We run a wholesale food business in Munich and are having a custom order management portal developed for our clients. We agreed with a local software agency for 14,500 EUR, and the project took about four months. Next week we are moving to the acceptance and handover phase.
Yesterday the agency rep sent over the final checklist and recommended running a static source code analysis before handover. For this they want to tack an extra 1,800 EUR service fee onto the invoice. Their reasoning is that security vulnerabilities and flaws in the code architecture can only be guaranteed through this analysis.
I know nothing about coding. What exactly is this static source code analysis? Isn't it a standard quality step that should already be done during regular development, or is it genuinely a critical process that we need to pay extra for?