Skip to content
Available for new work

Backend audit.

A backend audit reads everything the visual audit can only infer. With read-only access to your accounts and your code, I read the application line by line, from the database up, along with every module and plugin, and see what is actually happening rather than what a page implies. It suits an online store, a SaaS platform or any custom build, and comes at two levels, depending on how far in you let me.

From£1,200

  • £1,200 grey box, £1,500 white box
  • Read-only access only
  • Findings with figures against them
AI-generated
HighTag Manager

Every order counted twice in analytics

HighServer

Nine plugins set one price

MediumMerchant Center

Disapproved products in the feed

Example findings

The audit ladder

Read in order: each audit takes more access than the one before it. All prices exclude VAT.

What it delivers

What the outside view can only guess at

What it covers

  • The database, modelled before any code is read
  • The code line by line: the data, processing and business layers
  • Every module, plugin and package: version, whether it is maintained, known vulnerabilities, custom or third party
  • Code-level security scans: CVEs, SQL injection, cryptography, template, header and cookie injection
  • Google Ads: account structure, wasted spend and conversion accuracy
  • Analytics: real drop off, conversion rates and attribution
  • Tag Manager: what fires, what fires twice and what is broken
  • Merchant Center: feed health, disapproved products and coverage
  • Which findings are cheap to fix and which are structural
  • At white box: hosting, caching, server response and database behaviour
  • Every finding with a figure against it, ranked by what it costs

What it does not

  • Write access to anything: every login is read-only
  • The customer’s view of every template: that is the visual audit
  • The performance workstream: waterfalls, images and slow queries are the complete audit
  • Carrying out the fixes, quoted separately once you have the report

Grey box or white box

Two levels, one question: how far in?

Grey box means read-only access to your accounts and your code. It covers everything about how the store sells and measures itself, without touching the servers.

White box adds the infrastructure underneath: the hosting, the cache, how fast the server answers, and how the database behaves behind your slowest pages. Take it when the store is slow and nobody can say why.

  • Grey box£1,200Google Analytics, Google Ads, Tag Manager, Merchant Center, and the code: the theme, the modules and the customisations.
  • White box£1,500Everything in grey box, plus AWS or your host, caching, server response and database behaviour.

What the backend audit reads

The accounts, the code, then the servers

  1. AI-generated

    Google Ads and Analytics

    Account structure, wasted spend and whether conversions are counted accurately. Real drop off, real conversion rates and attribution, checked against what the site actually does.

  2. AI-generated

    Tag Manager and Merchant Center

    What fires, what fires twice and what is broken. Feed health, disapproved products and how much of the range Google Shopping can show.

  3. AI-generated

    The code

    How the theme, modules and customisations are built, and where the weight on every request comes from. Which findings are cheap to fix and which are structural.

  4. AI-generated

    The servers, at white box

    Hosting, caching at the edge and the origin, server response by template, and the queries behind your slowest pages.

What the report is organised around

Design, optimisation, security, performance

The code findings fall under four questions. Each one opens with a short summary of who it affects, what it is, where it is, why it matters and how to deal with it, so a manager can read the summaries and a developer the detail.

AI-generated

Design

Is the code well designed?

  • Maintainable and upgradable, or fighting its own framework
  • Gaps in the model: can it handle the product types and groupings your competitors offer
  • Custom modules and plugins that duplicate the core, or each other
  • Coding practice, constraints and error handling

Optimisation

Is it doing more work than it needs to?

  • Database lookups made where none are needed
  • Loops of queries one query could replace
  • Requests that fetch far more than they use
  • Work repeated on every page that could be cached

Security

What could be exploited?

  • A code-level penetration test, within the audit’s scope
  • CVE scans across every module, plugin and package
  • Raw database query scans for SQL injection
  • Cryptography, template injection, header and cookie injection scans
  • Business rules a user could get round

Performance

Where is it slow, and why?

  • How the code runs, not only how a page scores
  • The slowest paths through the code, by template
  • Weak points in the stack: hosting, cache, queues, search
  • At white box: server response and database behaviour

How your code is handled

Your code stays with me, then it is gone

Your code never shares a machine with anyone else’s. Every client gets their own isolated Linux environment, a hardened build of my own, on its own encrypted disk partition. The application is started the way your team starts it, Laravel Sail for a Laravel app for example, so there are no shared containers for data to leak between.

Customer data stays out of it. On Magento and Shopify a sanitised database dump with no customer data is possible, and that is what I ask for. On bespoke applications where it isn’t, I write a seeder that fills an empty database with dummy products and customers.

It goes to nobody else. I work alone, so nothing passes to a third party, and if a job ever needs a second person it is agreed with you first. Your code is never given to an AI tool: where a fact needs checking, I rewrite the logic in my own words and check that, on commercial accounts with training switched off, or on models running on my own hardware.

When the audit ends, the code is deleted, the environment destroyed and its disk partition wiped. If we go on to development, a fresh environment is made for it, I work on a fork of your repository, and changes reach yours only as pull requests you sign off.

This sits alongside any NDA you want in place.

  1. IsolatedIts own Linux environment
  2. EncryptedIts own disk partition
  3. SanitisedNo customer data
  4. DestroyedDeleted when it ends

Available for new work

UK based · PHP · Python · JS · TS. Every first call is free.