Skip to content
Audit

Production Health Audit

Your app is live and something is wrong. This tells you what's broken, what it's costing you, and what to fix first.

For React and Next.js apps in production — especially ones built fast with AI.

Tell me what is breaking

Two weeks, from $750. Read-only access, no meetings to start.

Coverage

What I look at.

Performance

Core Web Vitals, bundle size, render bottlenecks and slow data fetching.

For example: whether the largest image on a page is rendered client-side, so the browser pays a second round trip before anything appears.

Stability

SSR errors, hydration mismatches, memory leaks — the crashes that are hard to reproduce.

For example: whether anything is formatted from the server clock during render, so server and browser disagree and React discards the markup it just shipped.

Security

Exposed keys, missing server-side authorization, unvalidated input — the gaps AI code leaves most.

For example: whether an endpoint checks permissions only in the UI and not on the server, leaving the data one fetch call away.

Code health

Duplication, dead paths and structure — how painful your next six months will be.

For example: whether the same fetch-and-cache logic is pasted across many components, so one upstream change means many edits and a missed one becomes a bug.

Process

How it works.

Four steps, about two weeks end to end. Most of it is my time, not yours.

  1. You send a repo URL and read-only access

    Day one, by message. A staging URL helps if you have one. No call needed to start.

  2. I read the code and run the app

    I profile the app under realistic load, read the parts that handle money, auth and data, and reproduce whatever is actually failing. This is the bulk of the two weeks.

  3. You get the report

    Within two weeks of access. Written in plain language, every finding with the evidence behind it and what it costs you in practice.

  4. A 30-minute call

    We walk the findings, you ask what you want, and you decide what to do with it. No pitch attached.

What I need

What I need from you.

  • The repository URL, with read-only access for one account.
  • A staging or preview URL if one exists. Production works too, I only look.
  • One sentence on what feels wrong. "It gets slow after a while" is enough to start.

That is the whole list. No production secrets, no write access, no environment credentials, and no meetings before we begin. If your team needs an NDA first, send yours and I will sign it.

Scope

What this is not.

  • Not a rewrite. I tell you what to change; I do not rebuild your app to my taste.
  • Not a security pentest. I read the code for the gaps AI-written code leaves most, but I do not attack your infrastructure or test you against a compliance standard.
  • Not a code-style review. Naming and formatting are not findings unless they are actively costing you something.
  • Not a guarantee that nothing else is wrong. Two weeks buys depth where it matters, not a clean bill of health.
Deliverable

What you get.

  • A written report in plain language — every finding with evidence and business cost.
  • A prioritized fix list with effort estimates — what to do now, what can wait.
  • A 30-minute call to walk through the findings and answer questions.
Price

Agreed up front. No surprises.

from $750delivered within two weeks of access

The number you get up front is the number you pay. $750 covers one application; monorepos are quoted after I see the repo.

If you'd like me to implement the fixes too, the audit fee comes off the project.

No meetings to start — just a URL and read-only repo access. Never write access, never your production secrets.

FAQ

Before you ask.

What if you find nothing?

Then the report says so, and I tell you plainly rather than padding it with findings you do not have. A short, honest report is a real result: it rules out the code as the cause and points you at infrastructure, data or product instead. If you would rather not risk the fee on that outcome, say so before we start and we will agree what happens in writing.

Can you fix what you find?

Usually, and the audit fee comes off that work. The fix list is written so another developer can act on it too, so it is useful to you whether or not you hire me for the next step.

Do you sign an NDA?

Yes. Send yours and I will sign it before you send the repo. I do not publish client names, logos or screenshots without written permission: the case studies on this site describe the work without identifying who paid for it.

What if it is a monorepo?

The $750 covers one application. A monorepo is quoted after I see it, because the honest answer depends on how many deployable apps live inside. It is usually a single number, not a multiple.

Contact

Tell me what's broken

Tell me what your app is doing — I'll say whether an audit is even the right call.

No newsletter, no follow-up sequence — your details are used only to reply.

Prefer to start directly?