Skip to main content
AI bot ProDigi
ProDigi
Online
Hello, my name is ProDigi – you tell me the goal, I'll find the best way to get there! How can I help you?
2.08.2026 16:26 o'clock

A technical assessment of existing Drupal systems

Technical Drupal audit for operation, upgrade and relaunch

We assess the condition, the risks and the dependencies of your Drupal system within an agreed scope. You receive documented findings, clearly marked gaps in the assessment, and a prioritised action plan for an upgrade, a handover or continued stable operation.

When a technical Drupal audit is worth doing

An automated inventory finds anomalies. The manual assessment puts those findings, their dependencies and their consequences for operation and further development into context.

Before an upgrade or relaunch

We establish which components should be kept, updated, replaced or redesigned.

That gives the upgrade path a foundation you can rely on.

Before a change of supplier or a handover

Codebase, configuration, deployment, operation and existing documentation are assessed and put on record.

Open risks become visible before the handover, not after it.

When the support or security status is unclear

Versions, Drupal security advisories and known notes on external dependencies are checked against the agreed sources.

The next technical decisions rest on documented ground.

When there are performance or operational problems

Architecture, caching, deployment, monitoring and the available operational data help narrow down the possible causes.

Indications and confirmed findings stay clearly distinguishable.

One report for budgeting, procurement and delivery planning

The report is not tied to any one delivery partner. Engineering, product owners and operations can all use the same findings for budget planning, statements of work, tendering and prioritisation.

Every finding refers to the documented state of the assessment and names the location, the observation, the impact, the recommendation and the priority.

How much each finding is worth stays visible

Confirmed

Direct evidence within the agreed scope supports the finding.

Indication

A reasoned lead that needs further assessment or additional data.

Not assessed

The point lies outside the agreed scope, or could not be judged without sufficient access.

What we assess within the agreed scope

We work with agreed read-only access and named sources. Missing access or missing evidence is documented in the result as a limit of the assessment.

Versions and lifecycle

Drupal core, modules, themes, PHP, database and central dependencies, including support and end-of-life status.

Architecture and configuration

Content model, configuration management, multilingual setup, roles, integrations, search and caching.

Code and dependencies

Custom modules, theme, patches, the Composer lock file, technical debt and known security advisories from the agreed sources.

Security and permissions

Drupal security advisories, the update process, roles, exposed functionality and risks that are apparent in code and configuration.

Performance and operation

Caching, render paths, database, assets, hosting, deployment, monitoring, and any existing backup and restore evidence.

Technical SEO foundations

Crawling, redirect, canonical, sitemap and metadata problems. Search intent and GEO are covered in more depth by their own audit.

See the SEO/GEO audit

What the assessment is based on

  • repository and Composer lock file
  • configuration, deployment and hosting information
  • selected logs, monitoring and operational data
  • any existing backup and restore evidence

Not part of this technical Drupal audit

  • penetration tests and active vulnerability scans against the target system
  • load tests, changes on production and active restore drills
  • implementation, ongoing maintenance, and separate UX, accessibility or in-depth SEO/GEO audits

How deep we go follows the decision you are facing

The starting point ranges from a single, clearly bounded technical question to a full assessment with a joint workshop on what to do next.

Focused check

For one clearly stated question about support status, security advisories, the ability to update, or a bounded operational risk.

You receive prioritised findings on the agreed technical question.

Full technical assessment

For a broader look at architecture, code, configuration, security, performance and operation across the agreed system scope.

You receive the state of the assessment, a list of findings and a prioritised action plan.

Assessment with an action workshop

When engineering, product owners and operations need to agree on responsibilities and sequence together.

Responsibilities and the next decisions are ordered jointly on top of the findings.

How the audit runs

  1. Agree the scope and the accessSystems, the question to answer, methods, the state to assess and read-only access.
  2. Examine what is thereArtefacts, configuration, code, architecture and the available operational data.
  3. Put the findings in contextEvidence, impact, status, dependencies and priority.
  4. Hand over the resultsWalk through the report, the action plan and the open questions together.

Frequently asked questions

On access, active security testing, implementation and neighbouring audits.

No. A passive inventory and a review of code and configuration can be part of the audit. Penetration tests and active vulnerability scans against the target system need their own scope and explicit authorisation.

Depending on the scope, we need read-only access to the repository, the Composer lock file, configuration, deployment and hosting information, and to selected logs, monitoring data and backup evidence. Anything we cannot reach is documented as not assessed.

No. The report can be acted on by your own team, by another supplier or by PROGRESSIVE. Findings and dependencies are documented so that anyone can pick them up. Recurring updates and operational tasks then belong in Drupal maintenance, not in the audit.

The UX audit looks at obstacles people run into. The accessibility audit examines barriers, and the SEO/GEO audit goes deeper into search intent, landing pages and visibility.

Which technical decision should the audit prepare?

We agree the systems, the access, the methods, the exclusions and the format of the result. You then receive a quote.

Define the scope