Thoughts on building software that lasts
Insights on web development, design, Laravel, the TALL stack, and building software that matters.
Cloudflare Turns On Visitor Tracking By Default. Here's How To Check.
Cloudflare quietly started enabling Web Analytics on free domains, injecting a tracking beacon without an opt-in step. Here's what site owners should verify.
A Record-Breaking AI Model Dropped Yesterday. I Told My Clients to Do Nothing.
Anthropic shipped its fourth frontier model in under two months. Here is why chasing each release is the wrong move for most businesses, and what to build instead.
Kimi K3 Is the AI Model Businesses Can Download. That Changes the Question.
Kimi K3 is a new AI model from China that will soon be downloadable. For businesses, the real question is what owning the model changes.
AI Didn't Make People Wrong. It Made Them Stop Saying "I Don't Know."
A new five-experiment study found AI access nearly eliminated people's willingness to admit uncertainty, cut accuracy to a third, and doubled confidence. Here's what that means for how you run your business.
I Use AI Every Day to Ship Software. The Hype Still Drives Me Nuts.
The loudest AI takes point in opposite directions and both miss the useful part. What actually matters for the software your business runs on.
An AI Coding Tool Got Caught Uploading Whole Repositories. Here's What Owners Should Ask.
A wire-level analysis found xAI's Grok Build CLI uploads your entire repo, git history, and even secrets by default. The real lesson isn't about one vendor.
An AI Agent Leaked Private Repos From a Public Comment. The Same Trap Is in Most Agent Setups.
GitHub's AI agent leaked a private repo because of a public comment. It's the lethal trifecta, and the same trap sits in most agent setups.
AI Features Are Metered Now. Don't Let the Meter Run in Your Tests.
Every automated test that calls a live LLM costs tokens on every push. Here's how to build AI features so the meter never runs in CI.
Anyone's AI Can Find Your Bugs Now. Triage Is the Whole Job.
An LLM can find the same security flaws a researcher would. That quietly breaks the contract software has run on for years, and changes what actually keeps your business safe.
Your AI Agent Can't Tell Who's Talking. That's Why It Gets Hijacked.
New ICML 2026 research explains why prompt injection is OWASP's #1 LLM risk and can't be patched. Here's what it means before you wire an agent into your business.
Vibe-Coded Prototypes Are Hitting Production. Here's What Cleanup Actually Looks Like.
AI tools are dumping prototypes into production faster than teams can review them. Here's the cleanup playbook we use on vibe-coded apps.
GitHub Copilot Just Switched to a Meter. Your Software Budget Needs to Catch Up.
GitHub moved Copilot to usage-based billing on June 1. Every plan now ships with a fixed AI Credit allowance, and agentic sessions are draining it fast. Here's how it lands on a real software bill.
Vibe-Coding Isn't the Problem. The Person Holding It Is.
The argument against vibe-coding mostly attacks beginners shipping code they can't read. In experienced hands it's a force multiplier, and judgment is the only thing that has ever separated good output from bad.
The Client Brief Template
A one-page PDF that helps you clarify your project before you talk to any developer. Covers goals, audience, scope, budget, and timeline. Fewer surprises, better outcomes.
Have a project ready to start?
Whether you need a full-stack application, a design refresh, or a technical partner who gets it — we'd love to hear about it.