine, where it is open to attack, and a fixed price if there is work.
Why a review first
Why read before we touch?
We change nothing. Senior engineers read the code, the server setup, how the data is stored and the outside services it uses. Then they rank what they find.
You keep the report whether or not you hire us. The closest public example is BM Mobil, a WordPress site hacked again and again. We searched it for hidden ways back in (backdoors) and made it secure without a rebuild.
Read first. Rank the risks. Price the work.
1 week
System review, delivered within a week
2018
Building and running production software since
7
Products of our own we run in production
50+
WordPress and WooCommerce sites run in production
When a review comes first
You depend on a system nobody can vouch for
Each of these starts with a read of the code, hosting and data. The report then says which work follows.
The developer who built it has gone, and nobody knows how it is put together.
Takeover & Handover
02The site was hacked once. We cleaned it up, but is it really clean?
Maintenance & Hosting
03Three agencies quoted for the same fix, and the numbers are miles apart.
Scope & Fixed Quote
04The app came from Lovable, Bolt or Cursor, and real users are on the way.
Project Rescue
What you get
A written report you keep, whoever does the work
Written System Report
Each part marked broken, fragile or fine, with the reason, plus technical notes for your next developer. Fine tells you what not to spend money on.
Security Findings, Ranked
Who has access, passwords or keys left in plain sight, outdated plugins and packages, server and HTTPS settings, file uploads, and whether the server checks who is allowed to do what.
Backup and Recovery Check
Whether a backup exists and can actually be restored. One never restored is a hope, not a backup.
Fixed Price, If There Is Work
One price for the fixes or next build, credited if you start within 30 days. The report also says where AI would earn its place, and where it would not.
Who it is for
For systems you run but cannot see inside
A good fit
- The builder is gone or not answering, and you want an independent picture before a new developer quotes.
- The site has been hacked before, or handles payments and customer data.
- The code came from Lovable, Bolt, Cursor or Replit and needs a senior read before real users arrive.
Not a fit yet
-
Nothing Is Built Yet
Start with Discovery and go to Scope & Fixed Quote. Under attack right now? Say so in Discovery. Stopping an attack is urgent work, not a report.
-
You Need a Formal Pen Test or Certificate
A penetration test (pen test) or a certificate such as ISO 27001, SOC 2 or PCI DSS needs an accredited firm. This review makes that test cheaper to pass.
How the week runs
Read access in, a ranked report out
-
Step 01
Access
You give us read-only access to the code, hosting, database and admin. We change nothing.
-
Step 02
Read
Senior engineers read the code, server setup, data structure and services. On PHP projects, code-checking tools (PHPStan / Larastan) help.
-
Step 03
Report
Within a week of access: the findings, most serious first, and the fixed price if there is work.
-
Step 04
Walk-Through
We go through it so you can act on it, with anyone.
In production
The report comes from people who run systems
Systems we run are monitored on our public status page.
FAQ