The button nobody could find
Ecommerce audits.
An audit is a written, independent check of your website or application: what is wrong with it, what each problem is costing you, and the order to deal with it. Online stores, brochure sites, SaaS platforms and custom builds. Four audits, arranged by how much access you give me, from a £500 health check that needs only the address to a complete audit that reads the code line by line, every module and plugin, and the hosting.
Delivery cost shown last
Search returns nothing for plurals
Example findings
Ecommerce audit prices
Priced by what you hand over, not by topic
| Health check£500 | Visual audit£950 | Backend audit£1,200 | Complete auditQuoted | Workflow auditNot yet | |
|---|---|---|---|---|---|
| What it needs | Nothing. One topic, read from the public site. | Nothing. Every template, as a customer sees it. | Read-only accounts and code, then the servers. | Read-only admin, the repository and the server. | To be defined. |
| Needs no login or access | ✓ | ✓ | — | — | — |
| One topic, looked at in depth | ✓ | — | — | — | — |
| Every page template, laptop and phone | — | ✓ | — | ✓ | — |
| Competitors measured the same day | ✓ | ✓ | — | ✓ | — |
| Analytics, Ads, Tag Manager and Merchant Center | — | — | ✓ | ✓ | — |
| Reads the code line by line | — | — | ✓ | ✓ | — |
| Every module and plugin: versions and known vulnerabilities | — | — | ✓ | ✓ | — |
| Code-level security scans | — | — | ✓ | ✓ | — |
| Hosting, caching and database | — | — | ✓ | ✓ | — |
| Performance workstream | — | — | — | ✓ | — |
| Follows an order to dispatch | — | — | — | — | ✓ |
| Read it | Read it | Read it | Read it | Read it |
The health check is £500, the visual audit £950, and the backend audit £1,200 at grey box or £1,500 at white box. The complete audit is quoted, because the performance work depends on how many templates and systems are involved. All prices exclude VAT. Most audits are sold by subject, but the subject is often the thing you don’t know yet: a store losing sales could have a slow product page, a checkout error on one card type, a broken Google Shopping feed or a tag counting every order twice. Sorting by access answers a question you can answer today: how much you are comfortable handing to someone you haven’t worked with.
Which audit do I need?
Start from what you already know
Pick the one that sounds like your site. Each says when it fits, what access it needs and what it covers. If none of them does, a free call sorts it out in fifteen minutes.
How an audit is carried out
From the database up, line by line
The backend and complete audits read an application the way it is built: the database first, then the layers of code on top of it, then what the customer finally sees. Around 85% of the work is reading, by hand, line by line. The rest is checking and writing up.
Database first
- Database first
Model the database
I start with the database files and model what the database looks like, visually. It is the truest record of how an application is built, and a lot of the optimisation shows up here before any code is opened.
- Data layer
Map the code to the data
Then the application is read as three layers. First the data layer, mapped against the database: how data is stored, read and written, and whether the code keeps to the constraints the schema sets.
- Processing layer
Follow the data through
How data is transformed on its way through the application. This is where coding practice, error handling and failure states are checked: what happens when something goes wrong, not only when it goes right.
- Business layer
Question the rules
The rules the application enforces: prices, stock, customer groups, permissions. Are there gaps that could let somebody do what they shouldn’t, and could it be simpler to manage and change?
- Front end
See what it renders
What the code does once it reaches a screen. Is it showing things it shouldn’t, exposing products or data that should be hidden, and is that a data problem or a code problem? This is where the audit meets SEO.
- Every claim checked
Test every assumption
Everything found goes down first, then every assumption is tested. Where I question a finding, it is fact-checked with the help of AI, on a rewritten version of the logic in question, never on your code.
- Written up
Set it in the report
The findings are set into the report template, and the code references, file and line, are added by hand. Each section opens with a summary, so the report can be read in parts.
The health check and visual audit are black box: they see only what the public sees, so they begin at the front end.
What the report looks like
Every finding written the same way
- What it isin plain terms, with technical words explained where they first appear
- What it costsin money, customers or risk
- Evidencethe web address or screen where it was seen, the date, and the tool that measured it
- Approachhow I would deal with it
- Prioritywhere it sits in the order of work
Findings are ranked by what they cost you, so the first page tells you what to do first, and the report reads as easily to a finance director as to a developer. It stands on its own: hand it to your own developer or agency and they can act on it. An audit tells you what is wrong, why it matters and in what order to deal with it. If you’d like me to do the work, that is quoted separately once you’ve read the findings.
Ecommerce audit questions, answered
- How much does an ecommerce audit cost?
- A health check is £500, a visual audit £950, and a backend audit £1,200 at grey box or £1,500 at white box. The complete audit is quoted before it starts. All prices are fixed and exclude VAT: no day rates and no open-ended scope.
- What is the difference between black box, grey box and white box?
- They are the standard terms for how much access an auditor is given. Black box sees only what the public sees. Grey box adds read-only access to your accounts and code. White box sees everything, including the servers and the database.
- Do I have to give you access to my store?
- Not for the health check or the visual audit: both are done from the outside, like a customer. Access is only needed from the backend audit upward, and it is read-only.
- How long does an audit take?
- Most land in five to ten working days from kickoff, depending on the size of the store and the audit you choose. You get a firm date before anything starts.
- Why pay, when agencies offer free audits?
- A free audit is the start of a sales process and points toward the agency’s services. A paid audit works for you: you own the report, it doesn’t depend on hiring me afterwards, and findings are ranked by what they cost you rather than by what someone can sell.
- What kinds of site do you audit?
- Online stores on Magento 1 and 2, Adobe Commerce, Shopify and WooCommerce; brochure and content sites on WordPress and other CMSs; SaaS platforms and custom applications in Laravel, PHP, Django, Python, Next.js and Node. Every module, plugin and package is checked, custom and third party.
- Who does the work?
- I do all of it myself, and nothing is passed to a third party. I’ve audited 110 sites, and my first training was in digital forensics, which is where the habit of recording where and when each finding was seen comes from.
- What happens to my code?
- It goes into an isolated, encrypted environment used for you alone, is never given to an AI tool, and is deleted with the environment when the audit ends. The backend audit page explains it in full.
