Legacy Audit · PHP & Laravel

Your PHP codebase is 8 years old. It works. But nobody likes touching it anymore.

In two weeks, you get a clear map of your legacy codebase: risks, effort, a concrete modernization plan. Fixed price. No consultant-speak.

Alecs Ghinea

Alecs Ghinea · You work with me directly. No juniors, no handover.
No sales tactics. If I'm not the right fit, I'll tell you on the call.

fixed price, net
€7,500
fixed price, net
kickoff to report
2 weeks
kickoff to report
production PHP
14+ yrs
production PHP
legacy-audit-report.pdf
Sample findings
  • Critical PHP 7.4 in production, EOL since Nov 2022 3–4 wks
  • High 12 Composer packages with known CVEs 1 wk
  • Medium Payment flow without test coverage 2 wks
  • Quick win Enable OPcache preload, drop dead cron jobs < 1 day
Roadmap 3 phases · 14 weeks · no rewrite

Modernized production PHP for

  • leasingmarkt.de
  • AutoScout24 group
  • Hamburg e-commerce
  • Multi-tenant ticketing

The situation

You know the pattern.

Your hosting provider just announced PHP 7.4 EOL. The senior developer who actually understood the system left last month. A security audit produced 47 findings. The new developer, three weeks in, says: "I don't understand why it was built this way."

The business runs. The codebase makes money. But every change takes longer than planned, every migration gets postponed, and slowly it becomes clear: the risk isn't theoretical anymore.

Most agencies recommend a rewrite. Most freelancers want greenfield projects. What you need is someone who knows how to modernize a running PHP codebase without halting the business.

  • PHP 7.4 EOL announced by your host
  • The one senior who understood it just left
  • 47 findings from the last security audit
  • "Why was this built this way?"

What you have after 2 weeks.

A clear, written picture of your codebase:

Enough clarity to decide internally what happens next — whether you continue with me, with your team, or with someone else.

  1. Which risks need to be addressed immediately (security, EOL dependencies)
  2. Which quick wins are doable in under a day
  3. Which larger modernizations are worth doing — and which aren't
  4. How long each step realistically takes (in weeks, not story points)
  5. Where the pitfalls are that a normal code review would miss

How the audit works.

  1. 01

    Day 1 · 90 minutes

    Kickoff

    We walk through your codebase, your pain points, and your business goals together. I get read-only access to the repository, CI logs, and (if possible) a staging environment.

  2. 02

    Days 2–4

    Static Analysis

    I run tools like PHPStan, Psalm, Rector, and Composer audits against the codebase. In parallel: manual inspection of critical paths (payment, authentication, data access).

  3. 03

    Days 5–7

    Dependency & Infrastructure Inventory

    Complete list of all dependencies with EOL dates, known CVEs, and upgrade paths. Including PHP version, framework version, database, caching, external services.

  4. 04

    Days 8–10

    Risk & Roadmap Synthesis

    I structure findings into: Quick Wins (< 1 day), Medium Initiatives (1–4 weeks), Larger Modernizations (1–6 months). Each item with effort estimate in weeks.

  5. 05

    Days 11–14 · 90 minutes

    Walkthrough

    We go through the results together — with your team, your CTO, or both. You receive the full report as PDF and Markdown.

What I've worked on.

14+ years of PHP. 12+ years of Laravel. Hamburg-based. German, English, Romanian.

E-commerce · Hamburg

PHP 5.2 → 8.2

A production e-commerce platform with daily order volume was raised from PHP 5.2 to 8.2 across multiple stages. No downtime, no feature freeze. Result: current platform, hireable, Composer-based, tested.

Automotive marketplace

leasingmarkt.de (Autoscout24 group)

Multi-version Laravel migration for one of Germany's largest leasing marketplaces. Incremental, using the strangler pattern, without affecting ongoing operations.

Ticketing · current, Hamburg

Multi-tenant ticketing platform

14+ Docker microservices, FrankenPHP, vanilla PHP legacy code. PCI compliance remediation for the platform, GCP migration, AlloyDB integration.

What it costs.

Legacy Audit

€7,500 net, fixed price

No hourly billing, no surprises, no scope creep. If the codebase is unusually large or distributed (more than ~150,000 lines of code, or >5 microservices), we'll discuss it in the intro call and adjust the offer transparently.

Payment: 50% on engagement, 50% on report delivery.

Book the intro call

Included

  • Kickoff and walkthrough sessions (2 × 90 min)
  • Static analysis: PHPStan, Psalm, Rector, Composer audit
  • Manual review of payment, auth and data access paths
  • Dependency inventory with EOL dates and CVEs
  • Prioritized roadmap with effort in weeks
  • Full report as PDF and Markdown
  • NDA by default

Frequently asked.

What if our codebase is very small?
Below ~20,000 lines of code, a full audit is overkill. In that case, you get a 3-day Quickcheck for a fixed price of €2,500 instead.
Can the audit be done remotely?
Yes, that's the default. On-site days in Hamburg are possible (e.g. for kickoff or walkthrough), but not necessary.
What if we want to continue after the audit?
Three options: (1) Fixed-price upgrade project (typically €18k–€45k), (2) Fractional Tech Lead (€1,500/day, 1–2 days/week, 3-month minimum), (3) You execute the roadmap internally. I'm not committed in any of these — and neither are you.
Do you sign an NDA?
Yes, by default. Your template or mine, either works.
Who has access to the code?
Only me. No subcontractor, no team, no AI tool with training-data retention. All data is deleted 90 days after project end.
Alecs Ghinea

Next step.

Book a 30-minute intro call. We'll check together whether the audit fits your situation. If not, I'll tell you — and recommend someone who fits better.

Book a 30-minute call

Response within 24 hours · No mailing list · No sales pipeline