Someone else wrote it, it runs your business, and nobody wants to touch it

We take over PHP, Laravel and Yii systems built by other teams — including the ones whose original developers are long gone — and modernize them in place, without stopping operations.

If any of this is where you're stuck

  • The system runs the business. Someone else built it, it still works, and every proposal to change it dies on the same sentence: “we can't touch it.”
  • The people who wrote it are gone. No documentation, no tests, no staging that matches production — and the deployment procedure lives in one person's head.
  • A change that should take two days takes three weeks, because nobody can predict what else it breaks.
  • Your host, your payment processor or your security audit says the PHP version is out of support — and upgrading means touching code nobody understands.
  • The previous agency stopped answering. You have the server login and you're not sure you have all the source code.
  • You want to add AI — semantic search, an assistant over your own data, document processing — and your team's honest answer is that the system can't host it as it is.
  • Due diligence, an acquisition or an enterprise security questionnaire is coming, and the codebase is the part you're not looking forward to explaining.
  • You've been quoted a rewrite from scratch: a large number, 12–18 months, and no answer on what happens to the business meanwhile.

Modernization, in four parts

Takeover and stabilization

We read the system you already have — code, database, infrastructure, deployment — and take responsibility for it. First we make it safe to change: a reproducible environment, honest version control, a deployment you can roll back, monitoring that catches breakage before your customers do, and tests around the riskiest parts. Business logic stays untouched here. That's the point: you get the ability to change things before you change them.

Upgrades that don't stop the business

PHP version, framework version, dependencies, server stack — done incrementally, behind feature flags, with a rollback path at every step. Where the jump is too large to make directly (Yii 1.1, PHP 5.x, a framework someone forked in 2013), we bridge it: old and new run side by side while functionality moves across, module by module, on your schedule.

Refactoring, integration and the strangler approach

Instead of a rewrite, we put an API layer around what already works and replace the system from the outside in — the highest-pain module first, the rest when it earns its turn. Custom code that a maintained library now covers gets deleted; systems that never talked to each other get an integration layer; data migrates on your timeline. If a full rebuild really is the right answer, we'll say so — and say why, before you've spent anything.

Making it AI-ready

Most modernization projects skip this, which is why so many AI pilots die at the demo stage. AI needs what legacy systems lack: clean data boundaries, an API that isn't the UI, permissions the model can respect, structured logs, and a way to catch a bad answer before a customer sees it. We build that layer as part of the modernization, then ship the feature on top — semantic search, an assistant that answers from your data, document and PDF extraction, classification and routing.

Need AI in a system that's already in good shape? That's AI Integration → · Healthcare system under HIPAA? Healthcare Software → · Two systems that won't exchange data at all? Healthcare Interoperability →

A deadline that's already here

Most PHP systems running in production today are already out of support

Not “will be.” Are. These are the vendors' own published dates — the ones your security auditor, your underwriter and your enterprise customer's questionnaire will use:

What you're probably runningStatus as of today
PHP 8.1 and anything olderEnd of life. No security patches at all.
PHP 8.2Security fixes only — stop 31 December 2026.
Yii 1.1End of life 31 December 2026. No security fixes after that date.
Yii 2.0, below 2.0.50End of life 23 November 2026.
Yii 2.0, 2.0.50 and aboveSecurity fixes end 23 November 2026; final EOL November 2027.
Laravel 11 and olderOut of support. Laravel 10 had no security fixes since February 2025.
Laravel 12Bug fixes ended August 2026; security fixes end February 2027.

This isn't only about old systems. A Laravel 10 app built three years ago is already unsupported. Age isn't the measure — the vendor's support window is.

What “out of support” actually costs you, in the order it usually shows up:

  • A vulnerability is published for your framework version and there's no patch. Your options are a hand-written fix or an emergency upgrade — the most expensive way to do the work you were avoiding.
  • Your hosting provider drops the PHP version and gives you a migration window measured in weeks.
  • A processor, an insurer or an enterprise buyer asks for your supported-versions status in writing, and the honest answer stalls a deal.
  • Every month you wait, the gap widens by a month — and the upgrade gets that much more expensive.

What we do about it: an incremental, reversible upgrade path — no one-step migration of a live system, no quarter-long feature freeze. The first deliverable is a written path: which versions, in which order, what breaks at each step, and what it takes. You sequence it with real numbers instead of a vendor's urgency.

Our biggest disagreement with the industry

The rewrite is usually the wrong answer, and it's the one you'll be sold most often

A full rewrite is the easiest thing for an agency to quote and the hardest thing for you to survive. Twelve to eighteen months on an old system nobody is improving, while the new one relearns a decade of requirements — most undocumented, half of them rediscovered in production.

Sometimes a rewrite is right: the platform underneath is genuinely dead, the domain model was wrong from the start, or the code is small enough that rebuilding beats understanding. We'll tell you when that's your case. It usually isn't.

  • Stabilize first, change second. You cannot safely modernize a system you can't deploy predictably.
  • Modernize in place, module by module. New code goes behind a clean interface; old code keeps running until its replacement is proven.
  • Every step is shippable and reversible. No branch that lives for six months. No date on which everything switches over at once.
  • The business keeps running. No feature freeze, no “we'll get back to your roadmap after the migration.”

We've been doing this since 2007 — mostly on other people's code

19Years in business
200+Projects delivered
70Clients worldwide
45People on staff
  • Yii since 2010 — 60+ applications. Laravel, Yii, Zend, and a fair amount of code that predates all three.
  • Most of our long-running work started as somebody else's codebase, and often with a vendor who was no longer around.
  • Long relationships are the proof that matters here. Systems we took over years ago are still in production and still being developed.

Arcbazar — the world's largest crowdsourced architecture marketplace, 12,000+ registered users

The method on this page, on a live business, in two stages. We took it over in 2015: a mix of Yii 1.1 and an in-house framework, tangled enough that nobody could predict what a change would break.

Stage one — make it coherent: we removed the custom framework and unified everything onto one codebase, changing no business logic. Stage two — move it forward: new modules on Yii 2.0, the rest migrated module by module while the marketplace kept trading. No switchover date, no feature freeze.

Alongside that: application, database and storage split across AWS, search replaced with Elasticsearch, and years of continued development. Between 2015 and 2020 competitions roughly doubled and the average award rose from $760 to $1,015.

AI on top of existing systems — shipped, not slideware: a virtual assistant running on our own site, an ML-based award-suggestion mechanism inside Arcbazar trained on 1,500+ completed competitions, an AI advisor that answers from complex PDF tables, and a brand-strategy content portal where the model works with the client's own strategy as context.

Clutch 4.9 · 100% Job Success on Upwork · Top Rated

The contracting entity is Estonian; the engineering team is in Poland and Ukraine. We work under your NDA and MSA, inside your infrastructure if you prefer, and we answer subcontractor, data-residency and IP questions in writing. All source code and all IP are yours, from the first commit.

Three ways to find out what you're dealing with

Pick the one you're comfortable with.

You give us nothing

Legacy Risk self-check

12 questions about your system: versions, tests, deployment, environments, documentation, and what happens if your one key person leaves. It scores your exposure across four axes — security, changeability, operational risk, key-person risk — and gives you a scorecard you can forward to whoever signs off the budget.

No code, no access, no call. The result is on screen; email only if you want the PDF.

Run the Legacy Risk self-check

Free, and we do it ourselves

Environment Diagnostic

Two working days of server access, and we tell you what's running and what's unsupported.

What you get — a one-page status sheet:

  • OS, and whether it still gets security updates
  • Web server, PHP version, config, extensions
  • Database, framework, dependency versions
  • TLS status and published vulnerabilities
  • Backups, deployment, version control, staging
  • The three things we'd deal with first

Not a code review — that's the paid step below.

Request the diagnostic

From $1,500, credited toward the project

Code & Modernization Roadmap

The paid step — the one that answers what you're really asking: what would it take, and is it worth it?

We read the code, not just the environment: dependency risk, dead code, complexity hotspots, test coverage. Then the roadmap — the upgrade path, an honest modernize-vs-rebuild call, and a prioritized first 90 days with effort ranges.

Fixed scope, fixed timeline. The document is yours, and credited if you go ahead with us.

Book a 30-minute scoping call

How the diagnostic access works

  • A mutual NDA first. We sign yours; if you don't have one, we send ours and you're free to change it.
  • One named engineer. You'll know who, by name, before anything starts.
  • A dedicated account you create — an SSH user without sudo, or a limited hosting-panel account. Not your credentials, not root, not the production admin.
  • Two working days, then you close it. We ask you to disable the account the day we deliver, and confirm in writing when we're done.
  • We change nothing. We read configuration, versions and logs — nothing installed, deployed, restarted or modified.
  • We don't need your database contents or any customer data. Version and schema structure, not rows.
  • We'll send the exact list of checks before we start, if your security policy needs it in writing.
  • The report is yours either way. No obligation, no sales call attached — and written so another vendor could act on it.

Can't grant access — policy, or it isn't your call? That's normal. Start with the self-check and a call, and we'll work with what you can tell us.

Request a free Environment Diagnostic

How engagements are shaped

  • Environment Diagnostic

    A free, two-working-day read of what your system actually runs on — OS, web server, PHP and framework versions, database, TLS, backups, deployment process — done by us, on a dedicated account you create and close.

  • Code & Modernization Roadmap

    A fixed-scope, fixed-timeline read of the code itself: dependency risk, dead code, complexity hotspots, test coverage, an honest modernize-vs-rebuild recommendation, and a prioritized first 90 days with effort ranges.

  • Stabilization Sprint

    Reproducible environments, version control that reflects reality, a deployment you can roll back, monitoring, and tests around the highest-risk paths — so the system stops being frightening to change.

  • Upgrade Programme

    PHP, framework and dependency upgrades, done incrementally behind feature flags with a rollback path at every step, on the sequence agreed in the roadmap.

  • Modernization & Integration

    Strangler-pattern module replacement with an API layer around what already works, integrations between systems that never talked to each other, and data migration on your timeline.

  • AI-Readiness & AI Features

    The access, permission and logging layer a legacy system needs before it can host AI safely, then the feature itself — semantic search, an assistant over your own data, document extraction.

  • Ongoing Ownership

    We keep the system we modernized, on a retainer, with a named team — for as long as it keeps running the business.

Steps 3 and up are quoted after the roadmap: a PHP system isn't a number of hours until someone has read it, and a real number beats a range you can't plan against. Everything is fixed-scope with a fixed timeline.

The stack, and why it still matters

PHP
Since 2007, 200+ projects.
Laravel
Custom builds, migrations to Laravel from other frameworks and from none at all, version upgrades, and long-term support of systems other teams built.
Yii
Since 2010, 60+ applications; Yii 1.1 and Yii 2.0, including the systems that mix both.
Also in the codebases we've inherited
Zend, CodeIgniter, Symfony components, and plenty of in-house frameworks written before any of these were the obvious choice. That's not a problem — it's the normal starting condition.
Around it
MySQL, PostgreSQL, MongoDB, Redis · Elasticsearch, Sphinx, Solr · Nginx, Apache · AWS, Google Cloud · Docker · Git, CI/CD · React and Vue on the front end.

The language people wrote obituaries for in 2015 now runs a large share of the web, on a runtime several times faster, with a mature type system and two first-class frameworks. Your problem is almost never that the system is written in PHP. It's that it's written in a version nobody supports any more, by people you can no longer ask.

Why hire us for this specifically

  • We take over other people's code. It's not the exception in our portfolio — it's most of it.
  • 19 years, 200+ projects, 45 in-house engineers. Not a marketplace of contractors assembled per project.
  • Fixed scope and fixed timeline on the roadmap and on first engagements.
  • We say no to rewrites we don't believe in, including ones we'd be paid more for.
  • The roadmap is yours. Written to be usable by another vendor — a document you can only use with us isn't a diagnosis, it's a sales tool.
  • We stay. The systems we took over years ago are still in production, still ours to develop.

Three ways to start, in order of commitment

Nothing required

Legacy Risk self-check

12 questions, a scorecard you can forward, no call attached.

Run the self-check

Two working days

Environment Diagnostic

One named engineer, an account you create and close, a one-page status sheet to keep.

Request the diagnostic

When you're ready

30-minute technical call

Bring one system, one blocker, or one quote you want a second opinion on.

Book a call

Not sure which one fits? Let's talk.

OR LEAVE YOUR EMAIL AND WE’LL CONTACT YOU WITHIN THE SAME BUSINESS DAY

We reply within one business day, with a person, not a sequence. No newsletter, no drip campaign.