Taking over an existing codebase commonly starts around 20 to 60 hours for a small, accessible system and 60 to 200 hours for a larger or poorly documented application. At Vertinus's $49.99 hourly rate, those assessment ranges are roughly $1,000 to $3,000 and $3,000 to $10,000.

That first cost is not the price to finish every feature. It is the work needed to establish access, build and deploy the software safely, understand the architecture and data, identify urgent risks, and produce a responsible stabilization or completion estimate.

Planning range: allow 20-60 hours for a small system with good access and documentation; 60-200 hours for a larger, unfamiliar, or risky application; and a separately approved stabilization phase after the findings. Missing source, unavailable credentials, compromised infrastructure, regulated data, and failed production systems can require specialist work beyond these ranges.

Why a takeover has an entry cost

The original developer accumulated knowledge while building the system. A replacement must reconstruct the parts that were never documented: why a rule exists, which service owns a field, how deployment works, which task runs overnight, what customers depend on, and where failures are hidden.

The replacement also assumes operational risk. A small change can affect billing, data, access, or customer service when tests and environments are weak.

Typical takeover cost ranges

Small, accessible system: 20-60 hours

Approximately $1,000 to $3,000 at $49.99 per hour.

This range can fit one small web application with a current repository, straightforward cloud environment, usable credentials, modest database, known dependencies, and no active security incident.

The outcome should be a reproducible local or test build, access inventory, architecture summary, basic risk findings, and an estimate for the highest-priority next work.

Established application: 60-200 hours

Approximately $3,000 to $10,000 at $49.99 per hour.

This range may apply to several services, significant data, integrations, background processing, complex permissions, mobile clients, limited tests, partial documentation, or multiple environments.

The assessment may require representative scenario testing, dependency analysis, database review, deployment rehearsal, backup restoration, monitoring evaluation, and security-focused work.

Distressed or high-risk system: 200 hours and above

Starting around $10,000 at $49.99 per hour.

Missing source, corrupted data, unsupported technology, unknown production changes, compromised accounts, severe downtime, financial errors, regulated information, or many undocumented integrations can turn takeover into a recovery program.

Specialized security, cloud, database, legal, compliance, or incident-response providers may charge different rates and should be budgeted separately.

What the initial assessment should include

Access and ownership inventory

Record the source repository, cloud, domain, DNS, database, storage, identity, messaging, payment, analytics, monitoring, app-store, and vendor accounts. Identify legal owner, administrator, billing contact, recovery method, and missing access.

Reproducible build and deployment

Confirm that the source can be installed, built, tested, and deployed into an isolated environment. Document versions, commands, dependencies, configuration, secrets, migrations, and release steps.

Architecture and dependency map

Identify applications, services, databases, queues, scheduled tasks, file storage, third-party APIs, data flows, and operational owners. Highlight unsupported or unmaintained dependencies.

Data and migration review

Understand schemas, volume, sensitive data, backup status, recovery evidence, retention, and integrity controls. Reconcile important business totals or record counts where appropriate.

Security and access review

Review authentication, authorization, administrator access, secrets, public exposure, logging, dependency risk, backups, and obvious dangerous defaults at a depth appropriate to the scope.

Critical scenario baseline

Run representative workflows that the business cannot afford to lose. Record current success, known defects, data effects, and evidence. These scenarios become the regression baseline for takeover changes.

Findings and next-phase estimate

The client should receive prioritized findings, immediate safeguards, stabilize-repair-replace options, assumptions, and estimated hours for the next bounded phase.

What increases the takeover cost

  • No current source repository.
  • The deployed version differs from the repository.
  • Missing infrastructure or deployment configuration.
  • Production accounts remain under a former provider.
  • No tested backup or usable data export.
  • Unsupported languages, frameworks, operating systems, or databases.
  • Many third-party integrations with weak documentation.
  • Complex financial, inventory, scheduling, or permission rules.
  • Mobile apps and signing or store access.
  • Security incident or suspected unauthorized access.
  • Regulated, confidential, or contractually restricted data.
  • No one at the business can explain critical workflows.

What reduces the takeover cost

  • Current source and issue history.
  • Client-controlled production accounts.
  • Documented local setup and automated deployment.
  • Representative automated and manual tests.
  • Architecture, data, integration, and operating documentation.
  • Tested backups and a recent data export.
  • A named business owner who can answer workflow questions.
  • A prioritized first objective rather than a broad wish list.
  • Availability of the previous developer for a structured handoff.

Example: small internal job tracker

A company has a custom job tracker used by 18 employees. The repository is available, the application runs on one managed platform, and the database backup exists. Deployment is manual and there are no tests.

A takeover might allocate:

  • Access, repository, and service inventory: 4-8 hours.
  • Local setup and dependency repair: 6-14 hours.
  • Architecture, data, and security review: 8-18 hours.
  • Deployment and backup verification: 6-12 hours.
  • Critical scenario baseline and findings: 8-16 hours.

Total planning range: 32-68 hours, or about $1,600 to $3,400 at $49.99 per hour. Actual hours depend on the evidence discovered.

Example: customer platform with several integrations

A customer-facing system has employee administration, customer accounts, payments, document storage, email, an accounting connection, background jobs, and several years of data. The former agency controlled the cloud account and documentation is incomplete.

Access recovery, environment reconstruction, security review, data reconciliation, critical workflow testing, and a safe deployment rehearsal may require 100-240 hours before substantial new features. That is roughly $5,000 to $12,000 at $49.99 per hour, excluding outside specialist or vendor charges.

Stabilization is a separate phase

After assessment, the system may need:

  • Credential and account restructuring.
  • Dependency and runtime updates.
  • Build and deployment automation.
  • Backup and recovery improvements.
  • Monitoring, logs, and alerts.
  • Security and permission corrections.
  • Data repair or reconciliation.
  • Tests for critical workflows.
  • Documentation and support procedures.

A focused stabilization phase may require 40-160 hours for a small or moderate system, approximately $2,000 to $8,000 at $49.99 per hour. Larger systems can require substantially more.

Finishing features comes after control

Do not combine every unfinished request into the takeover estimate. First restore the ability to build, deploy, recover, and observe the system. Then re-scope incomplete features against current business priorities.

Some promised behavior may no longer be valuable. Some may depend on assumptions the original project never resolved.

Repair versus rewrite

A rewrite adds requirements discovery, new architecture, implementation, data migration, integration replacement, testing, user transition, parallel operation, and decommissioning. It is not automatically cheaper than understanding the existing code.

Replacement becomes credible when the current software cannot be legally or technically transferred, cannot be built, relies on unsupported foundations, is structurally unsafe, or costs more to change than a staged successor.

Compare a stabilization path with a replacement path using the same required outcomes, migration, risk, and transition period. The legacy software modernization cost guide covers those options in more detail.

How to control the takeover budget

  1. Authorize a small access and feasibility checkpoint.
  2. Require a written inventory and missing-access list.
  3. Set an assessment cap and decision point.
  4. Review findings before approving stabilization.
  5. Separate critical risks from desirable cleanup.
  6. Approve feature work only after a reliable baseline exists.

The recovery guide, what to do when a software developer disappears, lists the client-side preservation work that can reduce assessment time.

What Vertinus needs to estimate a takeover

Send the system purpose, user count, live status, repository access status, known stack, hosting and database providers, integrations, backup status, active incident, critical deadline, and the first outcome you need.

Vertinus charges $49.99 per hour for time actually worked up to the approved estimate. A takeover begins with a written, bounded assessment scope rather than an open-ended promise to fix everything.

Request an existing-codebase assessment. We will identify the access needed, define the first inspection boundary, estimate the hours, and return prioritized options for stabilization, completion, modernization, or replacement.