Thoughts on building software that lasts
Insights on web development, design, Laravel, the TALL stack, and building software that matters.
Cloudflare Turns On Visitor Tracking By Default. Here's How To Check.
Cloudflare quietly started enabling Web Analytics on free domains, injecting a tracking beacon without an opt-in step. Here's what site owners should verify.
An AI Coding Tool Got Caught Uploading Whole Repositories. Here's What Owners Should Ask.
A wire-level analysis found xAI's Grok Build CLI uploads your entire repo, git history, and even secrets by default. The real lesson isn't about one vendor.
An AI Agent Leaked Private Repos From a Public Comment. The Same Trap Is in Most Agent Setups.
GitHub's AI agent leaked a private repo because of a public comment. It's the lethal trifecta, and the same trap sits in most agent setups.
Cloudflare Opened OAuth to Everyone. The Default Integration Credential Just Changed.
Cloudflare opened self-managed OAuth to every customer. For third-party and delegated access, the long-lived API token is no longer the right default.
Anyone's AI Can Find Your Bugs Now. Triage Is the Whole Job.
An LLM can find the same security flaws a researcher would. That quietly breaks the contract software has run on for years, and changes what actually keeps your business safe.
Your AI Agent Can't Tell Who's Talking. That's Why It Gets Hijacked.
New ICML 2026 research explains why prompt injection is OWASP's #1 LLM risk and can't be patched. Here's what it means before you wire an agent into your business.
Laravel-Lang Got Compromised Through Git Tags. Here's What Every PHP Site Should Check Today.
On May 22, an attacker rewrote 700 existing git tags across Laravel-Lang packages instead of publishing new versions. composer.lock alone won't save you.
Vibe Coding Built Your Competitor's Website. Here's What They Don't Know Yet.
AI-generated websites are fast and cheap — until they expose customer data or crumble under real traffic. What business owners need to know before going all-in.
Give Partners API Access Without Building an Auth System From Scratch
Laravel Sanctum lets you issue API tokens to partners and power users in hours, not weeks — opening integration channels that can become real revenue.
Laravel Policies: Let Clients Manage Their Own Permissions
Laravel Policies and Gates give you fine-grained authorization that reduces support load and lets clients self-manage access without calling you.
The Client Brief Template
A one-page PDF that helps you clarify your project before you talk to any developer. Covers goals, audience, scope, budget, and timeline. Fewer surprises, better outcomes.
Have a project ready to start?
Whether you need a full-stack application, a design refresh, or a technical partner who gets it — we'd love to hear about it.