StackRefit Audit

Know what is fragile before anyone touches production.

A fixed-scope technical audit for legacy PHP, WordPress, Laravel, and Linux systems. We map the stack, surface risks, and give you a practical modernization roadmap without starting a rewrite.

From €750 · fixed scope3-7 days · read-onlyOptional · white-label report
Stack — beforefragile
AppPHP 7.4 · undocumented
FrameworkLaravel 6 · 4 majors behind
CMS / PluginsWP + 38 plugins, 12 outdated
DBMySQL 5.7 · EOL
ServerUbuntu 18.04 · EOL
Backupsuntested
Deploymanual SFTP
Who it is for

Useful when the risk is real, but the path is unclear.

The audit is built for systems that still matter commercially but no longer feel easy to change.

01

Agencies

Inherited client systems that need a credible quote, rescue path, or white-label technical read.

02

SaaS owners

Revenue-critical products where a rewrite feels expensive but the current stack feels risky.

03

Operators

Old web systems with unclear backups, server history, deploy process, or developer ownership.

Scope

What we check.

The work is read-only and focused on the production risk surface: the codebase, runtime, dependencies, server, backups, deploy flow, and knowledge gaps.

Runtime & framework

PHP, framework, CMS, database, server OS, and known end-of-life exposure.

Dependencies

Composer packages, WordPress plugins, themes, system packages, and obvious abandoned parts.

Backups & restore

Whether backups exist, where they live, and whether a restore path is credible.

Deploy process

How changes move from developer machine to production, including rollback confidence.

Maintainability

Where knowledge is concentrated, where documentation is missing, and where change feels dangerous.

Security posture

Configuration and version-risk observations. This is not a penetration test.

Deliverables

What you get back.

The output is designed to support a decision: stabilize, upgrade, hand over, care for the system, or leave it alone for now.

  • 01Stack inventory covering app, CMS/framework, runtime, database, server, backups, and deploy path
  • 02Version and end-of-life risk register with severity and practical next steps
  • 03Backup and restore confidence notes
  • 04Maintainability and documentation findings
  • 05Security and configuration observations from read-only review
  • 0630 / 60 / 90-day modernization roadmap
  • 07Optional white-label report for agencies
Timeline

A typical 3-7 business day audit.

Small systems can move faster. Multi-app or agency white-label work may need extra scoping before the clock starts.

Day 0

Scope & access

Confirm the system boundary, NDA needs, and read-only access path.

Day 1-2

Inventory

Map runtime versions, CMS/framework, packages, hosting, backup jobs, and deploy flow.

Day 3-4

Risk register

Separate urgent risk from background entropy, then size likely remediation paths.

Day 5

Roadmap

Turn findings into a practical 30 / 60 / 90-day plan with owner and effort notes.

Day 6-7

Review

Deliver the report and walk through priority decisions in plain language.

Pricing

Fixed-scope first. Implementation later.

The audit starts from €750. Final scope depends on how many applications, environments, repositories, and handover constraints are involved.

FAQ

Common audit questions.

Do you touch production?

No. The audit is read-only. Any production change belongs in a separately scoped sprint.

Do you need SSH or admin access?

Usually yes, but read-only is enough for the audit. If access is sensitive, we agree the handover path first.

Is this a security audit?

No. We include security posture observations, but this is not penetration testing or active vulnerability exploitation.

Can agencies white-label it?

Yes. The report can be prepared behind your brand, with no client contact unless you invite us in.

What happens after the audit?

You can stop with the report, hand it to your team, or scope a stabilization sprint, upgrade, handover, or care plan.

What if we already know the stack is bad?

That is exactly when the audit helps. It turns a vague risky system into a prioritized plan that can be quoted and sequenced.

Start with an audit

Need a second opinion before you quote, rewrite, or upgrade?

Send the rough stack and what is worrying you. We will reply with whether the audit is a fit and what access would be needed.

Request an audit →