All services

Project handover

Your PHP project has no developer any more. I take it on, with an assessment instead of a gut feeling.

The supplier is out, the developer resigned, or the agency no longer exists. The system keeps running and keeps earning money, but nobody dares touch it. I take such projects on: first an assessment that tells you where you stand, then step by step back into a state where changes are plannable again.

No documentationNo handoverOne contact950 € fixed
What you get
  • An assessment: what the system does, what it runs on, where it hurts
  • A risk list by urgency, with an effort estimate per item
  • Access to operations and deployment, written down instead of in someone’s head
  • A test net around the places that get touched first
  • Further development in steps, each one live on its own
  • Handover to your team, whenever you want it
Scope & working together

No subscription, no minimum spend. The entry point is a fixed price assessment, after that by effort or as a scoped project, whichever fits better. Also for systems without documentation and without the people who built them.

Remote from Germany. Straight with me, no agency in between.

The starting point

The problem is not the code. It is the missing knowledge.

A system that has been running for years carries decisions nobody can explain any more. Why one place rounds the way it does. Why an order gets written twice. Why that one cron job has to run at three and not at four. The code says what happens, not why, and the person who knew is no longer there.

That is why the first step is not a rebuild but understanding. What does the system actually do today, which quirks does it have, and which of them is somebody relying on without knowing it. Cutting corners here means building the first change on an assumption, and the bill arrives in production.

The second part sits outside the code: where the system runs, who holds the access, how a change gets out, and what happens if the server fails tomorrow. On projects taken over, that is regularly the more urgent part.

Does any of this sound familiar?
  • The developer or agency is gone, and there was no handover.
  • There is no documentation, no tests and nobody left to ask.
  • Nobody knows exactly where the system runs and who holds the access.
  • Small changes take weeks because nobody dares go near it.
  • An outage would be expensive, but there is no rehearsed way back.
  • Quotes for a rebuild are on the table, but nobody can put a number on what exists.

Who this is for

For companies whose productive PHP system suddenly has no responsible developer.

For managing directors, CTOs and product owners after a developer or supplier leaves. The system still runs, but knowledge, access and risks are not sufficiently documented.

01

Operations must be secured first.

Deployments, backups, access and acute risks need to be understood before feature work resumes.

02

Code and infrastructure are accessible.

Repositories, hosting and accounts can legally be transferred even if documentation is missing.

03

You need decision-making ability back.

The assessment must show what is urgent, what can wait and how ownership should continue.

What I do

What happens along the way

01

An assessment instead of a gut feeling

PHPStanComposer AuditDependency graph

Static analysis across the whole codebase, plus the dependencies, the runtime and the path a change takes to get out. The result is not a grade but a list: what the system does, what is a risk, roughly what fixing it costs. That lets you decide, including against me.

02

Access and operations first

Access inventoryBackupsRecovery

Before anything else, the question whether you can act in an emergency: who has access to server, domain, database and repository, do backups exist, and has one ever been restored. On projects taken over this is regularly the largest gap, and the cheapest one to close.

03

A safety net before the first change

PHPUnitCharacterization testsGolden master

Where no tests exist, characterization tests come first: they record what the system does today, regardless of whether it is right. The net does not have to be complete, it covers the paths that money hangs on. After that the first change is no longer a jump in the dark.

04

The most urgent risks first

PHP upgradeSecurity updatesA way back at every step

A PHP version without security updates, a package with a known hole, an account a former colleague still has. Such items come before any further development, and they come one at a time: each step goes live on its own and can be reversed on its own.

05

Making it changeable again

Further developmentFeature flagsStaged rollout

Only then the thing you actually called about: new features, a rebuild, an integration. The difference is that a net is in place now and someone can say what a change will set off.

06

Handover, whenever you want

DocumentationCI checksOnboarding

The goal is not that you need me. What comes out belongs to you: the tests, the documentation, the pipeline. When your team takes over or a new developer arrives, the handover is a meeting, not a project.

Is your system running without anyone who understands it?

Send me the key details. You get an assessment of what a handover would mean for you, before you commission anything.

How it runs

How this runs

Four steps, and after the second you know what you are getting into. No step assumes you commission the next one.

STEP 01

A 30 minute conversation

What kind of system is it, how long has it run without care, what hurts most right now. After that I tell you whether I am the right person. If I am not, I say so.

STEP 02

Assessment

Read access to the repository and to operations is enough. The result is a list with risks, effort and an order, plus an hour to go through it. Then you decide.

STEP 03

The urgent items

Access, backups, security updates, a test net around the critical paths. Rolled out one at a time, each step with a way back.

STEP 04

Further development or handover

From here it is about your plans. Or about a handover to your team, once you have someone again. Both are valid outcomes.

The other side

What the current state costs you.

The total is not printed below, because I do not know it. I do know the items, and in almost every case two of them already add up to a multiple of what the entry package costs. Do the maths yourself, then the number is yours.

  1. 01
    StandstillWhich plans are on hold because nobody wants to touch the system, and what would they be worth to you?
  2. 02
    Changes that take too longHow many days does a small change cost today, and how many would it be with someone who knows the system?
  3. 03
    An outage without a rehearsed recoveryWhat does a day of standstill cost, and how likely is it to hit you in the next year?
  4. 04
    Search and onboardingHow long will you look for someone with this stack, and how many weeks until they deliver?
  5. 05
    The rebuild you are considering insteadWhat figure is in that quote, and by what factor does it exceed the entry package here?

The entry package below costs less than a single working day of standstill in most companies. It replaces none of these figures, but it makes them provable for the first time.

Entry offer

Able to act within a week. Fixed price 950 €

Fixed price. Everything after that is quoted by scope, before it starts.

Not a report but a state: after a week you know where your system sits, who has access to it, and that a backup actually works. One acute item is fixed along the way. That holds even if you decide against me afterwards.

What you get

  • Access inventory: server, domain, database, repository, third party services, with the contracts behind them
  • One backup restored as a test. Not checked whether it exists, checked whether it works
  • Accounts of former staff and suppliers identified, with a recommendation to revoke
  • A system overview a new developer can read in a day
  • A risk list by urgency, with an effort estimate per item
  • One acute item from it fixed straight away, up to four hours. You pick which
  • An hour to go through it with you or your team, recorded on request

What you do not get

  • No fixing of the remaining risks beyond those four hours, that is quoted afterwards
  • No refactoring, no new features, no upgrade
  • No security review in the sense of a penetration test
  • No verdict on whether a rebuild would be cheaper without knowing its scope
  • No ongoing availability without an agreement of its own
  • Read access to the repository and to operations is enough. The restore test uses a separate environment, production stays untouched
  • The immediate fix needs write access to the affected part. What changes there is agreed beforehand and can be reversed on its own
  • Price net, plus VAT
  • Above roughly 200,000 lines or several applications the scope is agreed beforehand
  • The amount is credited if you commission me afterwards
  • You are committed to nothing. Some clients hand the results to their own team, and that is a valid outcome

The outcome

What is different afterwards

You know where you stand

Instead of an uneasy feeling, a list: what the system does, what is a risk, what fixing it costs. That is also the basis for deciding about a rebuild at all.

Able to act in an emergency

Access inventoried, backups tested, a recovery that has been rehearsed once. That is the part that costs nothing and saves everything.

Changes are plannable again

With a test net and a traceable path to production, a change is a task with a date again instead of a bet.

Not dependent again

What comes out belongs to you and is written down. The next developer needs days to get up to speed, not months.

Technologies I use

Technologies I use

Language
  • PHP 8.2
  • PHP 8.3
  • PHP 8.4
  • PHP 8.5
Frameworks
  • Symfony
  • Laravel
  • Laminas
  • Slim
Analysis
  • PHPStan
  • Psalm
  • Rector
  • Composer Audit
Tests
  • PHPUnit
  • Pest
  • Xdebug
  • Characterization tests
Data
  • MySQL
  • MariaDB
  • PostgreSQL
  • Doctrine
  • PDO
Runtime
  • Docker
  • PHP-FPM
  • Nginx
  • Apache
  • Valkey / Redis
Operations
  • AWS
  • Terraform
  • CloudWatch
  • Backups
Delivery
  • GitHub Actions
  • GitLab CI
  • Blue/green
  • Feature flags

Evidence

PHP and Zend Framework certified.

Most suppliers know the destination. With an old system, what decides the outcome is whether someone also knows the starting point: why a passage is written the way it is, and what replacing it sets off. Zend Technologies no longer exists under that name, and neither do the exams of the time. For the database side there is an Oracle certification on MySQL 5, because that is where the quieter traps sit: character sets, collations and a strict mode that starts refusing what used to pass.

Zertifikat: Tim Rutte, Zend Certified Engineer PHP 5.3, ausgestellt von Zend Technologies
Zend Certified Engineer – PHP 5.3
Zertifikat: Tim Rutte, Zend Certified Engineer Zend Framework, ausgestellt von Zend Technologies
Zend Certified Engineer – Zend Framework
Tim Rutte, Cloud & Software Architect

Who you are talking to

Directly with me as a freelancer. No agency in between.

I am Tim Rutte. More than 20 years in software development, and I regularly take on systems whose developers are gone. You talk to the person who touches your code, from the first call to the handover.

  • 20+years in software development
  • 50+successful projects
  • 2003working remotely since then
More about me

Common questions

Common questions about project handover

There is no documentation and nobody to ask. Does this still work?

That is the normal case, not the exception. It is exactly why the assessment comes first: it reconstructs from code, database and operations what the system does. Whatever cannot be settled that way goes on the list as an open question instead of disappearing into an assumption.

What does a handover cost?

The entry package costs 950 euros net at a fixed price and tells you what everything else costs. Without it any number is guessed: two applications with the same line count can be a factor of ten apart, depending on whether the dependencies are maintained and whether tests exist. After that I work by effort or as a scoped fixed price project, whichever fits better.

Do you also take on ongoing care?

Yes, but without a subscription and without a minimum spend. There are months with nothing to do, and those should cost nothing. What I commit to is being reachable in an incident and a response time agreed beforehand.

Would a rebuild not make more sense?

Sometimes it would, but that decision can only be made once what exists has a number on it. A rebuild has to do everything the old system does, including the quirks nobody documented and somebody relies on anyway. That is why the assessment comes before the question, not after it. Why rewrites fail so often is something I have written up in an article.

How quickly can you start?

For the conversation usually within a few days, for the assessment one to two weeks later depending on load. If something is burning, because the system is down or a hole is open, say so in the first sentence. Then I sort differently.

What about the previous supplier?

If they are reachable, an hour of handover is the best thing that can happen to you, and I ask specifically about the things that are not in the code. If they are not reachable, nothing changes about the approach. It takes longer, and the assessment carries more weight.

Do I get the access and rights myself?

Yes, and that is part of the assessment. At the end there should be a list on your side of who has access to what, which contracts sit behind it, and what happens if I am gone tomorrow. Accounts belonging to a former colleague go on the same list.

Do you handle the PHP upgrade as well?

Yes, it is often the first urgent item after the assessment. It is a project of its own with its own order and its own way back, and it has a page of its own with the details.