Skip to content

Cookies on Loupe

Essential cookies keep Loupe working and are always on. With your agreement, Loupe also loads analytics to count visits and see which pages and tools are used. There is no advertising tracking. You can change your choice at any time from cookie settings. Read the cookie policy

Loupe home

Code quality and security debt in software

Software that works today but is hard to change, poorly tested, built on unsupported components or open to attack. The cost of putting it right falls on the buyer.
Category
Online and platforms
Applies to
SaaS, App, Marketplace
Severity
Price it in
Last updated
Author
Loupe editorial
Reviewer
Not yet reviewed

Why it matters

In a software business the code is the product and the main asset. Buyers tend to judge it by what they can see, such as a working product, growing revenue and low churn. The cost of owning it depends on what they cannot see: how easily it can be changed, how well it is tested, how current its components are and how exposed it is to attack.

Technical debt behaves like a liability that never appears in the accounts. Shortcuts taken to ship features, frameworks that no longer receive updates and code only the founder understands all become spending after you buy. The first year's plans can turn into a rebuild while growth stalls. Security debt can be worse, because its bill may arrive as a breach: lost customer data, possible duties to notify regulators and customers, and the cancellations that follow.

The profit in the listing may also be flattered. A founder who writes the code without a market salary, or who has put off upgrades and security work, is running the business below its true cost. A realistic view of earnings includes a market cost for engineering plus the catch-up work the product needs. SDE shows what the business earns for an owner who does that work. If you plan to hire someone instead, adjusted EBITDA is the better guide, and the Loupe valuation tool calculates it by subtracting a market salary for the owner's role from SDE.

For anything beyond a small app, an independent code and security review before you commit is usually worth its cost. Use what it finds in the price and in the warranties you ask for.

Churn

Churn is the rate at which a business loses customers or recurring revenue over a period. Customer churn and revenue churn can tell very different stories.

Seller's discretionary earnings (SDE)

Seller's discretionary earnings is the yearly financial benefit a business gives one full-time working owner, before financing costs, non-cash charges and one-off spending.

Adjusted EBITDA

Adjusted EBITDA is EBITDA after normalising adjustments, showing what a business would earn with a paid manager in the owner's seat. Larger small-business deals are usually priced on it.

How to spot it

  • One founder or one contractor wrote most of the code, and nobody else has deployed it.
  • The product runs on language versions, frameworks or libraries that no longer receive security updates.
  • There are few automated tests, and releases are made by hand.
  • Some parts of the system are avoided, or new features have slowed while bug reports rise.
  • Passwords and keys are stored in the code repository, or live customer data is used for testing.
  • There is no recent penetration test, or findings from the last one remain open.
  • Incident logs or support tickets show repeated outages or data problems.
  • Hosting costs rise faster than customer numbers.

Questions to ask the seller

  • Who wrote the code, who can deploy it today, and who else has access to the repositories and live systems?
  • Which languages, frameworks and major components are used, and when were they last upgraded?
  • How much of the code has automated tests, and how are releases made and reversed?
  • Have you had any security incidents, breaches or suspicious access? How were they handled, and who was told?
  • When was the last penetration test or security review, and what remains unresolved?
  • What would you fix or rebuild first if you were staying?
  • Which open source licences apply to the components the product uses?

Documents to request

  • Read-only access to the code repositories, including commit history
  • An architecture overview and a list of third-party services and hosting providers
  • A scan of third-party components showing versions, known vulnerabilities and licences
  • Penetration test and security review reports, with evidence of fixes
  • Incident logs and uptime records for the last 24 months
  • Hosting and infrastructure invoices for the last 12 months
  • Agreements assigning code ownership from every developer and contractor
  • Backup and disaster recovery procedures, with the date they were last tested

Want this checked properly on a real listing?

A dossier checks the listing's figures, registrations and risks, with a source and confidence for every finding. Open a listing in the feed and request a dossier from its page.

  • Intellectual property held by the owner or freelancers

    The brand, code, content or designs a business depends on may legally belong to the owner or to whoever created them. Check ownership and get written assignments in place before completion.

    Severity: fixableLegal and compliance
  • Domains or accounts held in personal names

    The domain, social profiles, app store, advertising or payment accounts belong to the owner or a freelancer rather than the business. They may not pass to you unless the deal says so.

    Severity: fixableOnline and platforms
  • Deferred maintenance or capital spend

    An owner who stops repairing and replacing equipment before a sale makes profit look higher and leaves you with the catch-up bill.

    Severity: price it inFinancials
  • Undocumented processes

    When the way a business runs lives in one or two people's heads, the handover gets harder and early mistakes get more likely. It is usually fixable if you find it before you sign.

    Severity: fixableOperations and people
  • Customer data collected without valid consent

    An email list or customer database is only worth what you can lawfully use after the sale. If consent was never valid, part of the list, and the revenue it drives, may have to go.

    Severity: price it inLegal and compliance
  • Key staff not tied in

    If the people who hold the business together have no written terms, no notice periods and no reason to stay, a sale is the moment they are most likely to leave. Find out who matters and what keeps them.

    Severity: fixableOperations and people
  • Buying an online business: SaaS, ecommerce and content compared

    SaaS, ecommerce and content businesses are sold on the same marketplaces, but they earn money differently, fail differently and are valued differently. This guide compares the metrics, risks and diligence for each.

    9 minutes to read
  • Due diligence: what to check and in what order

    A sequence for due diligence that tests what could end the deal first, while it is still cheap to find out, and leaves the detailed and expensive work until the deal looks sound.

    10 minutes to read
  • The first 100 days after you buy

    How to use the first 100 days after completion: keep customers, staff and cash steady, learn the business before you change it, and start fixing the risks you found in diligence.

    8 minutes to read
  • Online business diligence for SaaS, ecommerce and content

    The checks that matter most when a business lives online: live account access, traffic, platforms, ownership of digital assets, code and the revenue behind the dashboards.

    About 120 minutes
  • Handover and the first 30 days

    What to settle before completion and what to do in the first month after you buy, so customers, staff and suppliers stay with the business while you learn how it runs.

    About 30 minutes
  • Key person risk

    Key person risk is the risk that a business loses value if one individual leaves or stops performing. In small businesses that person is often the owner.

  • Capital expenditure

    Capital expenditure is spending on assets that last more than a year, such as equipment, vehicles and premises. It uses cash but reaches the profit and loss account only gradually, through depreciation.

  • Adjusted EBITDA

    Adjusted EBITDA is EBITDA after normalising adjustments, showing what a business would earn with a paid manager in the owner's seat. Larger small-business deals are usually priced on it.

  • Warranties and indemnities

    Warranties are the seller's statements of fact about a business in the purchase agreement; indemnities are promises to reimburse specific losses. Together they decide who bears risks that diligence could not rule out.

  • See a low, likely and high value from the figures you have, and whether the asking price holds up.

Live listings where this applies

No live listings match these topics right now. Browse the feed to see everything that is for sale.