Featured
Top insights and essential guides for modern development
Hosting a Vision Model for Medical Images Under HIPAA: Self-Host, AWS Bedrock, or Azure OpenAI?
A working engineer's guide to running a text-plus-image AI model on protected health information. What PHI, covered entity, and BAA mean in plain English, the three realistic hosting paths (self-hosted open-weight models, AWS Bedrock, Azure OpenAI and Foundry), where the paperwork gets murky for image inputs specifically, and the checklist to run before the first byte of PHI moves.
Apple Rejected My App Eight Times. Here's the Playbook I Wish I Had.
Three apps through App Review in one summer: SereneReader, Pulse, and SiteGrade. One of them collected eight findings in three rejection rounds. Here is what App Review flags, what the real cause usually is, and which rejections you answer with a reply instead of a build. Covers the sandbox-on-production trap, Sign in with Apple on macOS, closed version trains, Terms of Use metadata, and how to write the reply.
I Open-Sourced the Engine Behind AccessHawk. Meet A11yHawk.
A11yHawk is the open-source, self-hostable accessibility scan engine that powers AccessHawk. Real browser capture, Lighthouse audits, and bring-your-own-key AI analysis against every WCAG criterion. Build your own accessibility tooling without the per-scan SaaS bill.
84 Malicious TanStack Versions Hit npm. My Portfolio Pulled Zero.
On May 11, 2026, the Mini Shai-Hulud worm published 84 malicious versions across 42 TanStack packages in a six-minute window. My portfolio runs on TanStack Start. None of the bad versions ever touched it. Here is why, and what every project running npm should be doing right now.
That Accessibility Widget Isn't Protecting You. It's a Lawsuit Waiting to Happen.
Accessibility overlays like AudioEye and accessiBe promise WCAG compliance with a single line of JavaScript. The FTC, the courts, and the disability community all disagree. I dig into why overlays fail, what legal exposure they actually create, and what it takes to build accessibility into your source code.
Railway Is My Go-To Infrastructure. Here's Why I Recommend It to Enterprise Clients
I run several production projects on Railway, from SaaS platforms with background workers to simple marketing sites. After years on AWS and Azure, Railway cut my go-to-live time from days to minutes. Config-as-code, built-in databases, non-serverless deployments by default, and a platform that ships meaningful features weekly.
Security
OWASP best practices, supply chain protection, and application security
84 Malicious TanStack Versions Hit npm. My Portfolio Pulled Zero.
On May 11, 2026, the Mini Shai-Hulud worm published 84 malicious versions across 42 TanStack packages in a six-minute window. My portfolio runs on TanStack Start. None of the bad versions ever touched it. Here is why, and what every project running npm should be doing right now.
WordPress Was Already a Security Nightmare. AI Agents Are About to Make It Unlivable.
Someone spent six figures on 31 trusted WordPress plugins, planted a PHP deserialization backdoor, and sat on it for eight months before lighting it up in April 2026. Nothing in WordPress malfunctioned: the plugin ecosystem worked as designed. Here's why AI agents make every outdated install a bigger target, and what to move to instead.
Secure Vibe Coding is Possible
AI coding tools generate code faster than ever, but security scanning hasn't kept pace. Learn how to integrate Semgrep into your AI-assisted workflow with the Semgrep MCP server for real-time vulnerability detection, a pre-commit hook, and GitHub Actions for CI enforcement.
Stop Supply Chain Attacks: Why Your Build Pipeline Should Use Locked Dependencies
Switching CI from npm install to npm ci, committing your lockfile, and adding a release-age cooldown closes the window npm worms rely on. Why each layer works, and how to set them up for npm, pnpm, Yarn, and Bun.
OWASP Top 10 Security Priorities for Vue.js Developers
The OWASP Top 10:2025 mapped to Vue 3: what each risk looks like in a Vue app, the Composition API patterns that help, and the parts only your backend can fix. Covers the new supply chain and exceptional-conditions categories.
Developer Tooling
Framework comparisons, secrets management, and productivity tools
Why I Chose Nuxt Over Next.js for AccessHawk
I built AccessHawk with Nuxt instead of Next.js. Vue's reactivity model and auto-imports made me faster, and I didn't have to give up TypeScript or testing to get there.
Doppler Fixed My .env Syncing Problem Across Windows and Mac
I develop on a Windows desktop during the day and a MacBook in the evening. Keeping .env files in sync across three projects was tedious and error-prone. Doppler stores secrets in the cloud and injects them at runtime, so I stopped thinking about it.
Infrastructure
Hosting, analytics platforms, and deployment strategies
Anthropic Dropped Subscription Support for OpenClaw. OpenRouter Is the Fix.
Anthropic's April 2026 billing change dropped subscription support for OpenClaw and other third-party harnesses. OpenRouter is the cleanest migration path: same models, automatic failover, and freedom to switch providers without reconfiguring anything.
I Built an API So My AI Agent Could Read My RSS Feeds
I follow around 35 RSS feeds for infrastructure security, DevOps, and full-stack engineering. Most of it is noise. I built a JSON API for SereneReader so my OpenClaw agent could check my feeds three times a day and tell me what actually matters.
I Built an RSS Reader Because Every Alternative Kept Getting in the Way
Most RSS readers have become bloated dashboards full of popups, AI summaries nobody asked for, and upgrade banners that follow you around. I built SereneReader to do one thing well: let you read. Keyboard-first navigation, a focused reading mode that strips away every distraction, and an interface that respects your attention.
I Replaced Google Analytics with Umami. I'm Not Going Back.
I migrated all my SaaS products and personal sites from Google Analytics to a self-hosted Umami instance on Railway. No cookies, no consent banners, GDPR/CCPA compliant by default, and an API good enough that I built my own real-time multi-site dashboard around it. Here's why enterprise teams should pay attention.
Railway Is My Go-To Infrastructure. Here's Why I Recommend It to Enterprise Clients
I run several production projects on Railway, from SaaS platforms with background workers to simple marketing sites. After years on AWS and Azure, Railway cut my go-to-live time from days to minutes. Config-as-code, built-in databases, non-serverless deployments by default, and a platform that ships meaningful features weekly.
Enterprise CMS
Sitecore and Umbraco solutions from a certified enterprise developer
Make Sitecore 10.3 → 10.4 Upgrades Easier with Central Package Management
Move every NuGet version in a Sitecore solution into one Directory.Packages.props file, and a 10.3 to 10.4.1 upgrade becomes a find-and-replace in one file. The setup, the project-file changes, the Sitecore feed warning to expect, and the errors you'll hit along the way.
Building MCP Tools on Umbraco 13 and N8N AI Chat Workflows
How I built an AI assistant over a healthcare technology vendor catalog with custom MCP tools inside an Umbraco 13 site, ElasticSearch instead of a vector database, and one n8n agent instead of several. Tool design, the system prompt, and why the multi-agent version lost.
AI & Automation
MCP tools, AI integration, and AI-assisted development
Anthropic Deleted 80% of Claude Code's System Prompt. Here's What to Delete From Yours.
Claude Opus 5 lands near Fable 5 intelligence at Opus 4.8 pricing, and the prompting habits that made Opus 4.8 good now make Opus 5 worse. Anthropic cut over 80% of Claude Code's system prompt with no measurable loss on coding evals. Here's how the model compares, plus what to cut from your CLAUDE.md, your verification instructions, your subagent caps, and the one API change that returns a 400.
Your Claude Prompts Are an Audit Gap. LiteLLM Closes It.
A staff engineer's case for putting LiteLLM in front of Claude to close the audit gap: PII filtering, secret detection, virtual keys per user, and a real log of every prompt. Config examples and an honest take on the tradeoffs.
Anthropic Dropped Subscription Support for OpenClaw. OpenRouter Is the Fix.
Anthropic's April 2026 billing change dropped subscription support for OpenClaw and other third-party harnesses. OpenRouter is the cleanest migration path: same models, automatic failover, and freedom to switch providers without reconfiguring anything.
Secure Vibe Coding is Possible
AI coding tools generate code faster than ever, but security scanning hasn't kept pace. Learn how to integrate Semgrep into your AI-assisted workflow with the Semgrep MCP server for real-time vulnerability detection, a pre-commit hook, and GitHub Actions for CI enforcement.
Cut LLM Context Usage by Up to 90%: Filter Azure DevOps MCP Tools with a Proxy Server
The Azure DevOps MCP server exposes 70 tools consuming 55,125 tokens of Claude's context window. Learn how to build a filtering proxy server that reduces this to just the tools you need, reclaiming up to 90% of your context for actual work.
Building MCP Tools on Umbraco 13 and N8N AI Chat Workflows
How I built an AI assistant over a healthcare technology vendor catalog with custom MCP tools inside an Umbraco 13 site, ElasticSearch instead of a vector database, and one n8n agent instead of several. Tool design, the system prompt, and why the multi-agent version lost.
Other
Additional articles and guides
Hosting a Vision Model for Medical Images Under HIPAA: Self-Host, AWS Bedrock, or Azure OpenAI?
A working engineer's guide to running a text-plus-image AI model on protected health information. What PHI, covered entity, and BAA mean in plain English, the three realistic hosting paths (self-hosted open-weight models, AWS Bedrock, Azure OpenAI and Foundry), where the paperwork gets murky for image inputs specifically, and the checklist to run before the first byte of PHI moves.
Apple Rejected My App Eight Times. Here's the Playbook I Wish I Had.
Three apps through App Review in one summer: SereneReader, Pulse, and SiteGrade. One of them collected eight findings in three rejection rounds. Here is what App Review flags, what the real cause usually is, and which rejections you answer with a reply instead of a build. Covers the sandbox-on-production trap, Sign in with Apple on macOS, closed version trains, Terms of Use metadata, and how to write the reply.
I Open-Sourced the Engine Behind AccessHawk. Meet A11yHawk.
A11yHawk is the open-source, self-hostable accessibility scan engine that powers AccessHawk. Real browser capture, Lighthouse audits, and bring-your-own-key AI analysis against every WCAG criterion. Build your own accessibility tooling without the per-scan SaaS bill.
GEO is the New SEO: Optimizing for AI Answer Engines in 2026
Generative Engine Optimization (GEO) is the discipline of getting cited by ChatGPT, Perplexity, Claude, and Gemini. It shares a foundation with SEO, but much of the work is new territory, and it's worth learning now.
Why I Rebuilt My Portfolio with TanStack Start
I previously wrote about choosing Nuxt over Next.js. Then I rewrote my entire portfolio in React. This isn't a framework war - it's about what TanStack Start gets right that Next.js doesn't, and why the rebuild was worth it.
That Accessibility Widget Isn't Protecting You. It's a Lawsuit Waiting to Happen.
Accessibility overlays like AudioEye and accessiBe promise WCAG compliance with a single line of JavaScript. The FTC, the courts, and the disability community all disagree. I dig into why overlays fail, what legal exposure they actually create, and what it takes to build accessibility into your source code.
Contact
Drop me a line. I read everything and reply within a day.
