forumNew topic

Agency is handing over the code — is there a tool I can use to check the quality before accepting?

KKemal K***Veteran
Job title
Software developer
Sector
Furniture manufacturing
Organization type
family business
Joined
Feb 2023
Message
57

Doki · Interface design · 2026

#1

We hired a local digital agency for our Munich-based industrial parts wholesale company. They're developing a B2B dealer portal where our clients can view custom price lists and place orders. We allocated a total budget of 22,000 Euro for the project, and final delivery along with the code transfer is scheduled for next month.

Per our contract, they will transfer the source code via a repository. The issue is, I'm not an engineer, and we don't have a developer on staff who can read through the code line by line to understand its architecture, catch security vulnerabilities, or spot bloated, copy-pasted blocks. The agency claims they do great work, but I want peace of mind before hitting that acceptance button.

Is there an automated source code analysis tool that a non-technical business owner can run to evaluate overall technical health, security vulnerabilities, or compliance with coding standards? What exactly do these tools inspect, and where do they fall short?

YYağmur A***Member
Job title
Technical service technician
Sector
Healthcare services
Organization type
300-person organization
Joined
Feb 2024
Message
349
Most Helpful#2

Short answer: Automated static code analysis scanners can assess code quality, security flaws, and duplicated blocks, presenting everything in a single report. However, these tools only check technical syntax and known vulnerabilities; they cannot evaluate whether the system properly implements your business logic or whether the database will crash under heavy traffic.

Here are the steps you can follow before the agency hands everything over: 1) Connect the code repository to cloud-based static analysis tools that offer a free tier or a project-based trial. These systems summarize metrics like security vulnerabilities, code complexity, and maintainability into simple letter grades. 2) Run dependency scanners to check whether third-party libraries are up to date and flag known security vulnerabilities. 3) Officially request a test coverage report from the agency to see if unit tests were written and how much of the codebase they actually cover.

If the automated report flags numerous critical issues, you have every right to send this list to the agency and demand fixes before signing the sign-off document. Still, for a 22,000 Euro investment, the safest approach is to take these automated reports and hire an independent senior software consultant for 3–4 hours of architectural review, which usually costs around 400 to 800 Euro.

BBarış Y***Expert
Job title
Backend developer
Organization type
boutique agency
Joined
Jun 2023
Message
296
#3

Automated tools run static application security testing (SAST). They easily catch SQL injection risks, exposed API secrets, and non-standard function structures. The first three metrics to check are: 'Critical Security Vulnerabilities', 'Code Duplication Rate' (under 5% is acceptable), and 'Unit Test Coverage'.

ZZehra D***Expert
Job title
IT manager
Sector
Food wholesale
Organization type
120-person company
Joined
Feb 2025
Message
44

Doki · Server maintenance contract · 2024

#4

The tool might say the code follows best practices, but it has no idea whether the portal calculates VAT correctly when an order is placed. I've seen plenty of software pass static scans with zero errors only to botch the order total on its very first day in production. Don't rely solely on automation; real-world scenario testing is a must.

AAli T***MemberCommunity member
Joined
Sep 2023
Message
37
#5

On our 15,000 Euro custom CRM project, we hired an independent expert to review the code for 600 Euro. The report uncovered an outdated PHP library and 4 queries that would have locked up the database. The agency fixed them with zero pushback. That 600 Euro saved us at least 3,000 Euro in future revision costs.

MMerve T***ExpertCommunity member
Joined
Feb 2024
Message
13
#6

Check your contract. Is there a 30 or 60-day warranty or bug-fix clause post-delivery? Even if you pull a report from a code analysis tool and lay it in front of them, the agency can easily brush it off saying "the code runs fine" if the contract lacks binding clauses about code standards.

HHatice K***MemberCommunity member
Joined
May 2024
Message
131
#7

Don't try to play developer; just be upfront with the agency. btw tell them, "Per our company policy, we run all code through an independent static analysis tool and attach the report to the handover sign-off." Hearing that alone usually gets them to clean up the obvious junk in the code before delivery.

DDilara Y***Veteran
Job title
Human Resources Manager
Sector
Real estate
Organization type
8-person team
Joined
Oct 2024
Message
98
#8

Can these tools also detect malicious stuff like viruses hidden in the code? And can we tell whether the agency actually wrote the project from scratch or just copy-pasted it off the internet?

Edit: asked below, I wrote the answer in the second message.

FFerhat G***New memberCommunity member
Joined
May 2026
Message
180
#9

The minimum three things you should demand from the agency at handover: 1) A setup and run guide, 2) A license list of all open-source libraries used (must permit commercial use), 3) Deployment scripts proving the system can spin up from scratch in an independent environment.

AAyşegülMember
Job title
Boutique hotel
Organization type
workshop
Joined
Aug 2024
Message
86
#10

I completely agree. btw don't hesitate to ask; those who don't ask always pay more.

Mistakes made on the source code analysis tool side are usually reversible but expensive. If you have questions, write them; I'll answer as best I can.

SSena Ç***Member
Job title
Software team lead
Sector
Security services
Organization type
120-person company
Joined
Jan 2025
Message
29
#11

I went through the same thing.

EErcan B***Member
Job title
Graphic Designer
Sector
Security services
Organization type
boutique agency
Joined
Mar 2026
Message
46
#12

i completely agree. like mistakes made on the source code analysis tool side are usually reversible but expensive.

weekly written progress reports are much more usful than asking for dates then btw hope this helps.

PPolat Ç***Member
Job title
Human Resources Manager
Sector
Media and publishing
Organization type
workshop
Joined
Oct 2022
Message
2

Doki · Vulnerability scanning · 2024

#13

The most overlooked point about source code analysis tool is this: Everything goes well for the first three months; problems arise in the fourth.

That's all, sorry if I went on too long.

AAv. Kemal U***Expert
Job title
Lawyer · IT
Organization type
300-person organization
Joined
Sep 2023
Message
168
#14

Correct.

AAhmet Z***MemberCommunity member
Joined
Feb 2024
Message
25
#15

You're right, I've been down that road too. The cheapest quote is usually the least thought-out one.

Just leaving this note, it might be useful.

UUfuk S***Member
Job title
Front office accounting
Sector
Agriculture
Organization type
cooperative
Joined
Jun 2022
Message
74

Doki · Incident response support · 2025

#16

You're right, I've been down that road too. If code ownership isn't in the contract, you have no bargaining power when leaving.

Proven by experience.

CCem I***MemberCommunity member
Joined
Sep 2025
Message
4
#17

I disagree with you on this point. The biggest time-waster for us was not knowing who had the final say.

CCansu C***MemberCommunity member
Joined
Mar 2022
Message
66
#18

Thanks this was very helpful.

DDamla A***MemberCommunity member
Joined
Jul 2025
Message
179
#19

The discussion got scattered, let me summarize. When making decisions, write down the worst-case scenario too, not just the best.

Ask who prepared the quote and who will actually do the work.

ÖÖmer M***MemberCommunity member
Joined
Nov 2023
Message
108
#20

The opposite happened to me, that's why I'm writing. When we decide without measuring, we always end up in the same place.

Correct me if I'm wrong.

Reply