Every order counted twice in analytics
Backend audit.
A backend audit reads everything the visual audit can only infer. With read-only access to your accounts and your code, I read the application line by line, from the database up, along with every module and plugin, and see what is actually happening rather than what a page implies. It suits an online store, a SaaS platform or any custom build, and comes at two levels, depending on how far in you let me.
Nine plugins set one price
Disapproved products in the feed
Example findings
The audit ladder
Read in order: each audit takes more access than the one before it. All prices exclude VAT.
What it delivers
What the outside view can only guess at
What it covers
- The database, modelled before any code is read
- The code line by line: the data, processing and business layers
- Every module, plugin and package: version, whether it is maintained, known vulnerabilities, custom or third party
- Code-level security scans: CVEs, SQL injection, cryptography, template, header and cookie injection
- Google Ads: account structure, wasted spend and conversion accuracy
- Analytics: real drop off, conversion rates and attribution
- Tag Manager: what fires, what fires twice and what is broken
- Merchant Center: feed health, disapproved products and coverage
- Which findings are cheap to fix and which are structural
- At white box: hosting, caching, server response and database behaviour
- Every finding with a figure against it, ranked by what it costs
What it does not
- Write access to anything: every login is read-only
- The customer’s view of every template: that is the visual audit
- The performance workstream: waterfalls, images and slow queries are the complete audit
- Carrying out the fixes, quoted separately once you have the report
Grey box or white box
Two levels, one question: how far in?
Grey box means read-only access to your accounts and your code. It covers everything about how the store sells and measures itself, without touching the servers.
White box adds the infrastructure underneath: the hosting, the cache, how fast the server answers, and how the database behaves behind your slowest pages. Take it when the store is slow and nobody can say why.
- Grey box£1,200Google Analytics, Google Ads, Tag Manager, Merchant Center, and the code: the theme, the modules and the customisations.
- White box£1,500Everything in grey box, plus AWS or your host, caching, server response and database behaviour.
What the backend audit reads
The accounts, the code, then the servers
- AI-generated
Google Ads and Analytics
Account structure, wasted spend and whether conversions are counted accurately. Real drop off, real conversion rates and attribution, checked against what the site actually does.
- AI-generated
Tag Manager and Merchant Center
What fires, what fires twice and what is broken. Feed health, disapproved products and how much of the range Google Shopping can show.
- AI-generated
The code
How the theme, modules and customisations are built, and where the weight on every request comes from. Which findings are cheap to fix and which are structural.
- AI-generated
The servers, at white box
Hosting, caching at the edge and the origin, server response by template, and the queries behind your slowest pages.
What the report is organised around
Design, optimisation, security, performance
The code findings fall under four questions. Each one opens with a short summary of who it affects, what it is, where it is, why it matters and how to deal with it, so a manager can read the summaries and a developer the detail.
Design
Is the code well designed?
- Maintainable and upgradable, or fighting its own framework
- Gaps in the model: can it handle the product types and groupings your competitors offer
- Custom modules and plugins that duplicate the core, or each other
- Coding practice, constraints and error handling
Optimisation
Is it doing more work than it needs to?
- Database lookups made where none are needed
- Loops of queries one query could replace
- Requests that fetch far more than they use
- Work repeated on every page that could be cached
Security
What could be exploited?
- A code-level penetration test, within the audit’s scope
- CVE scans across every module, plugin and package
- Raw database query scans for SQL injection
- Cryptography, template injection, header and cookie injection scans
- Business rules a user could get round
Performance
Where is it slow, and why?
- How the code runs, not only how a page scores
- The slowest paths through the code, by template
- Weak points in the stack: hosting, cache, queues, search
- At white box: server response and database behaviour
How your code is handled
Your code stays with me, then it is gone
Your code never shares a machine with anyone else’s. Every client gets their own isolated Linux environment, a hardened build of my own, on its own encrypted disk partition. The application is started the way your team starts it, Laravel Sail for a Laravel app for example, so there are no shared containers for data to leak between.
Customer data stays out of it. On Magento and Shopify a sanitised database dump with no customer data is possible, and that is what I ask for. On bespoke applications where it isn’t, I write a seeder that fills an empty database with dummy products and customers.
It goes to nobody else. I work alone, so nothing passes to a third party, and if a job ever needs a second person it is agreed with you first. Your code is never given to an AI tool: where a fact needs checking, I rewrite the logic in my own words and check that, on commercial accounts with training switched off, or on models running on my own hardware.
When the audit ends, the code is deleted, the environment destroyed and its disk partition wiped. If we go on to development, a fresh environment is made for it, I work on a fork of your repository, and changes reach yours only as pull requests you sign off.
This sits alongside any NDA you want in place.
- IsolatedIts own Linux environment
- EncryptedIts own disk partition
- SanitisedNo customer data
- DestroyedDeleted when it ends




