How to Choose a Web Agency: 7 Red Flags That Actually Matter
Don't fall for offers that are too good to be true. Here's what to watch out for when choosing a partner for your website development.

Alex T.
Full Stack Developer
TL;DR: Most businesses pick agencies based on portfolios and price, then get burned by slow sites, security holes, or vendor lock-in. Here’s how to evaluate technical competence, communication patterns, and contract terms that protect your investment—based on what actually breaks in production.
The Problem: Why 60% of Web Projects Miss Deadlines
I reviewed 40 agency handovers last year. Half had critical issues: 15-second load times on mobile, database credentials in GitHub repos, or “custom” CMSes that trapped clients with $500/hour update fees.
The pattern? Business owners evaluated agencies like they were buying furniture—looking at surface finish instead of structural integrity. When your site loses 40% of mobile traffic to slow loading (Google’s data), or when a plugin update crashes your checkout, the portfolio aesthetics don’t matter.
Here’s what to actually check.
1. Core Web Vitals Benchmarks, Not Just “Fast Loading”
Ask for specific Lighthouse scores from live sites they’ve launched.
What to request:
- •Mobile Performance score > 90
- •LCP (Largest Contentful Paint) < 2.5s
- •CLS (Cumulative Layout Shift) < 0.1
- •Real User Monitoring (RUM) data, not just lab tests
Red flag: If they say “we optimize for speed” but can’t show CrUX (Chrome User Experience) reports from Search Console, they’re guessing.
Why this matters: Google uses these metrics for ranking. A pretty site that scores 45 on mobile performance is invisible in search results.
2. Git Workflow and Deployment Transparency
How they manage code matters more than what language they use.
Ask to see:
- •Sample GitHub/GitLab repository (sanitized)
- •Deployment pipeline: Do they deploy via FTP (red flag) or CI/CD with automated testing?
- •Rollback procedures: “How fast can you revert a bad deploy?”
The test: Ask what happens if a plugin update breaks the site at 2 AM. If they say “we’ll fix it in the morning,” keep looking. If they describe automated blue/green deployments with instant rollback, that’s competence.
3. Security-First Onboarding
Basic security isn’t optional in 2026.
Checklist:
- •Do they provide separate staging/production environments by default?
- •Is there a Web Application Firewall (WAF) in the architecture diagram?
- •How do they handle dependency updates (npm/composer packages)?
- •Do they conduct OWASP Top 10 testing before launch?
Red flag: No mention of dependency scanning or if they store passwords in plaintext config files.
Concrete example: A proper agency will show you their composer audit or npm audit workflow and explain how they handle zero-day vulnerabilities in dependencies.
4. Real AI Integration vs AI Washing
Every agency claims “AI-powered” now. Most mean they use ChatGPT to write alt text.
Distinguish between:
- •Marketing fluff: “We use AI for better designs”
- •Actual integration: Automated image optimization, intelligent caching, AI-driven search with vector databases, or predictive content personalization
Ask: “Show me one specific AI implementation that reduced load time or improved conversion rates, with metrics.”
If they can’t quantify it—“We reduced image payload by 60% using ML-based compression” vs “We use AI”—it’s theater.
5. Post-Cookie Analytics Architecture
Third-party cookies are dying. If their analytics strategy is “install Google Tag Manager and add Meta Pixel,” they’re behind.
What modern agencies should offer:
- •Server-side tagging (reduces client-side bloat)
- •First-party data collection strategies
- •GDPR-compliant event tracking without cookie banners
- •Privacy-preserving attribution models
Technical check: Ask how they track conversions if Safari blocks all third-party scripts. If they don’t have a server-side solution, your attribution data will be 40% inaccurate.
6. Maintenance That Prevents Breakage, Not Just Fixes It
Most agencies offer “maintenance” meaning “call us when it breaks.” That’s too late.
Look for:
- •Automated dependency updates with test pipelines (Dependabot/Renovate)
- •Uptime monitoring with SMS alerts (Pingdom, UptimeRobot)
- •Monthly security patches included in retainer
- •Performance regression testing (Lighthouse CI)
Contract language to demand: “Agency will apply security patches within 48 hours of CVE release” not “best effort support.”
7. Code Ownership and Exit Strategy
I’ve seen businesses held hostage by agencies that own the GitHub repo and charge $300/hour for minor text changes.
Non-negotiables:
- •You own the code repository (transferred to your GitHub/GitLab on day one)
- •Documentation in the repo, not just in their heads
- •No proprietary CMS that locks you in (unless it’s a specific business requirement)
- •Local development environment setup documentation so your next dev can run the site
Test: Ask “If I want to move to another agency in 6 months, what does that process look like?” If they hesitate or mention “migration fees” for your own data, leave.
Results: What You Get With Proper Vetting
Agencies that pass these checks typically deliver:
- •Sites that rank because they perform, not because they stuffed keywords
- •99.9% uptime vs “sorry, the server crashed again”
- •Clear handover documentation that lets you switch providers without pain
- •Security incidents prevented rather than cleaned up
Trade-offs and Limitations
This approach takes longer. You might spend 3 weeks evaluating agencies instead of 3 days. But a 3-week vetting process prevents a 6-month rebuild.
You’ll pay more upfront. Agencies with CI/CD pipelines, security audits, and proper devops cost 20-40% more than “WordPress installers.” But total cost of ownership is lower when you’re not paying emergency rates for security patches.
Not every project needs this. If you’re building a 5-page brochure site that won’t change for 2 years, you don’t need Kubernetes and AI search. Match the complexity of the agency to your actual business requirements.
Conclusion
Choosing a web agency isn’t about finding the best designer or the lowest price. It’s about finding a technical partner who treats your business infrastructure with the seriousness it deserves.
Start with the Git workflow question. If they can’t explain their deployment process clearly, nothing else matters—not the portfolio, not the price, not the pitch.
Further Reading
- •Web Vitals Documentation - Google Developers
- •OWASP Top 10 Web Application Security Risks
- •The Twelve-Factor App Methodology (for evaluating modern web architecture)
- •Core Web Vitals Case Studies (real performance impact data)
Key Topics
- The Problem: Why 60% of Web Projects Miss Deadlines
- 1. Core Web Vitals Benchmarks, Not Just “Fast Loading”
- 2. Git Workflow and Deployment Transparency
- 3. Security-First Onboarding
- 4. Real AI Integration vs AI Washing
About the author

Alex T.
Full Stack Developer
Expert in business with experience in developing high-performing web solutions for clients from Romania.
Need help?
If you have questions about business or want to discuss your project, we're here to help.
Contact us
