How to Get Technical Due Diligence Right
Assessing the state of a website or application before acquiring, inheriting or taking over its maintenance.
The key figures
- Dependencies
- outdated components carry security risk
- Licensing
- open-source licenses have obligations
- Documentation
- its absence signals maintenance cost
- Access
- account ownership must be verifiable
Why this is worth getting right
Hidden technical debt, licensing issues and security problems are expensive surprises after the handover.
Do this, not that
Do
- Review dependency currency and known vulnerabilities
- Check open-source license obligations
- Verify account and domain ownership
- Assess documentation and test coverage
- Estimate remediation work before committing
Don’t
- Taking over systems without assessment
- License obligations discovered later
- Accounts left with previous suppliers
- Debt assumed to be small
When to bring in help
Our advice Bring in help before acquiring or inheriting systems.
Where this comes from
- OWASP — Vulnerable Dependency Management Cheat Sheet
- Creative Commons — About CC Licenses
The figures and practices above come from the sources listed.
Working on something like this?
We take on Web Design & Development work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.
Where to go next
Spotted something wrong? Report an error on this page. We correct on the page and say what changed.