Skip to content
0% platform fee for clients — always Post now →

This is an anonymized sample report. The case is fictional; the format, depth, and pricing are real.

Sample report

What a takeover assessment actually looks like.

The biggest objection to a fixed-price assessment is not knowing what you are buying. Fair. Here is a complete sample — the same structure every client receives before deciding what to do next.

Case: an e-commerce booking system. The previous developer delivered it in three weeks using AI tools, then stopped responding.

1. Executive summary

The system works today and serves real customers. It is built on a mainstream stack with no exotic dependencies, which is good news. Three security findings require action within two weeks, and hosting plus repository access must be transferred before any maintenance can begin.

Verdict

Yellow — maintainable after targeted fixes

Not a rewrite. Fix the security findings, transfer ownership, and the system can be maintained safely.

Your system may have the same problems. Start an assessment

2. Account and access inventory

The single most important section: nothing can be maintained until ownership is settled.

AssetStatusFinding
DomainIn orderRegistered under the client's own account; auto-renewal on.
HostingAction requiredRunning on the previous developer's personal account; the client is paying an invoice they do not control.
RepositoryAction requiredNo access granted. Code recovered from the server only; Git history lost.
Payment providerPending confirmationAccount exists in the client's name; ownership of the API keys pending confirmation.
Email serviceIn orderClient-owned; credentials rotated during the assessment.

Your system may have the same problems. Start an assessment

3. Architecture overview

A conventional monolith: React frontend, Node.js API, PostgreSQL database, deployed as two containers behind a managed load balancer. Booking state is handled correctly; the weak points are integrations, not core logic.

  • Frontend: React 19 + Vite, no server-side rendering, bundle contains two hard-coded API keys
  • Backend: Node.js + Express, single service, no background job runner
  • Database: PostgreSQL 15, migrations exist but the last four were applied manually
  • Integrations: Stripe payments, SendGrid email, Google Maps

Your system may have the same problems. Start an assessment

4. Security findings

Ranked by risk. Each finding includes what an attacker could do with it.

Hard-coded API keys in the frontend bundle

High risk

Two third-party keys are visible to anyone who opens browser dev tools. They must be rotated and moved server-side.

Payment callback without signature verification

High risk

The webhook endpoint trusts any POST request. A forged request could mark unpaid bookings as paid.

No backups for eight months

High risk

The last snapshot predates the current schema. A failed migration today would be unrecoverable.

Dependencies fourteen months out of date

Medium risk

Including three packages with published vulnerabilities. Upgrade path is straightforward.

Stack traces exposed in production errors

Low risk

Error responses leak internal paths. Easy fix, low urgency.

Your system may have the same problems. Start an assessment

5. Technical debt register

  • Git history lost — the recovered code should be committed as a fresh baseline
  • Four database migrations applied by hand, outside the migration runner
  • No staging environment; changes go straight to production
  • Booking reminder emails sent from a setInterval inside the web process
  • No monitoring or alerting of any kind

Your system may have the same problems. Start an assessment

6. Recommended options

Three ways forward, priced as fixed quotes so you can decide without a meter running.

Option A — Secure and stabilize

Fix the three high-risk findings, transfer hosting and repository ownership, set up automated backups and monitoring.

US$1,200 – 1,800

Option B — A plus debt cleanup

Everything in A, plus staging environment, migration cleanup, and dependency upgrades.

US$2,500 – 3,500

Option C — B plus ongoing maintenance

Everything in B, plus a monthly maintenance subscription: updates, monitoring response, small fixes.

US$3,000 – 4,000 + US$300/mo

7. Timeline

  • Days 1–2: access transfer, backup baseline, key rotation
  • Days 3–5: security fixes deployed to production
  • Week 2: debt cleanup and staging environment (Option B onwards)
  • Every deliverable documented in the standard handover pack

Your system may have the same problems. Start an assessment

Get this report for your own system.

From US$400, delivered in 3–5 business days. The report is yours to keep — use it with us, with another developer, or with your own team.