Report will highlight any areas where core code has been directly modified.
Report will not only list any local overrides (general not good to have, but sometimes unavoidable), but it will also notate where those local overrides are missing updates from the original
Custom code will be reviewed for best practice implementation as well as for any potential security risks (XSS, CSRF, PCI, SQL Injection)