StackRefit Audit

Know what is fragile before anyone touches production.

A fixed-scope technical audit for legacy PHP, WordPress, Laravel, and Linux systems. We map the stack, surface risks, and give you a practical modernization roadmap without starting a rewrite.

A fixed-scope legacy PHP, Laravel, WordPress, and Linux stack audit.

From €750 · fixed scope3-7 days · read-onlyOptional · white-label report
Stack — beforefragile
AppPHP 7.4 · undocumented
FrameworkLaravel 6 · 4 majors behind
CMS / PluginsWP + 38 plugins, 12 outdated
DBMySQL 5.7 · EOL
ServerUbuntu 18.04 · EOL
Backupsuntested
Deploymanual SFTP
Who it is for

Useful when the risk is real, but the path is unclear.

The audit is built for systems that still matter commercially but no longer feel easy to change.

01

Agencies

Inherited client systems that need a credible quote, rescue path, or white-label technical read.

02

SaaS owners

Revenue-critical products where a rewrite feels expensive but the current stack feels risky.

03

Operators

Old web systems with unclear backups, server history, deploy process, or developer ownership.

Scope

What we check.

The work is read-only and focused on the production risk surface: the codebase, runtime, dependencies, server, backups, deploy flow, and knowledge gaps.

Runtime & framework

PHP, framework, CMS, database, server OS, and known end-of-life exposure.

Dependencies

Composer packages, WordPress plugins, themes, system packages, and obvious abandoned parts.

Backups & restore

Whether backups exist, where they live, and whether a restore path is credible.

Deploy process

How changes move from developer machine to production, including rollback confidence.

Maintainability

Where knowledge is concentrated, where documentation is missing, and where change feels dangerous.

Security posture

Configuration and version-risk observations. This is not a penetration test.

Deliverables

What you get back.

The output is designed to support a decision: stabilize, upgrade, hand over, care for the system, or leave it alone for now.

  • 01Stack inventory covering app, CMS/framework, runtime, database, server, backups, and deploy path
  • 02Version and end-of-life risk register with severity and practical next steps
  • 03Backup and restore confidence notes
  • 04Maintainability and documentation findings
  • 05Security and configuration observations from read-only review
  • 0630 / 60 / 90-day modernization roadmap
  • 07Optional white-label report for agencies
Timeline

A typical 3-7 business day audit.

Small systems can move faster. Multi-app or agency white-label work may need extra scoping before the clock starts.

Day 0

Scope & access

Confirm the system boundary, NDA needs, and read-only access path.

Day 1-2

Inventory

Map runtime versions, CMS/framework, packages, hosting, backup jobs, and deploy flow.

Day 3-4

Risk register

Separate urgent risk from background entropy, then size likely remediation paths.

Day 5

Roadmap

Turn findings into a practical 30 / 60 / 90-day plan with owner and effort notes.

Day 6-7

Review

Deliver the report and walk through priority decisions in plain language.

Pricing

Three concrete audit packages.

Most inherited agency systems start with the Agency Audit at €1,250. Audit Lite is for small, single-site systems.

01 / 03

Audit Lite

€750EUR fixed tier
Best for

Small WordPress/PHP site

Scope
  • 1 app
  • 1 repo or CMS
  • No complex VPS review
  • Short report
What moves it up

Good fit when the site has one clear production surface and no custom hosting puzzle.

Agency resale angle

Entry-level inherited-site audit before quoting fixes.

02 / 03

Agency Audit

€1,250EUR fixed tier
Best for

Typical inherited WP/WooCommerce/Laravel system

Scope
  • App + hosting review
  • Backups and restore confidence
  • Deploy flow review
  • White-label report
What moves it up

Use this when the agency needs a client-ready deliverable and the hosting/deploy path matters.

Agency resale angle

White-label technical audit and 30/60/90 roadmap.

03 / 03

Stack Audit Plus

Stack Audit Plus: €1,750–€2,500 for most systems; larger estates quoted after scoping.Scoped range
Best for

Multi-app, VPS-heavy, custom PHP/Laravel

Scope
  • Deeper infrastructure review
  • Integrations and restore path
  • Implementation estimate
  • Expanded roadmap
What moves it up

Triggered by multiple apps, custom VPS setup, critical integrations, unclear restore paths, or estimate-ready remediation scope.

Agency resale angle

Senior technical discovery for a risky takeover or larger modernization proposal.

FAQ

Common audit questions.

Do you touch production?

No. The audit is read-only. Any urgent production change belongs in a separately scoped sprint and needs backup confirmation, named authorization, and a rollback plan.

Do you need SSH or admin access?

Usually yes, but read-only is enough for the audit. We do not accept production access unless a named responsible owner has authorized it.

Is this a security audit?

No. We include security posture observations, but this is not penetration testing, compliance certification, active vulnerability exploitation, or incident response.

Can agencies white-label it?

Yes. The report can be prepared behind your brand, with no client contact unless you invite us in.

Which audit package fits?

Most inherited agency systems start with the Agency Audit at €1,250. Audit Lite is for small, single-site systems. Stack Audit Plus is for multi-app, VPS-heavy, or integration-heavy systems.

Do you use external AI tools on client data?

Not without written approval. Client code, logs, credentials, and personal data are not processed through external AI tools unless the scope explicitly allows it.

What happens after the audit?

You can stop with the report, hand it to your team, or scope a stabilization sprint, upgrade, handover, or care plan.

When would you decline or refer the work?

We do not take over systems where no responsible owner can approve access and changes. Pen testing, compliance certification, active breach response, and legal review belong with specialist providers.

What if we already know the stack is bad?

That is exactly when the audit helps. It turns a vague risky system into a prioritized plan that can be quoted and sequenced.

Start with an audit

Need a second opinion before you quote, rewrite, or upgrade?

See scope, access needed, deliverables, timeline, and pricing.

Get the audit outline →