Technical audit for your Cmsmart Ecommerce or WooCommerce store
A bounded, written review of how your store is built and where it is fragile, with a ranked fix list. We read first and change nothing.

In short
What does a technical audit of an ecommerce store cover?
A Cmsmart technical audit reviews how your Cmsmart Ecommerce or WooCommerce store is built: theme and plugin code, speed, security basics, checkout, integrations and print files. You receive a written report with evidence, severity and a ranked fix list. It starts with a free assessment, access is read-only, and fixing is quoted separately.
| Scope | One store: code, plugins, hosting set-up, checkout, integrations and, where it applies, the product designer and the print-file path |
|---|---|
| What you get | A written report with findings, evidence, severity, the limits of the review and a ranked list of fixes |
| Typical inputs | Read-only admin and hosting access or a staging copy, the plugin list and the questions the audit must answer |
| Deliverables | The audit report, a walkthrough with whoever will act on it, an optional fix scope and an optional retest |
| How pricing works | Free assessment to agree the question, then a quote for the audit. Fixes are quoted separately. |
How it works
How an audit runs
The problem
Which problems can an audit find before they cost orders?
- An update that broke checkout on phones only
- Slow product pages that nobody can trace to a single cause
- Outdated or abandoned plugins nobody has reviewed
- Designs or print files that fail on some orders and not others
- Custom code from a previous developer that nobody on your side has read
Fit
When is an audit the right first step?
| A good fit | Another route fits better |
|---|---|
| You must choose between keeping the store, repairing it, rebuilding a part or moving it, and you need facts first | You already know the fault and want it fixed: a fix service is the quicker route |
| You can give read-only access to the store, or to a staging copy | No access can be given, so the review would rest on interviews alone |
| You want a written report another developer can check | You want release checks every week: that is care or managed support, not a point-in-time review |
What we do
What does the audit look at?
| Part | Input | Deliverable |
|---|---|---|
| Code and plugins | Theme and child theme, custom plugins, the plugin list and its update state, signs of conflicts | Findings on what is outdated, abandoned or risky to change |
| Speed and hosting | Page weight, caching layers, the settings of the server that we can see, product and checkout pages | Where time is lost, ranked by effort to fix |
| Checkout and orders | Cart, checkout, payment hand-off and order emails on desktop and phone; test orders on staging | Fragile steps with notes to reproduce them |
| Security basics | Users and roles, update state, login protection, exposed files, whether backups exist | Gaps in common hardening. A deeper review is the security audit service. |
| Integrations | How ERP, CRM, shipping and supplier connections move data and how they fail | Silent-failure points and who owns each field |
| Designer and print files | Product Designer settings, print areas, bleed and the file the order receives, on sample orders | Whether a customer's design becomes the file your printer needs |
The Cmsmart angle
What is reviewed against the Cmsmart plugin, and what is not
Where your store runs Cmsmart Product Designer for WooCommerce, its settings and print-file output are reviewed against what the plugin documents. Other plugins and custom code are reviewed as installed.
Core Read against the plugin's documented behaviour
- Print-Ready Files. The order screen shows whether each print file is Ready, Rendering, Failed or Not rendered, with a Regenerate button. The audit reads that trail on sample orders.
- Online Designer. Print areas, bleed, safe zone and templates are set per product. The audit checks that the settings match what your printer needs.
- Pricing Options. Option sets and price rules per product or category. The audit checks them for gaps and for rules that fight each other.
Custom Built as custom development
- Fixes that the report recommends, quoted as their own milestone
- Repairs to code written by another supplier
- Changes to integrations with your other systems
Scope
Included, not included, and extra
Clear lines before you start. The final scope is written into your proposal.
Included
- A written mission, scope and list of exclusions
- Read-only review of code, plugins, settings and the checkout journey
- Findings with the evidence and the reasoning behind each severity
- A statement of what the review could not see
- A ranked fix list with options: fix in place, rebuild a part, or accept the risk
- A walkthrough of the findings for the team that will make changes
Not included
- Fixing what is found. Fixes are quoted separately.
- A penetration test, or a certificate against any standard
- An SEO or content audit
- Licences, hosting and third-party fees (plugins, fonts, images, services, provider accounts)
- Anything that is not written in the approved scope
Extra, quoted separately
- Fixes, as their own milestone
- A narrower retest after you have fixed the findings you chose
- Care or maintenance after the audit
What we need from you
- Read-only admin access, or a staging copy
- The plugin list, and who wrote any custom code
- The symptoms or questions that started this
- A named person who decides what to do with the findings
- A staging copy of your store, or approval to create one
- Someone on your side who can make decisions when a question comes up
Process
How the work runs
Each phase is a milestone, approved and invoiced one at a time. The timeline is set in the assessment because it depends on your store, your products and your systems.
- Free assessment. We read your brief, your store and your constraints, and tell you whether the service fits and what it would involve.
- Written scope and quote. Included, not included, extra and what we need from you, set out before any work starts.
- Build on a staging copy, in milestones you approve one at a time in your dashboard.
- Acceptance with your own products, files and orders, including the awkward ones.
- Handover with a run book, then support through tickets in your dashboard.
This service in three phases
What happens, and what you receive
| Phase | What happens | What you receive |
|---|---|---|
| 1. Scope | We agree the one question the audit must answer and what is out of scope, and set up read-only access. | A written mission and its exclusions |
| 2. Review | We read the code and settings, run tests on a staging copy where a test would change data, and log anything found outside the mission. | Working notes on request |
| 3. Report | We take the people who will make the changes through each finding. | The report: evidence, severity, limits, ranked fixes and decision options |
Free assessment
Start with a free assessment
Describe your store and what you need. We reply with whether the service fits, what it would involve and a quote, with no obligation.
FAQ
Frequently asked questions
Do you fix what the audit finds?
Only if you ask for it after reading the report. Repairs are scoped and quoted as a separate milestone, and nothing stops you handing them to your own developers or to a different supplier.
Is the audit a security certification?
No. It is an engineering review. A clean result means the checks we ran found nothing, within the access given, on the date of the review. A certificate against a named standard needs an accredited assessor.
Will the audit change my live store?
No. Access is read-only by default. Tests that place orders or write data run on a staging copy.
What if the report says the store should be replaced?
Then the report gives the reasons and lays out the choices. One of them may be a move, which our migration and rescue services cover.
Can you audit a store another agency built?
Yes. The report states who built what in its method, and where independence matters you can see it.
Do you audit stores that do not use Cmsmart products?
Yes, any WooCommerce store. Cmsmart plugins are reviewed against their documented behaviour and all other plugins as installed.
Related services
Next steps and neighbouring services
Learn more
Related tutorials from the community
- GuideHow to market your E-commerce store on Instagram?According to statistics, there are about more than 1 billion Instagram active users each month, and about 50% of them following at...
- GuideEcommerce Mobile App Development - The Latest Guide 2023Whether you're an entrepreneur launching a new eCommerce venture or a seasoned business owner looking to enhance your digital stra...
- Guide6 Rules for a Better eCommerce User Experience
Who you work with
The team behind Cmsmart and its published work
- 2012Netbase since 2012Cmsmart Ecommerce is a Netbase JSC company
- 6,300+client projectssince 2012
- 80+countriesclients worldwide
- 17,133proposals writtenin our project system, live count
Client projects and countries: Netbase portfolio library and WorkSuite project records, as of Sep 2026. Proposals: records in our Cloodo WorkSuite project system, all-time, refreshed every 6 hours.

Talk to an ecommerce expert
Huy Nguyen (David)
Founder & CEO, Cmsmart · Netbase JSC
Every request is read by the team before you get a written scope and estimate.
Published Cmsmart projects

Online Store & Presence · classymag.plE-commerce Transformation for Magazine-Style Photobook OrderingDelivered, live store
Online Store & PresenceE-commerce Enhancement for Efficient Custom Product OrderingDelivered (store no longer online)
Online Store & PresenceInnovative Business Solutions for Enhanced Online Presence and EfficiencyDelivered (store no longer online)
Project records from our portfolio. They show the wider work of the team, not this exact service.
Top
