Do I need a website if I have social media?
They do different jobs. The risk is building only on land you do not own.
Guides on Next.js, React, backend architecture, databases, infrastructure, performance, security and search — from production work, not theory.
127 in-depth guides on web development, infrastructure and search.
They do different jobs. The risk is building only on land you do not own.
It is routine. The two things that go wrong are email and forgotten redirects.
It is almost always the photos. Here is how to fix it yourself.
A privacy policy is the one nearly everyone needs. The rest depends.
The simplest method is asking. The second simplest is a separate phone number.
Squarespace for most, WordPress if you need plugins, Wix if you want layout freedom.
Gather these seven things first and your project will not slip.
One to nine weeks. The delay is almost never the building.
Most people have backups. Far fewer have ever tested restoring one.
It is not about you. It is about why someone should trust you.
Yes, you need it. No, you should not be paying for it.
Usually no. An abandoned blog looks worse than none at all.
Test your own form right now. A surprising number have not delivered an email in months.
Usually four to six. More pages is not better, and thin pages actively hurt.
Usually yes. Here is when it genuinely is not, and how to price when every job differs.
Ten questions. The answers to three of them tell you almost everything.
Three real price brackets, and how to tell which one your business actually needs.
Two reviews a week beats twenty once. Here is the routine that actually works.
Hosting is renting space for your website to live. Here is what it should actually cost.
Work through these seven checks in order. One of them is almost always the answer.
Animation is cheap on a MacBook and expensive on a three-year-old Android. Only one of those is your audience.
A missing environment variable should crash the app at startup, not produce a confusing bug three hours into production.
The patterns that stop bugs, and the point at which type-level cleverness starts costing more than it saves.
Trust in software is built in the unglamorous states: what happens when something fails, and whether you can undo it.
A landing page is one argument made in the right order. Most fail on the first line.
Scope creep rarely arrives as one big change. It arrives as twenty small ones nobody priced.
Traditional SEO competes for a click. AEO competes to be the sentence the assistant reads out — often with no click at all.
Technical SEO is mostly engineering work: correct status codes, canonical URLs, crawlable HTML and fast pages. None of it requires a keyword tool.
Three numbers, each measuring a different way a page can feel bad: slow to appear, slow to respond, and unstable while you use it.
Not a compliance document. This is the list we actually work through before a client site handles its first real user.
A 1.2GB Node image that runs as root and ignores SIGTERM is the default outcome. Every part of that is avoidable.
GEO is less about ranking and more about whether an AI system can describe your company accurately when someone asks about it.
Vercel sells you time. AWS sells you control. The right answer depends on which of the two your team is short of.
The two Next.js routers are not two syntaxes for the same thing. They are different rendering models, and that difference decides your data fetching, caching and hiring plan.
A canonical tag is a suggestion, not an instruction. Getting it consistently right across a site is what makes the suggestion credible.
An API is a product with developers as users. Most of what makes one good is consistency, not cleverness.
LCP is not one number, it is four phases. Optimising the wrong one is why so much performance work produces no measurable change.
Sprinkling memo and useCallback across a codebase is not optimisation, it is superstition. Measure first, then apply one of four structural fixes.
The Top 10 is a list of categories, not bugs. Here is what each one looks like in a real codebase.
Most Dockerfiles are copied from a tutorial and never revisited. Twenty minutes of attention usually halves both build time and image size.
Adding an index is easy. Knowing which one, in which column order, and which existing indexes to delete is the part that changes query times.
Blocking AI crawlers protects your content from training. It may also remove you from the answers people now use instead of search.
Every host looks fine on day one. The differences show up when traffic triples, a region goes down, or you need to leave.
Server components are not 'SSR with extra steps'. They change what code ships to the browser at all — and that changes how you structure a codebase.
Structured data does not improve rankings directly. It changes how your result looks and how machines understand your page, which is worth more than it sounds.
Node is single-threaded for your code. Every millisecond you spend in a synchronous loop is a millisecond nobody else's request is being served.
INP is the metric that exposes how much JavaScript you shipped. A page can load in a second and still feel broken when tapped.
Most 'state management' debates are category errors. Server data and UI state are different problems and need different tools.
React escapes text by default, which handles most XSS. The remaining cases are the ones people write deliberately.
Kubernetes is excellent at problems most teams do not have yet. The cost of adopting it early is paid in engineering hours you needed elsewhere.
Everyone runs EXPLAIN. Fewer people read the row estimates, which is where the actual answer usually is.
AI systems do not read your page. They retrieve chunks of it. Write so that any single chunk still makes sense alone.
Putting a CDN in front of a site does nothing by itself. The cache headers you send decide whether it helps or just adds a hop.
Most 'Next.js is showing stale data' bugs are one of four caches doing exactly what it was told. Here is the mental model that makes them predictable.
A div can be styled to look like anything. It cannot be understood as anything, which is the whole problem.
The sessions-versus-JWT argument is really an argument about revocation. Decide how fast you need to be able to log someone out.
CLS is the most fixable Core Web Vital. Almost every point of it comes from an element that did not tell the browser how big it would be.
These are not beginner mistakes. They are the ones that pass review, work in development, and break under real conditions.
SameSite=Lax handles most CSRF. 'Most' is doing real work in that sentence, and the gap is where the interesting attacks live.
You do not need to run a cluster to ship to one. This is the subset of Kubernetes that appears in an application developer's day.
Every PostgreSQL connection is a process. Ten containers with a pool of twenty is two hundred processes, and your database was configured for one hundred.
AI Overviews answer the question and cite a few sources. Being one of them is the new position one — with fewer clicks attached.
Serverless is excellent for spiky, stateless, short work. The trouble starts when your workload is none of those things.
Hand-writing meta tags per page guarantees drift. Here is how we wire the Metadata API once so no page can ship without a canonical, an OG image and a description.
A sitemap is a list of the URLs you are confident about. Padding it with redirects and noindex pages teaches Google to ignore it.
Rate limiting is not just abuse prevention. It is the mechanism that stops one client's bad afternoon from becoming everyone's outage.
Bundle size is the cost you pay on every visit, on every device. It is also the one performance metric that only ever grows unless someone owns it.
Every codebase is well organised on day one. The question is what it looks like after forty feature requests have been bolted onto the same Button.
Parameterised queries have solved this for twenty years. Injection persists because of the one query someone built with string concatenation.
A pipeline that takes 25 minutes and fails randomly does not improve quality. It teaches the team to merge on red.
MongoDB is schemaless in the same way a spreadsheet is: you still have a schema, it is just enforced by whoever wrote the last query.
Most cloud bills have 30% of obvious waste in them. Finding it takes an afternoon; the hard part is having the conversation about what to turn off.
Rendering strategy is a per-route decision, not an architectural religion. A single Next.js app can and should use all four.
Migrations lose traffic for one reason more than any other: a redirect map that was built quickly and never checked.
Every request that sends an email, generates a file or calls a third party is a request that should have returned already.
Fonts are usually the second-largest asset on a page and the most common cause of text that appears late, then jumps.
Some decisions can be changed in an afternoon. These seven set the shape of the codebase for years, so they deserve an hour of thought each.
Six headers, most of them one line each. They will not fix a vulnerability, but several of them turn one into a non-event.
Zero downtime is not a deployment tool setting. It is a property of an application that can run two versions at once.
Caching is easy until the cache expires. Everything interesting about Redis in production happens in the seconds after a popular key disappears.
Search engines stopped matching strings a long time ago. They match things — and if they cannot tell which thing you are, nothing else helps.
DNS is the layer everyone touches twice a year and nobody remembers. It is also the fastest way to take a site offline for 24 hours.
A server action is a public HTTP endpoint with nicer syntax. Treat it like one and they are excellent; forget that and you have shipped an unauthenticated API.
'Discovered – currently not indexed' is Google saying your page is not worth the crawl. That is a content problem wearing a technical costume.
GraphQL solves a real problem for a specific shape of team. If you are not that team, it is a large bill for flexibility you will not use.
Images are usually the largest thing on a page. Format and compression choices routinely cut that weight in half with no visible difference.
Forms are where most web products earn their money and where most accessibility audits fail. The details are small and the impact is not.
Your application is mostly other people's code. The security question is not whether you trust it, but what happens when one of them is compromised.
Observability is not more dashboards. It is being able to answer a question you did not anticipate, without shipping new code.
The honest default for most products is PostgreSQL. Here is the specific set of conditions under which it is not.
AI search measurement is genuinely immature. The honest approach is a few reliable signals and a manual log, not a dashboard implying precision.
Certificates are free and automatic now. The remaining failures are almost all renewal automation that silently stopped working.
next/image solves format, sizing and lazy loading for you — and then hands you two props, sizes and priority, that decide whether your LCP is 1.2s or 4s.
Search engines still cannot see your images. Everything they know comes from the filename, the alt text and the words around it.
The goal of error handling is not to prevent crashes. It is to make sure that when something fails, you can tell what, where and for whom.
Every third-party tag runs on your main thread, in your users' browsers, with your performance budget. Almost none of them have an owner.
Most accessibility failures in React apps come from a handful of repeated patterns. Fix these twelve and the audit gets short.
An API has no UI to hide behind. Every endpoint is directly reachable, and that is the correct way to think about securing one.
Clicking through a cloud console works right up until you need the same thing again, in another region, at 2am, from memory.
The migration that takes your site down is almost never the complicated one. It is the ALTER TABLE that took a lock nobody expected.
An FAQ section is either the most useful part of a page or three hundred words of filler. The difference is where the questions came from.
Routing uploads through your application server is the default and the wrong one. Presigned URLs remove the bottleneck and most of the risk.
Middleware is the cheapest place to redirect a request and the most expensive place to make a database call. The matcher config is the whole game.
Internal linking is the one ranking factor you fully control. Most sites still link almost entirely from the navigation.
Microservices solve an organisational problem with a distributed systems bill. If you do not have the organisational problem, you just have the bill.
Performance work that happens once decays within two quarters. A budget makes it a constraint every pull request has to respect.
Users judge reliability by how your app behaves when something goes wrong. Most apps put all their design effort into the happy path.
Forced quarterly rotation and mandatory symbols make passwords worse. Current guidance says length, breach checks and MFA.
Container security starts with four lines in a Dockerfile and a scan in CI. Most breaches involve failures at that level, not exotic escapes.
You do not have backups. You have restores — and you only know whether you have those if you have done one this quarter.
Topical authority is not a number of articles. It is whether someone who reads your site comes away genuinely informed about the subject.
Most teams asking for multi-region want lower latency for distant users. That is usually a CDN problem, not an architecture problem.
Launch day problems are almost never novel. This is the list that catches them — the same one we run on every client deployment.
Google renders JavaScript. It renders it late, inconsistently, and other crawlers often do not render it at all.
Webhooks are an API you deliver to someone else's unreliable server. Design for their failures, not just your success.
A perfect Lighthouse score and failing Core Web Vitals is not a contradiction. They measure different things, and only one of them is your users.
Most slow React pages are not slow because of rendering. They are slow because six requests are queued behind each other for no reason.
Most sites need less than the compliance industry suggests and more than they currently do. The gap is usually consent and retention.
During an incident, the instinct is to find the cause. The job is to restore service. Those are different activities and the order matters.
Both are excellent. The differences that matter now are extensibility, data type strictness and operational culture, not raw speed.
Google does not penalise AI content. It penalises content produced at scale primarily to manipulate rankings — which is what most AI content is.
The question is not whether a secret will leak. It is whether you will know, and how long it takes to make the leaked one useless.
The question is never 'React or Next.js'. It is 'do I want to own routing, rendering, bundling and SEO myself, or not'.
The hard part of versioning is not the URL scheme. It is agreeing on what counts as breaking, and then actually retiring the old version.
A test suite nobody trusts is worse than none — it costs time and provides false confidence. Here is what we actually test on client projects.
Read Committed prevents dirty reads. It does not prevent two people spending the same balance — and that is the bug you will get.
You cannot debug what you cannot picture. This is the map of a production request, layer by layer.
Shorter notes on craft, product and process.
Why the smallest interface details — loading states, empty states, error copy — decide whether users trust your product.
How treating Core Web Vitals as a design constraint — not a post-launch fix — changes the way you build interfaces.
Breaking down the structural decisions behind high-converting landing pages — beyond just 'add more social proof.'
Emerging UI patterns for products built on voice synthesis and conversational agents — and where most teams get it wrong.
A framework for deciding when motion adds clarity versus when it's just decoration competing for attention.
The scoping mistakes that turn a four-week project into a four-month one — and how we structure engagements to avoid them.
No spam. Just the occasional case study and craft breakdown.