A quote that comes back within a day should be treated as a warning, not a service level. A competent team responds with questions first: about integrations. A supplier that commits to a figure before understanding the scope is probably guessing, and a guess becomes a change request later — on your budget.
Watch for any distance between the people you meet and those who eventually appear in the repository. Request named engineers in the contract, with a provision covering replacement. A vendor that talks only about roles and never names people is keeping the option to staff you with whoever is free.
Insist on the source repository from the first week. A team that delivers nothing difference between laravel and wordpress demos is inviting you to trust a black box. Regular commits and laravel or symfony pull requests reveal the actual pace far better than a slide deck. The same holds for the build and deployment setup: if it does not exist, promises about quality remain just talk.
Ambiguous wording in the contract around code ownership is never an accident. The agreement must state plainly that the code, designs and documentation belong to the client upon settlement of the relevant invoice. Also check the governing law and the milestone terms: heavy prepayment with nothing due in return for weeks removes the only leverage you have.
Last, examine communication. Establish what overlap the teams will share each day, who answers day-to-day questions and within what time. Four hours of overlap is normally sufficient; zero overlap turns each small question into a lost day. Unclear written communication in the early emails will not improve later.