Find out exactly how bad it is, before you spend a penny fixing it.
If your platform is critical to the business but nobody fully understands it any more, the worst position to be in is guessing. You can't plan around a risk you can't see, and you can't brief a developer on a problem you can't describe. The audit is the smallest possible commitment that still gives you something worth having: a clear, honest picture of what you own and what it needs.
It is fixed price, fixed scope, and fixed timescale. You know exactly what it costs and exactly what you get, before I start. Even if you never hire me again, you walk away knowing precisely where you stand.
What I review
Codebase and technical debt — a full analysis of the application: structure, test coverage, documentation, and the real technical debt hiding in the parts nobody wants to touch.
Security and vulnerabilities — SQL injection, XSS, CSRF, and authentication weaknesses, plus a dependency and vulnerability assessment across PHP, framework, and libraries.
Server and infrastructure — disk space, memory limits and timeouts, error logs, backup status, and PHP version currency. The quiet problems that accumulate until something finally gives.
Performance bottlenecks — slow queries, missing caching, and the specific things making the platform feel sluggish.
What's in the report
You get a plain-English report, written for the person who signs off the budget rather than the person who writes the code. It follows the same structure every time:
1. Executive summary — the headline risks in one page, no jargon.
2. Security findings — what could be exploited, and how urgent each one is.
3. Infrastructure and stability — disk, memory, backups, error logs, PHP version.
4. Technical debt and maintainability — how hard the platform is to change safely.
5. Prioritised, costed action plan — every finding ranked by risk, with a realistic estimate against it, so you can decide what to fix now, what to schedule, and what to leave.
Price and timescale
The Platform Security & Health Audit is £1,950, delivered within two weeks. Fixed price, fixed scope. If the audit surfaces critical items, I can follow it with an optional, separately-scoped hardening sprint to fix them, but that is your decision to make once you have the report in hand.
The audit is the natural first step. It scopes any modernisation work honestly, so nothing is ever cold-quoted, and it establishes the baseline a support retainer picks up from. Start here, and the rest of the journey is planned around what is actually there, not what anyone guessed.
Next step
With the report in hand, the next stage is Modernise: legacy PHP to Laravel, scoped directly from what the audit found.