Third-party code audit
Every external script, font, pixel, and embed on the site gets listed — with what it does and who receives the data. Then we remove what isn't earning its place and self-host what is.
Most sites carry a stack of third-party scripts nobody chose deliberately — each one slowing the page down and sending your visitors' data somewhere you can't see. We move your site to a clean, hardened setup and keep every link and ranking you already have.
The list below is the baseline. Anything beyond it is scoped and quoted after the review, never added silently.
Every external script, font, pixel, and embed on the site gets listed — with what it does and who receives the data. Then we remove what isn't earning its place and self-host what is.
HTTPS enforced everywhere, modern TLS configuration, and the security headers most sites are missing — content policy, frame protection, referrer policy, MIME-type protection.
Every existing address is mapped to its new home with a permanent redirect. Links people have bookmarked keep working, and search engines carry your ranking across instead of starting over.
Removing tracking scripts is usually the single largest speed improvement available to an existing site. Compression, image optimisation, and caching finish the job.
What your site actually collects, where it goes, and whether your privacy policy still describes reality. Most consent banners exist because of scripts nobody needed.
What we found, what we changed, what we deliberately left alone, and what we recommend next. Plain language, kept for your records.
You can check the left column on your own site right now: open it in a browser, press F12, and look at the Network tab. Every domain other than your own is a third party receiving something.
This site is the reference build
Open your browser's Network tab on any page here. Every request goes to this domain — no analytics, no CDN, no external fonts. That's the standard we migrate clients to, and you can verify it yourself in about ten seconds. The reasoning is written up in our privacy tutorials.
A migration goes wrong when links break and rankings vanish. That is entirely preventable, and preventing it is most of the work.
We examine what your site loads, what it collects, and how it is served. Free, and yours to keep either way.
A written scope: what gets removed, what gets replaced, and a complete map of old address to new address.
The new site is built and tested away from the public one. Nothing visitors see changes yet.
We cut over with redirects live from the first second, and the old version kept intact so it can be restored.
Redirects, forms, headers, and indexing all verified after the switch — then you get the written report.
It depends almost entirely on what the site is built on and how many pages need mapping. A small static site is a modest job; a large site on an unfamiliar platform is a larger one.
The review is free and comes before any quote, so the number you get is based on what is actually there rather than a guess. See what drives website cost.
Most migrations run 1–3 weeks, and the visitor-facing switch itself is a single planned changeover rather than a period of downtime.
The review comes first and is quick. Building and testing the replacement is the part that takes the time — deliberately, because that is where broken migrations are prevented.
Because we publish the security work rather than just claiming it. There are 141 free tutorials on this site covering the same ground we apply to client work.
You can read exactly how we think about this before you spend anything — start with web security.
Not if the migration is done properly. Rankings are lost when old addresses start returning errors instead of pointing at their replacements. We map every existing URL to its new location with a permanent redirect before the switch, and verify them afterwards.
You lose third-party surveillance, not measurement. Server-side statistics and privacy-respecting analytics can tell you what pages are read and where visitors arrive from without profiling anyone. We'll walk through the options with you.
It removes a large part of what usually creates the obligation — most consent banners exist because of advertising and analytics scripts. But compliance depends on everything your organisation does with personal data, not only your website, so we don't claim to certify it. We tell you exactly what the site collects; a lawyer signs off compliance.
No. The replacement is built and tested separately, and the switch is a single planned changeover. The previous version is kept intact so it can be restored if anything unexpected appears.
Often, yes — a lot can be improved without a rebuild. The review tells us whether hardening what you have is the better answer, or whether replacing it costs less than maintaining it. We'll say which, plainly.
Related, but the order matters: a compromised site needs containing and cleaning before anything is migrated. Start with our page on what to do when a website is hacked, then this becomes the step that stops it recurring.
Send us your address and we'll tell you what your site currently loads, what it sends where, and what we'd change. You keep the findings whether or not you hire us.
Free review • No obligation • Findings are yours to keep