TL;DR
When acquiring a codebase, rotate all credentials immediately, scan for hardcoded secrets in git history, audit dependencies for vulnerabilities, revoke access for previous developers, and review authentication patterns. Of the 20 items below, 6 are critical and need doing today. Nine more are important enough to finish this week. The last 5 round out a thorough audit. Trust nothing until verified.
Taking over someone else's codebase is a bit like moving into a house where you don't know who has copies of the keys. The previous team might have been great, or they might have left API keys scattered across the repo like breadcrumbs. Work through this checklist before you integrate anything into your stack.
Quick Checklist (5 Critical Items)
Credential Audit 5
Access Control 4
Dependency and Code Audit 5
Infrastructure Review 6
Treat Acquired Code as Untrusted
When you acquire a codebase, you're inheriting someone else's security decisions, along with whatever mistakes and technical debt came with them. You have no visibility into how credentials were handled or who had access historically. What shortcuts got taken? You usually don't find out until something breaks.
A 2024 study by Synopsys found that 84% of codebases contained at least one known vulnerability, and 48% contained high-risk vulnerabilities. The older the codebase, the higher the likelihood of issues. We see the same pattern in CheckYourVibe scans of handed-off projects: it's rarely the new code causing trouble, it's what got left behind in old configs and forgotten admin routes.
Should I rotate all credentials after acquiring a codebase?
Yes, always. You have no way of knowing who had access previously, or whether credentials ever got shared somewhere they shouldn't have. Rotate everything.
How do I find hardcoded secrets in an acquired codebase?
Use secret scanning tools like TruffleHog, GitLeaks, or GitHub's built-in secret scanning. Also manually search for common patterns like 'api_key', 'password', 'secret', and 'token' in the codebase. And don't just check the current state, scan the entire git history too, since old commits still count.
How long should a security audit of acquired code take?
A basic security audit takes 4 to 8 hours for a small application. Larger applications may require days or weeks. Prioritize credential rotation and access revocation first, as these are the highest risk items.
Scan Your Acquired Codebase
Get an automated security assessment to identify vulnerabilities quickly.