A number produced without questions is a bad sign. An experienced provider returns clarifying questions before any number: about users and python v php volumes. A vendor custom php development that prices with no clarification is simply working from a template, and that guess will be corrected later — at your expense.
Be wary of any distance between the people you meet and those who eventually appear in the repository. Insist on named engineers in the contract, with wording that requires notice before anyone is swapped. A vendor that only offers a pool of resources and refuses to name specific engineers is reserving the option to staff you with whoever is free.
Insist on the source repository from the start. A partner that hands over nothing between demos is asking you to trust a black box. Visible commits reveal the actual pace far better than any status report. This extends to the automated test suite: if there is no pipeline, promises about quality remain unverifiable.
Loose phrasing around intellectual property is never a formality. The document needs to state explicitly that all deliverables belong to the client as they are paid for. Look too at the jurisdiction and the payment schedule: heavy prepayment with nothing due in return for weeks takes away the only leverage you have.
Finally, examine the working rhythm. Establish how many hours the teams will share with your working day, which person handles questions and how quickly. Some genuine overlap generally works; zero overlap stretches each small question into a day of delay. Sloppy written English in the sales phase does not improve once the work starts.