Notes from building things that hold up
Notes on revenue-critical code, plugin modernization, founder engineering, and products that last.
Almost everything here comes out of the same kind of work: the parts of a product where being wrong is expensive and the failure is quiet. Billing that has to survive a retry, a plugin you cannot take offline because thousands of sites are running it, a decision a founder cannot fully delegate. I write these to think properly about a problem rather than to publish on a schedule, so each one is opinionated, tries to name the trade-off honestly, and says where I would do the opposite. Start with a topic below if you want the argument as a body of work rather than a list of posts.

Auth mistakes in early products, and how to fix each
The same auth bugs show up in early products: session fixation, weak hashing, no rate limiting, tokens in the wrong place. Here is the fix for each.
Building something where this kind of work matters?
I'm in GMT+6 and work async-first, so your timezone is never a reason not to reach out.
Get in touch