There's a specific kind of thrill in finding a project for sale that's exactly what you'd have built — already made, already working, already earning. The temptation is to move fast before someone else grabs it. That temptation is precisely how people get burned.
Here's the one rule that survives every acquisition horror story: every number is a claim until you've seen where it comes from. A revenue screenshot is a claim. A traffic graph is a claim. "It runs itself" is a claim. Good sellers won't mind you verifying — they'll expect it. The ones who mind are telling you something. So before you fall in love, run the checklist.
Check 01Follow the money
Revenue is the number people lie about most, because it's the number you're paying for. Screenshots take thirty seconds to fake, so don't accept them. Ask to see the live payment dashboard — Stripe, Paddle, the App Store, whatever it runs on — over a screen-share, and get the last 12 months exported, not a cherry-picked month.
And watch the timing. A sudden revenue spike in the weeks right before a sale — one that doesn't line up with any jump in traffic — is one of the oldest tricks in the book. It's there to inflate the asking price, and it usually evaporates the month after you buy.
Check 02Trace the traffic
Same principle: don't accept a picture of an analytics graph. Ask for read access to the actual analytics — Google Analytics, Search Console, Plausible, whatever's running — so you can poke around yourself. What you're looking for is where the visitors come from, because that's what tells you how fragile the whole thing is.
Check 03Read the actual code
You're buying software, so look at the software. You don't need to audit every line, but you do need to answer three questions: does the code actually match what the seller says it's built with? Is it something a normal developer could pick up and change? And — the one people forget — does the seller even own it?
Code written by a contractor without a signed IP assignment doesn't fully belong to the seller, which means it can't fully become yours. And if there's exactly one person on earth who understands how it works, you're buying a bus-factor of one. Ask who wrote it, ask to see it run, and ask what breaks if the original developer disappears.
Check 04Confirm what actually transfers
A deal isn't the code alone — it's everything that makes the code work. Before you close, get a written, itemized list of what comes with it, and make sure the important pieces can actually move to your name.
The tellRed flags that mean walk away
Most bad deals announce themselves if you're listening. Any one of these on its own is a conversation; two or three together is your cue to politely walk.
You're not being paranoid, you're being a buyer. A seller with a real business will happily prove it. The only person who fears verification is the one with something to hide.
The netLet the platform do the worrying
Here's the reassuring part. Even after you've done the homework, you don't have to trust a stranger with your money and hope. That's the entire job of a secure, on-platform payment: the buyer pays in crypto, the source code stays locked until the payment is confirmed, and then it unlocks. Nobody can walk off with both the code and the cash.
On Vertos, every deal runs on secure crypto payments by default, and every listing comes with that free AI Analysis of the real code. Do your own diligence anyway — no tool replaces a careful buyer — but know that the structure is built so an honest deal is easy and a dishonest one is hard.
Common questionsFrequently asked questions
How do you do due diligence before buying a SaaS or website?
Verify every claim at its source rather than trusting screenshots. Check revenue against the live payment-processor dashboard and 12 months of exports; verify traffic with read access to the analytics account, not images; review the actual source code for quality and ownership; and confirm the domain, accounts, and IP will transfer. Any gap between what’s claimed and what you can verify is a red flag.
How do you verify a website’s revenue before buying it?
Ask the seller to screen-share the live Stripe or payment-processor dashboard and export the last 12 months of transactions and, for SaaS, the subscriber list with MRR and churn. Screenshots are easy to fake; the live account and raw exports are not. Watch for a revenue spike right before the sale that doesn’t match traffic, and for any single customer making up more than 10–15% of revenue.
What are the biggest red flags when buying an online business?
A seller who won’t screen-share the revenue dashboard or dodges data requests; metrics that only exist as screenshots; a sudden pre-sale revenue spike; traffic from a single source or obvious bots; source code owned by contractors with no IP assignment; a one-developer bus factor; pressure to move fast; and refusing to pay on-platform.
Buy the head start.
Keep the safety net.
Every project on Vertos ships with a free AI Analysis of the actual code and secure crypto payments on every deal. Browse, verify, and buy without the leap of faith.
Browse projects →Buy the good ones. Walk from the rest. You'll know the difference now.
— The Vertos team