Before an upgrade or relaunch
We establish which components should be kept, updated, replaced or redesigned.
That gives the upgrade path a foundation you can rely on.
A technical assessment of existing Drupal systems
We assess the condition, the risks and the dependencies of your Drupal system within an agreed scope. You receive documented findings, clearly marked gaps in the assessment, and a prioritised action plan for an upgrade, a handover or continued stable operation.
An automated inventory finds anomalies. The manual assessment puts those findings, their dependencies and their consequences for operation and further development into context.
We establish which components should be kept, updated, replaced or redesigned.
That gives the upgrade path a foundation you can rely on.
Codebase, configuration, deployment, operation and existing documentation are assessed and put on record.
Open risks become visible before the handover, not after it.
Versions, Drupal security advisories and known notes on external dependencies are checked against the agreed sources.
The next technical decisions rest on documented ground.
Architecture, caching, deployment, monitoring and the available operational data help narrow down the possible causes.
Indications and confirmed findings stay clearly distinguishable.
The report is not tied to any one delivery partner. Engineering, product owners and operations can all use the same findings for budget planning, statements of work, tendering and prioritisation.
Every finding refers to the documented state of the assessment and names the location, the observation, the impact, the recommendation and the priority.
Direct evidence within the agreed scope supports the finding.
A reasoned lead that needs further assessment or additional data.
The point lies outside the agreed scope, or could not be judged without sufficient access.
We work with agreed read-only access and named sources. Missing access or missing evidence is documented in the result as a limit of the assessment.
Drupal core, modules, themes, PHP, database and central dependencies, including support and end-of-life status.
Content model, configuration management, multilingual setup, roles, integrations, search and caching.
Custom modules, theme, patches, the Composer lock file, technical debt and known security advisories from the agreed sources.
Drupal security advisories, the update process, roles, exposed functionality and risks that are apparent in code and configuration.
Caching, render paths, database, assets, hosting, deployment, monitoring, and any existing backup and restore evidence.
Crawling, redirect, canonical, sitemap and metadata problems. Search intent and GEO are covered in more depth by their own audit.
The starting point ranges from a single, clearly bounded technical question to a full assessment with a joint workshop on what to do next.
For one clearly stated question about support status, security advisories, the ability to update, or a bounded operational risk.
You receive prioritised findings on the agreed technical question.
For a broader look at architecture, code, configuration, security, performance and operation across the agreed system scope.
You receive the state of the assessment, a list of findings and a prioritised action plan.
When engineering, product owners and operations need to agree on responsibilities and sequence together.
Responsibilities and the next decisions are ordered jointly on top of the findings.
On access, active security testing, implementation and neighbouring audits.