Initial Technical Audit
An assessment of your store's technical condition in six areas, plus any further areas agreed in the order, for a fixed price paid in advance. You get a written report with the findings, their severity, the recommended steps and an indicative cost estimate, and we present it at an online meeting.
The audit assesses the technical condition of your online store, using access you provide. It is agreed in a written order, has a fixed price paid in advance, and ends with a written report that we present to you at an online meeting.
What the audit covers
Six areas. We choose how deep to go in each according to how much it matters to running your store.
- The platform and its updates
- Hosting and the server
- Source code and extensions
- Security, without active tests: we read the code and the configuration and do not attack the store
- Performance
- Email and domain settings
Further areas, such as an integration that matters to you, can be agreed in the order.
What you get
A written report with:
- the findings, area by area,
- the severity of each finding,
- the recommended course of action,
- an indicative cost estimate for the work it recommends.
We present the report at one online meeting on a date we agree, within 30 days of handing it over. The cost estimate is indicative, not a binding quote. Where an area could not be assessed because the access was missing, the report says so.
What we need from you
We agree with you which access we need, and after the order is signed we send you the list by email. You provide the access and tell us who operates the server, the hosting and the code repository. Where a third party operates them and the access needs its consent, you obtain that consent. The audit changes nothing in your systems. If any access has not arrived within 10 business days, we assess that area from the materials we have.
What the audit does not include
It does not fix anything. It does not include active security tests, exports of production data, legal, tax or accounting assessments, or further consultations on the report after its presentation. For third-party systems connected to the store, we assess only their module in your store’s code. The audit is not a penetration test, a security certification or an expert opinion. The findings can be followed up in another engagement, with us or with any other team.
What an audit can find
From the ten years of e-commerce engineering behind the practice, anonymized:
- Every product page spent ~300 ms, sometimes whole seconds, inside a synchronous server-side call to a marketing API, on every single view. A transaction trace found it. Moving the call to a queue removed it, with before/after numbers to prove it.
- A cache hit rate stuck at 20–30% because a stock-status extension purged the entire Varnish cache after every order. The extension’s vendor denied it, so a clean-install reproduction with varnishlog captures settled the question.
- Checkout failed sitewide at order #65,536: a third-party module’s table used a SMALLINT primary key, which had reached its maximum value.
- A catalog query 110 times slower than it should be, with three stacked causes: the platform requesting 10,000 IDs from the search engine by design, a database version regression amplifying it, and a vendor module breaking the API schema on top.
- A nightly import that grew from 6 to 48 minutes. The root cause was a cleanup cron that had failed silently, leaving an 8 GB staging table inside a 13 GB database.
- A customer’s order list brought from 3.5 s to 800 ms once the query stopped hydrating the full order detail for every row it listed.
Slow stores are rarely slow for the reason everyone suspects, which is the point of measuring first.
When this fits
- You took over the store from a previous agency and do not know what state it is in
- The platform is behind on updates and nobody can say what catching up would take
- LCP is above 2.5 s, the threshold Google calls good at the 75th percentile (web.dev, checked 13 July 2026), and the cause is not known
- You’re considering a replatform and want to know whether the current platform is the actual problem
- You need a technical second opinion before signing a bigger contract
Price and timing
The audit has a fixed price, stated in the order, invoiced and paid in advance. We hand over the report within the number of business days the order states, counted from the later of two dates: the day your payment reaches our account, and the day you provide the access (or the period for providing it ends).
Before we send you an offer, we look at your store from the outside, free of charge. Tell us about your store to start. That look is not the audit and comes with no report.
Related services
- Magento 2 / Mage-OS / Adobe CommerceEnterprise commerce for complex catalogs, B2B, and multi-store, on Mage-OS and Adobe Commerce.
- ShopifyThe fastest path from idea to checkout, with Hydrogen for headless builds when storefront speed is the product.
- Platform migrationFrom WooCommerce, Magento 1, or a custom stack to a platform that won't trap you. Catalog, customers, orders, and SEO are preserved through cutover.