Codebase Assessment: An Independent Review of Your App Before You Decide
A fixed-price, written review of your existing app: code quality, security basics, tests, dependencies, hosting and what it would take to finish, fix or upgrade it. For founders and agencies taking over or rescuing a project. From $520 ($400 founding), about 1–2 weeks. The fee is credited toward follow-on work.
See a sample report, proposal and weekly update- Price
- from $520
- Founding
- from $400
- Timeline
- ~1 week
- Format
- Fixed scope, fixed price
- Hours
- US Eastern Time, async
Who this is for.
A good fit if
- Founders whose developer or agency left mid-project
- Teams deciding whether to fix, finish, upgrade or rebuild
- Agencies taking over a client app they didn’t build
- Buyers checking an app before acquiring or funding it
Common triggers
- A developer disappeared and nobody knows what state the app is in
- Bugs keep coming back and estimates keep growing
- You’re about to hire a new developer or agency and want a baseline
- An upgrade or end-of-life deadline
Not a fit if
- You need a penetration test or a compliance certificate (this is a code review, not a pen test)
- The code is WordPress plugins or themes
- You want the problems fixed in the same fee (the report comes with a fixed quote for that)
What I do, and what you get.
What I do
- Read the code, git history, tests, dependencies and deploy setup
- Run automated checks: dependency vulnerabilities, secrets in the repo, static analysis, test run
- Check the basics of auth, access control, data handling and backups
- Review hosting and deploy (Standard)
- Rank what I find by risk and effort
- Recommend a path (fix, finish, upgrade, or rebuild in parts) with honest reasons
- Answer questions by email for 7 days
What you get
- Written report: a summary for non-technical readers, then details
- Prioritized fix list with effort estimates
- Dependency and end-of-life table
- Architecture sketch of how the app fits together
- Recommended path and a fixed quote for the next step
- Handover notes
- If the report doesn’t contain a prioritized fix list with effort estimates, I refund the fee
Your part
- Read access to the repository (and server or cloud for Standard)
- A short description of what the app should do and what’s broken
- Any docs, tickets or messages from the previous developer
Included
- Code, tests, dependencies, git history
- Automated vulnerability and secret scans
- Security basics review
- Hosting and deploy review (Standard)
- 7 days of email follow-up
Not included
- Fixing anything (quoted in the report)
- Penetration testing or certification
- Legal or IP ownership review
- WordPress plugins or themes
- Meetings beyond one optional call
Fixed prices, agreed before work starts.
Up to 20k lines of code, one repo
Up to 80k lines, plus hosting and deploy review
Build your scope
- Timeline
- ~1 week
- Payment
- Paid in full before work starts
- Earliest start
- Oct 5
The fee is credited in full toward a follow-on project of $1,000+ approved within 30 days.
Not a commitment. I confirm the exact price in a written proposal.Founding price: 3 of 7 spots left, until Mar 31, 2027 — one-off work, in return for a testimonial. How it works
Prices are in USD, paid by bank transfer against an invoice. Work under $1,000 is paid upfront; larger work is 50% to start and 50% before handover, or monthly milestones. The full fee of this service is credited toward a follow-on project of $1,000 or more that you approve within 30 days.How working together works
Variations
- Laravel/PHP, Go, Python, Vue/Nuxt
- A full review, and fixes can follow.
- Other stacks (React, Node, etc.)
- I can review them, and the report says clearly which fixes I’d do and which need another developer.
- Before an acquisition or investment
- The same report, written for the buyer.
- Agency takeover
- The report is written so the agency can share it with its client.
How it runs.
- 01
Describe the situation
Email what the app is, the stack and the situation.
- 02
Invoice and access
You pay the invoice and grant read access.
- 03
Review and report
I review the app and write the report.
- 04
Questions
You read it and ask questions by email, with an optional 30-minute call.
- 05
Fixed quote
You get a fixed quote for the next step.
Where I have done this before.
Licensing & Entitlement Platform
Led a production Go service with 654 tests and structural tests that fail the build when an architecture rule is broken, plus 99 verified documentation pages.
Read the case study →Healthcare · Patient booking · Bilingual webHospital Website & Serial Booking System
Built, not yet live: 305 automated tests and plain-language technical and non-technical overviews.
Read the case study →Questions buyers ask.
Is this a security audit?
It covers the security basics and runs scanners, but it isn’t a penetration test. For a deeper review, see Security Audit & Hardening.
Will you tell me to rebuild?
Only if the evidence supports it. Most apps are cheaper to fix or finish in parts, and the report shows the numbers.
Can I share the report with my new developer?
Yes. It’s yours.
What if my stack isn’t one you work in?
I’ll say so up front. I can still review it, but fixes may need someone else.
How is the fee credited?
If you approve a follow-on project of $1,000 or more within 30 days, the full fee comes off it.
Ask about Codebase Assessment.
Tell me what you have and where it hurts. I reply within one US business day with either a fixed quote or the entry step that makes a fixed quote possible.
Helpful to include
- Stack and versions
- Approximate size
- Where it’s hosted
- What the app does
- What’s going wrong
- Who built it and whether they’re reachable
- What you need to decide, and by when
More in Project Rescue & Takeover
Rescue & Finish
When a developer or agency left your app half-built or unstable, I take it over after a Codebase Assessment, stabilize it, and finish the agreed scope in fixed monthly phases. For Laravel, Vue/Nuxt, Go and Python apps. From $1,300 ($1,000 founding) per monthly phase. Every rescue starts with an assessment.
AI-Built App Rescue
A new service: a fixed-price audit of an app built with Lovable, Bolt, Cursor or similar tools, covering data access rules, exposed keys, auth, backups and deploy, with a clear fix plan. I make the fixes on Laravel, Vue/Nuxt, Go, Python and Postgres/Supabase SQL. Audit from $390 ($300 founding), about a week.
Ownership & Access Check
A new service: I find where your domain, DNS, hosting, email, code and app accounts live, whose name each one is in and who can log in, then give you a one-page map and a plan to move everything into your name. From $195 ($150 founding), about a week. For owners whose developer left or went quiet.