Legacy Risk Self-Check

For Owners of PHP, Laravel & Yii Systems

For:
Owners and technical leaders responsible for a PHP, Laravel or Yii system someone else built — especially where the original developers are gone, documentation is thin, or a change that should take days ends up taking weeks.
Why it matters:
Most PHP systems running in production today are already out of the vendor's security-patch window, whether or not anyone noticed. This scorecard tells you where your exposure actually is — across security, changeability, operational risk and key-person risk — so you know which gap is the expensive one before an auditor, an insurer or an outage finds it first.

This is a self-assessment based on what you tell us — not a security audit, not a code review, and not a substitute for the Environment Diagnostic or the Code & Modernization Roadmap.

How to Use

  1. For each of the 12 questions, click the option that best describes your situation.
  2. Your score updates as you answer — both an overall score and a breakdown across four axes: security, changeability, operational risk, key-person risk.
  3. Treat it as preliminary until all 12 are in, then it's final.

greenice.net | September 2026

19 years | 200+ projects | PHP, Laravel & Yii takeover experience

Answered
0 / 12
Overall Exposure
Select answers below
Security
Changeability
Operational Risk
Key-Person Risk
1
Support Status
Is the PHP version and the framework version you're running still receiving security patches from the vendor?
2
Dependency Updates
When did you last update third-party packages and dependencies?
3
Vulnerability Exposure
Has anyone checked whether a published CVE currently applies to your exact stack?
4
Test Coverage
If you changed one core piece of logic today, would anything tell you what broke?
5
Staging Environment
Do you have a staging or test environment that matches production closely enough to trust?
6
Change Lead Time
How long does a small, well-understood change usually take from “we need this” to live?
7
Deployment Process
How does a deploy happen today?
8
Monitoring
Would you know a critical feature broke before a customer told you?
9
Backup & Restore
Have you actually tested restoring from a backup — not just confirmed backups run?
10
Original Developer Access
If your original developer(s) or agency were unavailable, could someone else deploy a change today?
11
Documentation
Is there any written documentation of how the system is built and deployed, beyond what's in one person's head?
12
Source Code & Credentials Custody
Do you have full, verified custody of all source code, server credentials, and domain/DNS access — independent of any one vendor or person?

Your result

Complete all questions to see your result.

⚠️

This is worth a technical conversation, not just a scorecard

Based on what you told us, at least one gap here isn't something that waits for the next planning cycle.

Score Interpretation

0% – 20%
Low Exposure
Based on what you told us, the basics are in place across the areas we asked about. Worth revisiting annually, and whenever a support window closes.
21% – 60%
Moderate Exposure
Based on what you told us, real gaps exist in at least one axis that matters — often support status, deployment, or how much lives in one person's head. A focused review finds the expensive ones first.
61% – 100%
High Exposure
Based on what you told us, several of the areas we asked about show real gaps. The fastest path forward is the Environment Diagnostic: a free, two-day read of exactly what you're running on.

Free 30-Minute Technical Call

We'll walk through your specific gaps, based on what you told us above, and lay out what a free Environment Diagnostic or a fixed-scope Code & Modernization Roadmap would actually cover for you.

Get your estimate now

OR LEAVE YOUR EMAIL AND WE’LL CONTACT YOU WITHIN THE SAME BUSINESS DAY

We reply within one business day, with a person, not a sequence. No newsletter, no drip campaign.