forumNew topic

Agency wants extra money for static source code analysis — what is this, is it necessary?

İİlker T***Member
Job title
Food wholesaler
Joined
Dec 2023
Message
58
#1

We run a wholesale food business in Munich and are having a custom order management portal developed for our clients. We agreed with a local software agency for 14,500 EUR, and the project took about four months. Next week we are moving to the acceptance and handover phase.

Yesterday the agency rep sent over the final checklist and recommended running a static source code analysis before handover. For this they want to tack an extra 1,800 EUR service fee onto the invoice. Their reasoning is that security vulnerabilities and flaws in the code architecture can only be guaranteed through this analysis.

I know nothing about coding. What exactly is this static source code analysis? Isn't it a standard quality step that should already be done during regular development, or is it genuinely a critical process that we need to pay extra for?

MMustafa O***MemberCommunity member
Joined
Feb 2024
Message
77
Most Helpful#2

Short answer: Static code analysis is an audit process that scans the source code text using automated algorithms without actually executing the software, flagging security vulnerabilities, memory leaks, logic bugs, and non-standard coding practices. This method is very useful for catching potential risks during development, but under modern software standards, it should not be considered an optional luxury—it belongs in the routine development pipeline.

The agency asking you for 1,800 EUR is questionable for several reasons: 1) These days, static analysis consists of automated scripts that run in minutes with software tools; it is not a human manually reading code line by line for weeks. 2) This process basically catches SQL injections, weak encryption methods, dead code, and deviations from architectural standards. 3) Charging you extra just to check the quality of their own code is commercially unethical.

For a small-to-mid-sized order portal project, this check is certainly beneficial, but rather than paying the agency this money, you should take one of two paths: First, rely on the contract's general quality and defect-free delivery clauses to demand this basic test report at no extra charge. Second, take delivery of the codebase, have an independent external specialist scan it for a nominal fee, and put an unbiased report in front of the agency.

ÖÖzgür A***ExpertCommunity member
Joined
Feb 2025
Message
1
#3

I've been managing software projects for years, and this request sounds completely like an attempt to milk extra revenue. Modern software teams hook static analysis tools straight into their CI pipelines so they run automatically on every single commit. Telling a client 'let us check our own work before handover, but you have to pay for it' is simply unacceptable.

BBurak Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
cooperative
Joined
Mar 2022
Message
104
#4

Static analysis inspects the code's syntax tree. It flags vulnerabilities in database queries, exposed API keys, or library incompatibilities without running the code. It's useful, but it literally boils down to running a tool and exporting a PDF. Unless it includes a manual line-by-line audit, it technically costs nowhere near 1,800 EUR.

KKader K***MemberCommunity member
Joined
Oct 2023
Message
6
#5

Happened to us in Stuttgart on a B2B portal with a similar budget of 16,000 EUR. They wanted 1,200 EUR, we refused. We accepted the code, paid a freelance senior dev 350 EUR to run an external audit. We then made the agency fix the 8 critical issues found under their warranty obligation.

AAlper K***Member
Job title
Content Editor
Sector
Sports and fitness
Organization type
sole proprietorship
Joined
Mar 2024
Message
60
#6

You can't trust the agency's report anyway. When they run their own tools, they can easily dial down the filters to produce a squeaky-clean report. The auditor and the developer cannot be the same entity. If you're going to spend extra budget, never give it to the agency that built the project.

AAli Y***MemberCommunity member
Joined
Mar 2025
Message
157
#7

if we don't get this analysis done at all, will we run into security issues while the system is running? i mean, does skipping it directly break the site or is it only about hidden background bugs?

UUğur Ö***Member
Job title
Sales Manager
Sector
IT services
Organization type
regional distributor
Joined
Jan 2024
Message
5

Doki · Brand identity · 2026

#8

Open your contract right now and read the delivery acceptance criteria. If it mentions delivering 'secure code adhering to industry standards', demand this report as a mandatory quality document without paying an extra dime. If they refuse, don't pay anything extra, just wait for the handover.

MMert E***MemberCommunity member
Joined
Sep 2024
Message
28
#9

def do not pay. they will just push one button to run a tool and hand you a pdf file. total waste of money makes way more sense to get an outsider to inspect it after delivery.

OOnur K***Expert
Job title
R&D Manager
Joined
Aug 2023
Message
142
#10

Under the principles of contract for work (Werkvertrag) in German law, the contractor is obligated to deliver a defect-free product. Any issues revealed by static code analysis are essentially flaws that should have been remediated prior to delivery. Passing this auditing cost onto the client is legally very questionable.

EEsra T***Member
Job title
Data Analyst
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
66
#11

let me write how it's done in practice. takinng notes for two weeks yields better results than a six-month estimate.

i'm also curious if anyone does it differently.

ÖÖzge T***Expert
Job title
Brand Consultant
Organization type
regional distributor
Joined
Jun 2023
Message
164

Doki · E-commerce infrastructure · 2023

#12

You're right. The cheapest quote is usually the least thought-out one.

If I were you, I'd go this route.

LLale K***MemberCommunity member
Joined
Oct 2024
Message
253
#13

Timely topic.

FFatma C***MemberCommunity member
Joined
Sep 2024
Message
13
#14

I'm curious too.

RRıdvan Ö***MemberCommunity member
Joined
Apr 2025
Message
5
#15

Don't miss this: The biggest time-waster for us was not knowing who had the final say.

Solutions that work at a small scale collapse when you grow; I learned this late. If you post the result here it will help others too.

SSelin Ö***MemberCommunity member
Joined
Nov 2025
Message
336
#16

We experienced almost the exact same thing last year. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Just leaving this note, it might be useful.

OOya G***Member
Job title
Production Manager
Sector
Catering
Organization type
300-person organization
Joined
Oct 2023
Message
66
#17

Same here.

GGizem Y***Expert
Job title
Marketing manager
Organization type
a company within a holding
Joined
Sep 2023
Message
168
#18

I completely agree. Everyone rushing into static code analysis gets stuck at the same point.

Hasty decisions become decisions you have to fix six months later. That's all, sorry if I went on too long.

AAli Ö***Member
Job title
Accounting clerk
Sector
Plastic
Organization type
20-person company
Joined
Nov 2023
Message
42

Doki · Mobile app · 2023

#19

Same here. Mistakes made on the static code analysis side are usually reversible but expensive.

This is my opinion, I'm not claiming it's absolute truth.

TTolgaNew member
Job title
Developer
Organization type
cooperative
Joined
Nov 2024
Message
41
#20

Just a heads-up. If acceptance criteria aren't written, when the work is done is open to debate.

Don't hesitate to ask; those who don't ask always pay more. Correct me if I'm wrong.

Reply