How to set up HSTS without locking yourself out
HSTS is powerful and unforgiving. Roll it out in stages, audit subdomains first, and treat preload as a one-way door.
Practical, privacy-first writing on the web tools we build and the problems they solve.
HSTS is powerful and unforgiving. Roll it out in stages, audit subdomains first, and treat preload as a one-way door.
A practical guide to noopener, noreferrer and nofollow: what they change, when to use them, and what they do not fix.
A practical guide to preload, prefetch and preconnect: what each hint does, when it helps, and when to leave it alone.
WebP lossless often beats PNG on file size, but not always. Here is when it helps, when it does not, and how to test it properly.
An AI knowledge base per project gives service providers an AI that knows their clients, cases, and conversations — with sources, without noise.
llms.txt is useful as a clear AI-facing index, but it is not a standard, not enforceable, and not a replacement for robots.txt.
Image filenames are a small ranking signal and a useful maintenance habit. Here is how to name them without overdoing SEO.
Permissions-Policy can reduce browser feature access, especially in iframes. It is useful, but narrower than many teams assume.
Self-host Google Fonts to reduce third-party requests, improve privacy posture, and gain better control over performance.
Variable fonts are powerful, but production results depend on subsetting, caching, rendering, CSS discipline, and design restraint.
HTTP status codes shape crawling and indexing, but not all of them matter equally. Here is what SEOs and developers should prioritize.
Compress web audio well by choosing the right codec, bitrate, source workflow, and listening test—not by crushing everything to MP3.