Back to Services

PHP code audit: security, performance, maintainability

A code-level review of your PHP application, including code written with AI tools. You get a prioritized list of findings with concrete fixes, not a generic score.

What a PHP code audit tells you

A PHP code audit answers one question: how risky is it to keep running and changing this application? We read the code, run static analysis and check every dependency. Then we rank each finding by what it means for your business, not by how a tool labels it.

Most of the systems we review have grown over years. Some started on PHP 5 or 7, some on an older Symfony version, some as plain PHP without a framework. Others were built quickly with AI coding assistants. The question is always the same: what needs attention first, and what can wait?

The report is useful on its own. You can hand it to your own team, to a new hire or to another agency, and they know where to start.

When teams ask for an audit

  • →The only developer has left and nobody knows the state of the code
  • →You are about to take over or buy a PHP application
  • →A penetration test found issues and you need a plan to fix them
  • →A PHP or Symfony upgrade is overdue and nobody wants to start it
  • →Parts of the code were generated with AI tools and never reviewed

What the audit checks

Six areas, each reviewed with tools and by reading the code. The weighting depends on your system: an online shop gets a closer look at checkout and payments, an internal tool at permissions and data access.

Security

SQL injection, XSS, CSRF, file uploads, authentication and session handling, authorization on every route, secrets in the repository, and how user input travels through the application.

Dependencies

Composer and npm packages: known vulnerabilities, abandoned packages, how far each one is behind, and how long your PHP and framework versions are still supported. The free update check gives you a first impression in advance.

Architecture and maintainability

Structure, coupling between modules, duplicated logic and dead code. We mark the places where one change forces edits in many files, and the modules that are riskiest to touch.

Performance

N+1 queries, missing indexes, inefficient ORM usage, caching and expensive work done on every request. Where it matters, we profile real requests instead of guessing.

Tests and delivery

Which critical paths are covered by tests, whether the tests actually run, and how code reaches production: CI pipeline, deployment steps, configuration and secrets per environment.

AI-generated code

Code written with Copilot, Cursor, ChatGPT or similar tools, checked for the specific mistakes these tools tend to make. More on this in the next section.

Audit for AI-generated and vibe-coded code

More PHP applications are now built largely with AI coding assistants, sometimes by people who describe what they want and accept whatever the tool writes. This vibe-coded software often works in the demo and fails where nobody looked: security, edge cases and error handling.

AI-generated code looks tidy, which makes it harder to review. The problems are rarely syntax errors. They are missing checks, invented APIs and patterns copied from outdated examples. A vibe code audit looks for exactly these.

You get the same report as for any other audit, with a separate section on AI-specific risks and a short set of review rules your team can apply to AI-generated code from now on.

Typical findings in AI-generated PHP code

  • •Database queries built from strings instead of prepared statements or the ORM
  • •Routes and API endpoints without authorization checks
  • •Validation that only exists in the frontend
  • •Packages that do not exist, are abandoned or were installed in outdated versions
  • •API keys and passwords committed to the repository
  • •Error handling that hides failures or shows internal details to users

How the audit runs and how long it takes

The PHP code audit runs as our Code Readiness Sprint: 1 to 2 weeks, depending on the size of the codebase. It is the entry point for working with us and useful on its own. If the result is not usable, we rework it at no extra cost.

01

Intro call and access

In a free 30-minute call we agree on the scope and what worries you most. After that we need read access to the repository. Access to production is not required.

02

Automated analysis

Static analysis, dependency and vulnerability scans, complexity and duplication metrics. This maps the codebase and shows which areas deserve a close read.

03

Manual review

We read the critical paths: login, permissions, payments, data imports and anything that handles personal data. Tools show symptoms; reading the code shows the cause.

04

Report and walkthrough

You receive the written report and a working session with your team to go through the findings. Quick fixes are applied during the sprint where possible.

What you receive: sample report outline

Every report follows the same structure, so a manager can read it and a developer can act on it.

  1. 1

    Summary

    One page in plain language: the overall state, the biggest risks and what to do first.

  2. 2

    System overview

    PHP and framework versions, main modules, external services, infrastructure and how the code is deployed.

  3. 3

    Security findings

    Each issue with its location in the code, severity, how it could be exploited and a concrete fix.

  4. 4

    Dependency status

    Outdated and vulnerable packages, end-of-life versions and a suggested upgrade order.

  5. 5

    Architecture, tests and performance

    Fragile modules, duplication, test coverage of critical paths and measured bottlenecks.

  6. 6

    AI-generated code

    Where relevant: AI-specific findings and review rules for your team.

  7. 7

    Prioritized backlog

    All findings ranked by business risk, each with an effort estimate, ready to turn into tickets.

Tools and method

We combine automated static analysis with manual code review, because tools alone miss the context.

Tooling we use

  • →PHPStan / Psalm (PHP static analysis)
  • →Composer audit and npm audit for known vulnerabilities
  • →SonarQube for complexity and duplication
  • →Xdebug + Blackfire for PHP profiling
  • →ESLint + TypeScript strict mode for the JavaScript side
  • →OWASP ZAP for basic vulnerability scanning

Findings ranked by business risk

Tools report issues by category. We report them by business risk. A complex function in an admin page used once a month matters less than a simpler one in your checkout.

Every finding includes an effort estimate and a suggested fix, not just a description of the problem.

After the audit

You decide what happens next. Your team can work through the backlog on its own, with the walkthrough session as a starting point.

If nobody is available to do the work, we can continue as your interim developer: fixing the issues without a feature freeze, setting up CI quality gates and keeping dependencies current.

PHP code audit: frequently asked questions

How long does a PHP code audit take?+

1 to 2 weeks, depending on the size of the codebase and how many areas you want covered in depth. We agree on the scope in the intro call.

What does a code audit cost?+

It depends on the size and state of the codebase. We estimate the effort in the intro call, and you get a concrete quote before we start.

Is a code audit the same as a penetration test?+

No. A penetration test attacks the running application from outside. A code audit reads the source code and finds the causes, including issues a pentest cannot reach. If you already have a pentest report, we use it as input.

Do you need access to our production system?+

No. Read access to the repository is enough for most audits. For performance questions, access to logs or a staging environment helps.

Which PHP versions and frameworks do you audit?+

Current PHP versions as well as older ones like PHP 5 or 7, with a focus on Symfony and plain PHP. If the application has a JavaScript frontend in React or Next.js, we can include it.

Can you audit code written with AI tools?+

Yes. We review it like any other code and add checks for the mistakes AI assistants typically make. It does not matter which tool was used.

What happens after the audit?+

Your team can work through the prioritized backlog, or we continue as interim developers and fix the issues while regular development keeps going.

Case study · B2C SaaS · Pre-Series-A

Next.js Performance Rescue Ahead of a Series A

Three-week audit + refactor of a Next.js App Router build that fell over at 100 concurrent users right before investor demos.

Read the case study →

Want to know where your PHP application stands?

Book a free 30-minute intro call. We will tell you what we notice and whether an audit makes sense for you.