✳ Nairobi, Kenya
- WhatsApp+254 799 756 331
- Emailhello@muvevi.com
- LinkedInlinkedin.com/in/muvevi
- GitHubgithub.com/mutua-muvevi
- Twitter / X@muvevi
Available for freelance & full-time roles.
Let's build something great.
Code Audit & Review
A focused review of your existing codebase — security vulnerabilities, performance bottlenecks, structural debt, and a prioritised remediation roadmap. Written report, debrief call, actionable output.
Most codebases accumulate debt silently. A feature ships, a shortcut is taken, a dependency goes stale — and six months later you're debugging a production incident at 2am tracing it back to a decision made under pressure in a sprint.
A code audit interrupts that cycle. I go through your codebase with the OWASP Top 10 as a baseline, then look deeper at architecture, data access patterns, dependency health, and performance. The output is a written report with everything ranked by severity and a remediation path for each item.
The audit is fixed-scope, time-boxed, and delivered with a 30-minute debrief call where I walk you through the findings and answer questions.
- OWASP Top 10 security assessment
- SQL injection, XSS, CSRF, and auth vulnerability scan
- Dependency audit (outdated, deprecated, known CVEs)
- Database query performance analysis (N+1, missing indexes)
- Code structure and maintainability assessment
- API contract review (error surfaces, versioning, rate limiting)
- Environment and secrets management review
- Written report with severity rankings (Critical / High / Medium / Low)
- Remediation roadmap with time estimates
- 30-minute debrief call + async Q&A for 7 days
Read-only repo access and a 30-min call to understand the stack, team size, and what concerns you most.
Dependency audit, known CVE checks, static analysis, and Lighthouse/performance baseline run first.
Auth flows, data access patterns, API error surfaces, secrets handling, and structural review — done by hand.
Delivered within 5 business days. Every finding has a severity, an explanation, and a remediation path.
30-minute walkthrough of findings. 7 days of async Q&A after the call.
Find what's broken before your users do.
Questions before committing? Let's talk.