Skip to content
Call 03333 20 97 97
bristol.digital: empowering ideas
Legacy PHP rescue and modernisation
On this page

PHP security audit and fixes

Find the vulnerabilities in your old application before somebody else does, and fix them.

Older PHP applications often contain patterns that were acceptable when they were written and wouldn't be today: weak password storage, unsafe database queries, forgotten admin pages, abandoned libraries. Attackers scan for these automatically, around the clock.

I review your application and server, prioritise what actually matters, and fix it.

Book a free conversationLegacy System Assessment, from £2,500


Signs you need one

  • You run unsupported PHP, a framework or a CMS that no longer receives security fixes. Check your PHP version
  • You've failed or expect to fail Cyber Essentials, a customer security questionnaire or an insurer's renewal checks
  • A penetration test has produced a list of findings nobody knows how to fix
  • You've been hacked before, or suspect you may have been. Hacked site cleanup
  • You hold personal or payment data, and you've never had the code reviewed
  • The original developer has gone, and nobody can say whether it's secure

What I review

Area Typical issues I look for
Input handling SQL injection, cross-site scripting (XSS), command injection
Authentication Weak password hashing (e.g. MD5 or SHA-1), no multi-factor authentication, default or shared logins
Authorisation Users reaching other users' data, admin functions without proper checks
Sessions and cookies Session fixation, missing security flags, long-lived tokens
Request forgery Missing CSRF protection on forms and actions
File uploads Executable files uploaded, no type or size checks
File handling Path traversal, unsafe includes, exposed backups
Dependencies Outdated or abandoned libraries with known vulnerabilities
Secrets Passwords and API keys in code or in public repositories
Configuration Debug mode on, phpinfo() pages, exposed .env or .git directories
Encryption Outdated TLS, missing HTTPS, unencrypted sensitive data or backups
Server and infrastructure Unpatched operating system, open ports, weak SSH, file permissions
Logging and monitoring Nothing recorded, so attacks go unnoticed
Backups and recovery Untested, stored on the same server, or non-existent

This broadly follows the OWASP Top 10 categories, adapted to PHP and to the realities of ageing systems.


How I work

1. Scope

We agree what's in scope: the application, the server, or both, and what data is involved. I work from copies and read-only access wherever possible. How I handle access

2. Discover

I use AI-assisted analysis across the whole codebase, with automated scanning of dependencies and configuration, to find likely weaknesses far faster than a purely manual review. How I use AI

3. Verify

Every finding is checked by a person. Automated tools produce false alarms, and a report padded with false positives wastes your time. I confirm which issues are real and how exploitable they are.

4. Prioritise

Findings are rated by seriousness and likelihood, in plain English: what could happen, how likely it is and what to fix first. Not a 200-page scanner printout.

5. Fix

Where you want me to, I fix the issues, with tests around the changes, human review and a staged rollout, so the fixes don't break the application.

6. Report

You receive a written report you can show to customers, insurers and auditors, and a record of what was changed.


What you receive

  • A prioritised risk register
  • A plain-English summary for owners and non-technical decision-makers
  • A technical report for whoever maintains the application
  • Fixes, where included in scope
  • Recommendations for longer-term hardening, upgrades and monitoring

What this is not

I'm straightforward about the limits:

  • It's a code, configuration and architecture review. It is not a formal penetration test or a certification. If you need an accredited penetration test for compliance, I can help you scope one and fix what it finds.
  • I can't guarantee an application is unhackable. No one can. The goal is to remove the real, known weaknesses and make attacks harder and easier to detect.
  • I provide technical remediation, not legal advice or Data Protection Officer services. Data protection and security

Compliance support

I can fix the technical findings behind failures in Cyber Essentials, cyber insurance questionnaires, customer supplier audits and PCI DSS requirements, and supply the documentation to support your answers. I can't certify you against any of them.


What it costs

A security review is included in the Legacy System Assessment, from £2,500. If you want a focused security-only review, tell me about the system and I'll quote a fixed price after a free conversation.

Fixes are quoted fixed-price where scope is clear, or at £950 per day for open-ended work. Urgent incident work is from £1,300 per day. Pricing


For agencies

If a client has had a penetration test result or failed questionnaire and your team doesn't want to fix a legacy application, I can do it white-label or direct. Agency terms


Frequently asked questions

Is this the same as a penetration test?

No. A penetration test attacks a running system from outside. My review examines the code, configuration and architecture from inside, which often finds problems a test misses, and gets them fixed. If you need a formal test for compliance, I can say so and help you prepare.

We already have a penetration test report. Can you fix the findings?

Yes. That's common. I'll turn the findings into a prioritised plan and fix them, with tests, so the fixes don't break anything.

Will you find everything?

Not everything, and nobody honestly can. I'll find the significant, real problems, and tell you clearly what I looked at and what I didn't.

Do I need to upgrade PHP as well?

Often, yes. Unsupported software is itself a risk, and some vulnerabilities can't be fixed without upgrading. I'll tell you what's essential and what can wait. PHP upgrades

What if you find evidence we've already been hacked?

I'll tell you promptly. You may have legal duties to report a breach, so take advice quickly. Hacked site cleanup

Will you need access to live data?

Usually not. Most of the work can be done on code, configuration and limited or sanitised data.


Tell me what you've inherited.

Not sure how exposed you are? Tell me about the system and I'll tell you honestly what a review would involve.

Book a free conversationLegacy System Assessment, from £2,500

Call Book a free conversation