Shopify Store Due Diligence Checklist for Agencies

A shopify store due diligence checklist agency teams can actually use looks different from most of what ranks for that phrase right now. Search it and you land on advice written for someone about to buy a Shopify store on Flippa or through a broker: check the financials, verify the traffic, ask why the owner is selling. That's a real situation, but it isn't the one most agencies are in. Agencies don't usually buy the stores they work on. They inherit them, mid-migration, mid-rebrand, or mid-complaint about whoever built the thing last. The question in that room isn't "should I pay for this business." It's "what am I actually agreeing to fix, and what's already broken that nobody mentioned on the discovery call."
Why the standard checklist doesn't fit an agency pitch
The two most thorough guides on this topic take a buyer's sequence: financial documents, traffic verification, supplier relationships, then a red-flags section for a business you might purchase outright. That's the right structure if you're wiring a purchase price to a stranger on Flippa. It's the wrong structure if you're deciding whether to quote a rebuild, and it skips almost everything an agency needs to know before writing a scope of work: what theme the store is running, what apps are installed and whether any of them conflict, whether the checkout has been customized in ways that don't survive a migration, and why the last agency isn't in the room anymore.
One closer guide, written for Shopify agencies in the UK, comes at this from the other direction. It's about a client vetting a prospective agency, not an agency vetting a prospective client's store. That's a useful document to have read, but it doesn't answer the question this post is for.
The checklist: what to check before you pitch or take over a Shopify store
1. Read the theme before you read the brief
Before you sit through a discovery call, look at what's actually live. A theme detector reading of the storefront tells you in a few seconds which theme the store declares and, when it publishes one, its Theme Store ID. A renamed theme, or no Theme Store ID at all, hints at a custom or heavily modified build; a stock name does not prove the opposite, since no outside read can tell how much the code was changed. Either way it's a starting point for scoping, and it's information you can gather before the prospect has told you anything.
2. Map the installed app stack
Ask what apps are running, then check for yourself. An app detector scan shows which apps it can identify from what the storefront loads, not just what came up in the sales conversation. Treat that list as a floor: apps that run only in the admin, the checkout, or on Shopify's servers leave no trace in the page, so finding none proves nothing. This matters more on Shopify than on most platforms because app conflicts, deprecated APIs, and theme app extension debt are a common source of the bugs a new agency inherits and gets blamed for. If the store still depends on checkout.liquid customizations, that's a migration cost to price in now, not something to discover after signing.
3. Count the catalog before you scope the work
Catalog size and structure drive a lot of the actual labor in a migration or rebuild. Pulling a product export gives you a real product and variant count, with SKUs, vendors, and product types, instead of relying on whatever number is in the pitch deck. A store the exporter hasn't seen before joins its collection queue, so run it a day or so ahead of the call. Collections, metafields, and anything else that only lives in the admin you'll still need to see from inside the store.
4. Ask directly why the client is switching agencies
This is one of the most common real-world diligence triggers and one of the least discussed in the buyer-focused guides: a Shopify Plus partner gets asked to take over a store built by a previous agency. The answer to "why are you switching" tells you more about the engagement than almost anything else on this list, and it's the one item on this checklist that costs nothing but a direct question.
5. Check traffic composition, not just traffic volume
A prospect telling you their store gets a lot of traffic doesn't tell you where it comes from. One buyer-diligence guide flags a specific heuristic worth borrowing for agency work too: traffic where 90% of visits are Direct, from a store with no strong brand presence to explain it, is a sign the traffic may be inflated.
6. Check page speed against a plain benchmark
Page speed is easy to check and easy to skip. The same buyer-guide literature cites a widely used figure from Google, reported as 53% of mobile site visits being abandoned once a page takes longer than three seconds to load. That's a buyer's statistic, not an agency one, but it's a useful gut check either way: a slow storefront is a scoping item, not a surprise you should be finding after the contract is signed.
7. Check the return or refund rate if it's shared
If financials are on the table, the same buyer guide that flags Direct traffic treats a refund rate over roughly 5-10% as a warning sign. For an agency this is less about deal risk and more about signal: a high refund rate can point to product quality or fulfillment problems that have nothing to do with the website, and no rebuild will fix them.
8. Verify the revenue number independently
A pitch deck number is a claim, not a fact. Checking it against public storefront signals gives you something to compare it to before the call, rather than after. StorePrism's revenue estimator builds its estimate from the store's public inventory, read on a schedule over time. For a store it has watched long enough, that gives a floor on what the store demonstrably sold plus a monthly projection; for one it hasn't, it says it is still gathering data rather than guessing. It won't replace a look at real financials, but when it has an answer it gives you a second number to hold the conversation against.
9. If it's Shopify Plus, check the parts that are hard to migrate
Plus-tier stores carry migration risk that doesn't show up on a standard storefront read: checkout.liquid or checkout extensibility customizations, Shopify Functions or Scripts that encode business logic nobody wrote down, and multi-store Organization structures with B2B channels layered on top. None of the buyer-focused checklists we read mention any of this, because a Flippa buyer isn't usually looking at a Plus store with custom checkout logic. An agency taking one over needs to know before quoting, not after.
10. Write down what you found before the call
The point of the checklist isn't just to gather information, it's to have a record of what you found and when you found it, separate from what the prospect told you. That record is what turns into your scope of work, and it's what protects both sides when the engagement runs into something nobody mentioned.
What this checklist doesn't prove
None of the above tells you whether the client will be good to work with, whether the previous agency's invoices got paid, or whether the number in the pitch deck is accurate to the dollar. A theme read shows what's live on the storefront right now, not what's waiting in a codebase you haven't gotten repo access to yet. A traffic or revenue estimate built from public signals is a data point for a pricing conversation, not a substitute for real financials once you're far enough along to ask for them. Treat every item here as something to check before the call, not something that replaces the diligence you'd still want to do once there's a signed NDA on the table.
FAQ
What should an agency check before pitching on an existing Shopify store? Start with what's publicly visible: the theme, the installed app stack, and the catalog size. Then ask directly why the client is switching agencies, and check traffic composition and page speed as a gut check against whatever numbers are in the pitch deck.
How do you verify a Shopify store's traffic is real? There's no single test, but a traffic mix that's overwhelmingly Direct is a documented red flag in the buyer-diligence literature, and worth checking even when you're not the one buying.
What are the red flags when taking over a Shopify store from another agency? The most direct one is the answer to why the client is leaving their current agency in the first place. Beyond that, a high refund rate, an unusually slow storefront, and heavy custom checkout logic on Shopify Plus are all things worth pricing into a quote rather than discovering mid-project.
Do agencies need the same due diligence as someone buying a store outright? No. A buyer is verifying a business before paying for it. An agency is scoping a project before quoting it. The checks overlap, but the reason for running them, and what you do with the answers, is different.
Before the next pitch
Most of what's written about Shopify due diligence assumes you're about to buy the store. If you're an agency deciding what to quote instead, the checklist looks different: read the theme, map the apps, count the catalog, and ask why the last agency is gone. Run the numbers you're given against something you checked yourself before you're in the room. StorePrism's revenue estimator is one way to get that second number before your first call, once it has watched the store long enough to give one.