Sound familiar?
- You are about to pay for a big new phase and are not sure the foundations are sound
- An investor, buyer or insurer wants evidence the software is secure
- You are changing supplier and want to know what you are inheriting
- Your app was built quickly with AI tools and nobody has reviewed it
- Performance is getting worse as data grows
- Your developer says everything is fine, but problems keep appearing
Key facts
- Covers security, dependencies, architecture, code quality, tests, database, hosting and data protection
- Combines automated tools with a developer reading the code by hand
- Security checks are guided by the OWASP Top 10 web application risks
- Every finding has a severity, an explanation in plain English and a recommended fix
- Includes a summary for directors and technical detail for developers
- Useful for apps built with AI coding tools, which often ship with exposed secrets or missing access checks
- We review PHP, Laravel, Symfony, WordPress, Node.js, TypeScript, React, Vue and Python code
When a code audit is worth doing
A code audit gives you an independent view of software you depend on but cannot easily judge yourself. The usual triggers are:
- Before investing more: check the foundations before a big new phase
- Due diligence: an investor, acquirer or insurer wants evidence
- Changing supplier: understand what you are inheriting and what the handover must include
- Recurring problems: outages, slow pages or bugs that keep returning
- AI-built software: applications generated quickly with AI coding assistants often work in a demo but ship with secrets in the code, missing authorisation checks or database rules that let one user read another's data
The audit is independent. We are not trying to win a rebuild; a good outcome is often a short list of fixes and a clean bill of health on everything else.
What we check
| Area | Examples |
|---|---|
| Security | Authentication, authorisation on every route, injection, cross-site scripting, CSRF, file uploads, secrets in code, password storage, session handling, security headers |
| Dependencies | Language and framework versions against vendor support dates, known vulnerabilities via composer audit and npm audit, abandoned packages |
| Architecture | Separation of concerns, duplication, how hard common changes are, integration patterns |
| Code quality | Static analysis with PHPStan or ESLint, error handling, logging, consistency |
| Tests | What exists, what it covers, whether it runs automatically |
| Database | Schema design, indexes, slow queries, backups and restore |
| Hosting and deployment | Server versions, deployment process, environments, monitoring |
| Data protection | Personal data stored, retention, access logging, encryption |
Tools plus a person reading the code
Automated scanners are quick and find a lot, including outdated packages, obvious injection patterns and leaked keys, but they miss the problems that matter most in business software. For example, a scanner cannot tell that a logged-in customer can view another customer's invoice by changing a number in the URL, or that the discount logic can be applied twice. Those findings come from a developer reading the code with the business process in mind.
We run the tools first, then review by hand, focusing on the areas where a mistake would hurt most: login, payments, personal data, admin functions and integrations with accounting or payment systems.
The report
You get a report written for two audiences. The summary explains, in plain English, the overall health of the system, the most serious risks and what we recommend, so directors can make decisions. The findings register gives developers what they need: location in the code, explanation, severity, and a suggested fix.
Severity reflects real business risk, not just a technical score. An injection flaw on an internal page behind a login is still serious, but it is less urgent than a public form that exposes customer data. We finish with a call to walk through the findings and answer questions.
How the audit runs
An audit follows a simple sequence. We start with a short call to understand what the system does, who uses it, how it is hosted and what has prompted the review, because that tells us where to look hardest. You give us read-only access to the repository and, ideally, a staging site and a copy of the database structure with personal data removed. We never need to change anything on your live system to carry out an audit.
We then run the automated checks, read the code, and test any suspected issues on staging rather than live. If we find something critical during the audit, such as an exposed API key or a route that leaks customer data, we tell you straight away instead of waiting for the final report, so it can be fixed immediately and checked again before the report is finished. Everything you share with us is kept confidential and deleted at the end if you ask.
After the audit
The report is yours to use as you like. Your existing developer can work through it, or we can quote a fixed price to fix the findings. If the audit shows deeper issues, the next step might be software rescue, a PHP upgrade or a staged modernisation. Every audit starts with a free chat about the system and why you want it reviewed.
What we deliver
- A written audit report with an executive summary and a findings register
- Severity ratings for every finding, from critical to informational
- A dependency and version report showing unsupported or vulnerable components
- Security findings with reproduction notes and fixes
- A prioritised remediation plan with suggested phases
- A walk-through call to explain the findings to your team
How it works and what it costs
Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data.
Free chat
Tell us the problem in plain English: what you do now, what goes wrong and what "better" looks like. No charge, no obligation.
Scoping
We map the processes, systems and data involved, agree what is in and out, and write it down so there are no surprises.
Fixed-price quote
You get a fixed price for the agreed scope, or a phased plan for bigger builds, so you can start small and prove it works.
Build and test
We build in short stages you can see and try, test against real data, then go live carefully with a rollback plan.
Hand over and look after
You own the code and the data. We can host it, support it and keep improving it, or hand it to your own team.
Frequently asked questions
What is included in a code audit?
A dijitul developments code audit covers security, dependencies and versions, architecture, code quality, tests, database, hosting and deployment, and data protection. You get a written report with severity-rated findings, a prioritised fix plan and a call to walk through it.
Is a code audit the same as a penetration test?
No. A code audit reviews the source code, configuration and hosting from the inside. A penetration test attacks the running system from the outside. They complement each other. dijitul developments carries out code audits; if you also need a formal penetration test, we can help you scope one with a specialist.
Can you audit an app built with AI coding tools?
Yes, and it is increasingly common. Apps generated quickly with AI assistants often work in a demo but contain secrets in the code, missing authorisation checks or weak database access rules. dijitul developments reviews them like any other codebase, with extra attention to those patterns.
Will our current developer see the report?
That is your decision. Many clients share it so their developer can work through the fixes. dijitul developments writes findings factually and constructively, focusing on risks and fixes rather than blame, so the report is useful whoever acts on it.
What access do you need for a code audit?
Read access to the source code repository is the minimum. A copy of the database structure, ideally without personal data, plus read access to hosting configuration and a staging site make the audit more thorough. We sign a confidentiality agreement if you need one.
How much does a code audit cost?
It depends on the size of the codebase and the areas you want covered. dijitul developments quotes a fixed price after a free chat and a quick look at the repository, so you know the cost before the audit starts.
Related
Tell us what you need to build
Free chat, clear scope, fixed-price quote. You own everything we build.