"Every time we fix something, something else breaks"
It isn't carelessness. It's an application with hidden connections and no safety net.
You ask for a small change and get a new problem somewhere unrelated. The invoice is wrong after someone fixed the login. The report changed when somebody tidied a form. Everyone becomes nervous about touching anything.
This is one of the most common signs of an ageing PHP application, and it's fixable. The answer isn't more careful developers. It's making the connections visible and building a safety net.
Book a free conversationLegacy System Assessment, from £2,500
Why it happens
- Hidden connections. The same function, table or setting is used in places nobody remembers. Change it in one place and others change too.
- Copied code. The same logic exists in several places. Fix one copy and the others behave differently.
- Shared state. Global variables, sessions and shared database tables mean one part can silently affect another.
- Side effects. A function that "just" calculates a price also changes a record, sends an email or writes a log, and something else relies on that.
- No tests. Without automated checks, a break is discovered by a customer, not by a developer.
- No documentation. Nobody can tell you what depends on what.
- Code written for the pressure of the day, then built on top of for fifteen years.
- Different behaviour in different environments, so a change that worked on a test server fails on the live one.
None of that is anybody's fault. It's the accumulated result of reasonable decisions made under time pressure.
What doesn't work
| Common reaction | Why it falls short |
|---|---|
| "Be more careful" | Nobody can be careful about connections they can't see |
| More manual testing | Slow, incomplete, and forgets the corners of the application |
| A big "freeze" before every release | Delays everything and doesn't find the hidden connections |
| Hiring more developers | New people find the same traps, more slowly |
| Rewriting from scratch | Expensive, risky and loses the knowledge in the code. Rewrite vs refactor vs upgrade |
What does work
1. Make the connections visible
I map how the application hangs together: what calls what, which tables each process touches, where logic is duplicated. AI-assisted analysis makes this far faster than it used to be, and I check what it finds against the running application. How I use AI
2. Build a safety net where it matters
I don't try to test everything. I write tests that capture how the important behaviour works today: orders, payments, invoices, reports, permissions. Then a change that alters something it shouldn't is caught before it reaches a customer.
3. Find the hot spots
A small part of most applications causes most of the breakage. Identify them, protect them, and untangle them first.
4. Change in small, reversible steps
Small changes, each tested and reviewed, with a way back. A big change is hard to check. A small one isn't.
5. Test somewhere that looks like production
A staging environment that matches the live one, using anonymised or synthetic data where personal data is involved, so you find problems before customers do.
6. Watch it in production
Error monitoring and logging, so problems are seen in minutes, not weeks.
7. Write it down
Documentation of what the application does and what's fragile, so the knowledge stops living in one person's head. Documentation
What changes for you
- Changes stop being frightening, because breakage is caught early
- Fixes cost less, because developers aren't spending days working out what else might be affected
- You can see what's risky, and decide what to fix, leave or replace
- Upgrades become possible. You can't safely upgrade what you can't safely change. PHP upgrades
A realistic start
You don't have to fix everything at once.
- Free conversation about what keeps breaking
- Legacy System Assessment: the structure, hot spots and risks, with a prioritised plan. From £2,500
- A safety net around the worst offenders first, then work outwards
- Ongoing care if you want a technical owner. Ongoing care
For a specific recurring bug, start here: Bug investigation and performance
What it costs
Assessments are fixed-price, from £2,500. Safety-net and stabilisation work is quoted fixed-price where scope is clear, or at £950 per day. Pricing
For agencies
If a client application keeps biting your team, I can stabilise it white-label or direct. Agency terms
Frequently asked questions
Is the code just bad?
Often not. It may be perfectly reasonable code that grew over years without tests or documentation. The problem is the lack of a safety net, and that can be added.
Can you add tests to code that has none?
Yes, and it's usually where I start. I write tests that capture current behaviour, so we can tell when a change alters it. How I work
How long before things stop breaking?
It depends on the application. Protecting the highest-risk areas first often makes a visible difference quickly, and the rest follows in stages.
Do we have to stop development while this happens?
No. The work runs alongside, in small steps, on a copy of your environment.
Will you tell us if it's beyond saving?
Yes. Sometimes the honest answer is partial replacement. I'll say so, with evidence.
Tell me what you've inherited.
Describe what keeps breaking, even if you can't explain it. I'll tell you where I'd look first.
Book a free conversationLegacy System Assessment, from £2,500