Skip to content

Software, web & mobile

Somebody has to pick this up. It may as well be us.

Half-built, abandoned, or running on a framework that stopped getting security patches two years ago. We will tell you whether it is worth saving before you spend anything on saving it.

It arrives in a handful of ways. The developer stopped replying. The agency that built it no longer supports that kind of work. The person in-house who understood it has left. Or it still runs, but it is on a version of PHP that your host has given you until the spring to move off.

The common thread is that nobody will give you a straight answer about how bad it is. Quoting to take on somebody else's code is risk, and most suppliers price that risk by either refusing or quoting a rebuild. Neither tells you what you actually need to know.

So we start with a small, fixed-price assessment. A few days, a written verdict, and the report is yours whether or not you use us for the work. It is the cheapest way to replace a vague worry with a number.

What drives the cost

The assessment is a fixed price. What the work afterwards costs depends on:

  • How big and how old the codebase is, and whether anyone documented anything.
  • How far the framework has moved on. One major version behind is a job; five is closer to a rebuild.
  • How much access you still have - recovering accounts from an unresponsive supplier takes time.
  • Whether it runs at all, and whether there are tests to tell you when you have broken something.

We will tell you when the honest answer is to start again, even though finishing somebody else's work is usually the bigger invoice for us. A rebuild you chose is cheaper than a rescue you regret.

What you get

What the assessment covers

Can it even be run?

First job is getting it building and running somewhere that is not production. A surprising number of inherited projects cannot be, and that alone tells you a lot.

What it is actually built on

Framework, language and dependency versions, and which of them are past end of life. Dates, not adjectives.

Security posture

Known vulnerabilities in dependencies, credentials committed to the repository, anything exposed that should not be. This is usually the part that decides urgency.

What works and what never did

The gap between what you were told was finished and what is genuinely finished. Often the most uncomfortable part of the report.

Your data

Whether it is intact, whether it is backed up, and whether anybody has tested restoring it. Backups that have never been restored are not backups.

What you actually own

Domain, DNS, repository, hosting, app store and analytics accounts. We check whose name each one is in - it is frequently not yours.

A written verdict

Finish, upgrade or rebuild, with an honest cost against each option, so you can choose on numbers rather than on how it feels.

How it works

How a rescue runs

No engineer turning up unannounced, and no invoice with surprises on it.

  1. 1

    Work out what access exists

    Before anything else. Sometimes recovering control of a domain or a repository is the urgent job and the code can wait.

  2. 2

    Fixed-price assessment

    Usually a few days. Bounded deliberately - you should not be spending heavily to find out how much you need to spend.

  3. 3

    The verdict, in writing

    Options, costs and the risks of doing nothing. Yours to keep, and perfectly usable to brief somebody else.

  4. 4

    Then the work, if you want it

    Finish, upgrade or rebuild, scoped in phases. No obligation to use us for it.

Questions

The things people ask first.

Usually. A lot of what we do early on is recovering control - proving ownership to a registrar, getting into a hosting account, tracking down where the code actually lives. It is rarely as hopeless as it feels, though it can be slow. What we cannot do is access accounts you have no right to, so the first question is always what is in your name.

It depends what you signed, and plenty of small businesses never signed anything. We will help you work out where you stand and what it means practically. For what it is worth, everything we build is yours by default.

Genuinely depends, and anybody who answers before looking is guessing. Finishing is often cheaper than it feels, because the unglamorous groundwork is usually the part that got done. Sometimes the foundations are bad enough that every change costs triple and a rebuild pays for itself inside a year. The assessment gives you both numbers.

More urgent than most people are told. Once a version stops receiving security patches, known vulnerabilities simply stay open. Hosts start refusing to run it, payment providers start failing compliance checks, and some insurers ask the question directly. It is rarely an emergency today and it is rarely safe to leave another year.

No. Most of the messes we inherit came from someone under-briefed, under-paid or asked to keep changing direction. It is not useful and it is usually not fair. We care about what to do next.

We say so, in writing, with the reasoning. You keep the report either way and you are free to take it elsewhere. We would rather lose the work than take money to prop up something that is going to fail again.

A quick word about cookies

We use a couple of cookies to make the site work, and we count visits with our own analytics - no third parties, no advertising, and no IP addresses stored. You can turn the counting off and we will not record your visit at all. Cookie policy.