Handbook
Practices, not tools
Individual tools are in the toolbox. These are the approaches — what to check before a launch, how to work out whether a bug is yours, and which security work pays for itself.
- The Checks Worth Running Before a Launch Most launch disasters are not dramatic. They are a robots file that came from staging and a share card that renders as a bare link.
- Is It My Code, the API, or the Browser? The console message usually names a rule, not a cause. Three checks in the right order tell you whose problem it actually is.
- Core Web Vitals Without the Score Obsession A hundred in the lab and a failing field assessment is a normal, consistent outcome — not a contradiction to be reconciled.
- Which Security Headers Are Worth the Risk Three of them are safe to ship this afternoon. One of them will break your analytics, and it is also the one that matters most.
- Taking Over a Site Somebody Else Built The documentation is wrong or missing. Everything you actually need can be established from outside in about an hour.