Your Backup Is Green. Can You Actually Restore the Website?
A successful backup job does not prove recoverability. Audit restore tests, RPO/RTO, data scope, access, dependencies, and functional validation before a real outage happens.
Insights
Honest takes on AI-generated code, website obligations, privacy, hosting, and technical strategy for small businesses.
Audiences
Local sectors with sensitive contact points get their own entry pages and clear technical scope boundaries.
94 posts
Filter by category
A successful backup job does not prove recoverability. Audit restore tests, RPO/RTO, data scope, access, dependencies, and functional validation before a real outage happens.
Passkeys are more than a new sign-in button. Audit RP ID, origins, server verification, conditional UI, user verification, cross-device use, and recovery as one authentication architecture.
A practical handover audit for registrar access, nameservers, DNSSEC, CAA, mail records, TTLs, and recovery before an agency or hosting change.
103 Early Hints can start critical resources sooner. Bad preloads, stale assets, auth boundaries, and misleading TTFB measurements can erase the benefit.
WordPress can roll back automatic plugin updates when PHP fatal errors are detected. Learn why that matters — and why rollback still does not replace functional tests, monitoring, or recovery.
A working Google, Microsoft, or SSO login does not prove a secure OAuth/OIDC integration. Audit redirect URIs, PKCE, state/nonce, issuer binding, and preview environments.
CHIPS scopes third-party cookies to a top-level site. Audit Partitioned, browser fallbacks, embedded widgets, sessions, and the privacy assumptions around them.
A Brotli or gzip toggle in hosting is not proof of delivery. Audit Content-Encoding, Accept-Encoding, CDN and proxy behavior, cache variants, and real transfer size.
Session cookies do not automatically protect private responses. Audit Cache-Control, Vary, CDN rules, and logout behavior with two test accounts.
RFC 9989 replaces the old DMARC specification. What changed around pct, test mode, reporting and website email – and how to audit SPF, DKIM, alignment and deliverability in practice.
Safe schema changes need more than a successful migration. Audit lock risk, backwards compatibility, rollback safety, and the expand-contract release pattern.
Permissions Policy limits browser capabilities such as camera, microphone, and geolocation. Audit headers, iframe delegation, third-party widgets, and rollouts without blindly breaking features.
Sticky headers, consent banners, chat panels, and fixed toolbars can hide focused links and fields. Audit WCAG 2.2 Focus Not Obscured in real keyboard journeys.
An AAAA record can open a second production path. Audit DNS, reachability, TLS, redirects, and security controls separately across IPv4 and IPv6.
Why service workers can keep users on stale frontend versions after a deployment, and how to audit the update lifecycle, caches, and rollout behavior.
Why inaccurate lastmod timestamps, redirects, and non-canonical URLs weaken a sitemap, and how to audit it as a reliable technical inventory.
Webhooks rarely fail on the happy path. Audit signatures, replay controls, retries, duplicates, ordering, idempotency, and durable queue boundaries.
Source maps are not automatically a security flaw. But accidentally public maps can reveal source code, filenames, and project structure. Audit build, deployment, and error monitoring deliberately.
Autofill is part of the conversion journey. Audit autocomplete semantics, input purpose, address sections, and mobile form behaviour before avoidable friction becomes abandonment.
A technical audit guide for recovery flows: token lifetime, single use, referrers, third parties, redirects, rate limits, and session invalidation.
A practical audit for analytics, chat, A/B testing, consent tooling, and other third parties: which scripts create business value, and which consume load time, main-thread time, and maintenance budget?
Websites use window.postMessage to exchange data with iframes, login popups, payment windows, and widgets. Audit targetOrigin, event.origin, event.source, message schemas, and privileged actions.
A centred overlay is not automatically a working modal dialog. Audit focus, keyboard navigation, Escape, inert backgrounds, focus return, and native dialog semantics.
Domains, DNS, hosting, source code, and Search Console can work for years until an agency changes. This handover audit shows which accounts and ownership paths should be clear before the transition.
Why noindex and robots.txt do not replace access control, and how teams can audit staging and preview environments for indexing, access, data exposure, and production coupling.
Backups can succeed every day and still fail during an incident. Audit restore tests, dependencies, RPO/RTO, credentials, validation, and real recovery time before you need them.
Multilingual pages can be reachable yet still lose the right language version in search. Learn how to audit canonicals, hreflang clusters, sitemaps, and language switching.
An old CNAME pointing to a deleted cloud or SaaS resource can become a claimable subdomain. Audit DNS lifecycle, verification, and decommissioning before trust outlives the service.
CORS decides whether browser JavaScript may read a cross-origin response. It does not replace authentication, role checks, CSRF protection, or server-side access control.
A SPA can render a perfect not-found screen while still sending HTTP 200. Learn how to audit soft 404s, client routing, status codes, monitoring, and indexing.
Contact forms, password resets, receipts: audit SPF, DKIM, DMARC, alignment and bounce handling before important website email quietly disappears.
A first-party tracking endpoint gives you more control over data flows, but it does not automatically make analytics or advertising consent-free. Audit Consent Mode, server containers, logs, and data minimisation.
Prefetch and prerender can make navigation dramatically faster — but they can also trigger analytics, cart state, login logic, and server work too early. Here is how to audit the rollout.
A session cookie can use HTTPS, HttpOnly, and SameSite while still being scoped too broadly across subdomains. Audit Domain, Path, prefixes, and real login flows.
Extensions, MIME types, and antivirus scans are not enough on their own. Audit validation, quarantine, storage, browser delivery, and access control.
A new release is online, but open tabs can keep old code. Audit the service-worker lifecycle, cache versions, skipWaiting, and mixed-version deployments.
Retries, duplicates, reordering, and silent worker failures make webhooks fragile. Audit idempotency, queues, signatures, and reconciliation.
WP-Cron is traffic-triggered by default. Learn how to inspect scheduled jobs, spot overdue events, and make critical WordPress automation more reliable.
AI crawlers do not all serve the same purpose. Learn how to separate search, model training, agents, and real access control across robots.txt, CDN, and WAF.
Chrome can restore some `Cache-Control: no-store` pages from bfcache. Learn how to test logout, stale data, forms, analytics, and page lifecycle.
npm Trusted Publishing and build attestations strengthen the software supply chain. They prove origin — not that code is safe or free from malicious logic.
A delete button rarely removes every copy. Learn how to audit databases, identity, files, processors, logs, and backups as one erasure workflow.
Multi-step redirects slow pages, distort measurement, and make migrations fragile. Learn how to audit old URLs, status codes, and final destinations.
Small click and tap targets cause mistakes, abandonment, and accessibility barriers. Learn how to audit navigation, forms, and overlays under WCAG 2.2.
Trusted Types reached broader browser availability in 2026. Learn how to find DOM XSS risks, introduce Report-Only, and avoid breaking production.
A myth-busting audit for Next.js, Vite, source maps, and build artifacts: how to detect and remediate credentials accidentally shipped to browsers.
Why green backup jobs do not prove recoverability — and how a realistic restore test validates data, configuration, and operational readiness.
How an outdated WordPress site became a modern Next.js website with clearer positioning, protected customer access, web dictation, CI and controlled VPS deployment.
Why a contact file does not fix vulnerabilities by itself — and which processes make sure reports are received, assessed, and resolved.
Why publicly reachable test environments can create indexing, privacy, and security problems — and how to protect them properly.
Unclear validation errors lose qualified leads and exclude users. Learn how to audit forms for understandable, accessible error recovery.
A technical red-flag audit for SPF, DKIM, DMARC, and the deliverability of forms, password resets, and transactional email.
Seven red flags reveal whether account recovery safely restores access or quietly creates support cost, abandonment, and security exposure.
Why domain ownership, renewal, registrar access, and transfer locks belong in every website operations review.
Why automated TLS renewal still needs external monitoring, escalation, and a practical recovery runbook.
How the Reporting API exposes CSP violations, deprecated features, and other silent browser failures—and why it complements rather than replaces monitoring.
Five common mistakes involving hero images, responsive delivery, and lazy loading that hurt mobile speed, stability, and conversions.
How incorrect cache rules, stale HTML, and deleted assets create inconsistent releases and silent conversion failures after deployments.
How a third-party script inventory, CSP, and Subresource Integrity expose security, privacy, and performance risks.
How noindex, robots.txt, incorrect canonicals, and broken sitemaps can make entire sections disappear after deployment.
Why uptime checks and error tracking miss silent conversion failures, and how synthetic checkout tests expose lost revenue earlier.
Why faster code generation without clear review rules accelerates technical debt, security gaps, and maintenance risk.
Why a polished relaunch without a proper redirect map loses rankings, links, and conversions—and how to catch the most important failures before launch.
Why npm audit alone is not a supply-chain strategy, and how lockfiles, dependency review, and a lightweight SBOM inventory improve incident response.
How a growing VPS moved from heavyweight app orchestration to CI artifacts, PM2, Doppler and Caddy without risking live services in a big-bang cutover.
A website is not properly handed over when the client only receives an admin login. This checklist covers ownership, access, documentation, and operational independence.
Why a .env file is not a vault and how secrets leak through builds, containers, logs, and frontend bundles.
A form can show a success message while still losing enquiries. These checks reveal delivery, UX, and monitoring gaps.
Why a green backup status does not prove that your website can actually recover after an outage.
A practical security check for Docker-based websites, SaaS projects, and agency deployments.
HTTP security headers such as CSP, HSTS, and Referrer-Policy are small configurations with large impact. Website teams should treat them as maintenance, not as a one-time scan.
Interaction to Next Paint shows whether a website really responds quickly after loading. Website teams should review real user flows, JavaScript work, and form interactions.
Since the European Accessibility Act and national implementation laws, shops, booking flows, and digital services should treat accessibility as an ongoing website check, not a one-time redesign task.
Interaction to Next Paint is part of Core Web Vitals and shows whether a website actually responds after loading. Website owners, agencies, and dev teams should include INP in maintenance, QA, and performance audits.
Contact forms, booking flows, and transactional emails need clean DNS and sender configuration. SPF, DKIM, and DMARC belong in every website check.
Cookie banners, Consent Mode, and tag managers must be checked together. The key question is not only whether a banner is visible, but whether scripts really wait for the right consent state.
WordPress plugins are useful, but every plugin is also a dependency, attack surface, and maintenance task. Website teams should review, reduce, and document plugins regularly.
The EU Data Act puts more attention on switching cloud and data processing services. Website teams should use this as a practical reason to check hosting, backups, exports, and vendor lock-in.
AI-generated text, images, and summaries need provenance, review, and technical documentation. For website teams, this is less a plugin problem and more a workflow problem.
AI-generated and AI-assisted website content needs provenance, review, and clean data hygiene. For website owners, this is a practical workflow topic.
Contact forms, reports, newsletters, and invoices quickly end up in spam when DNS and sending paths are messy. SPF, DKIM, DMARC, and one-click unsubscribe belong in website checks.
Many website risks are not caused by spectacular hacks, but by undocumented plugins, missing update routines, and unclear responsibility. Here is how Website-Pflichtencheck creates technical clarity.
Google keeps third-party cookies in Chrome manageable through user settings. For website owners, that is not an all-clear: tracking, consent, and third-party scripts still need regular checks.
Since June 2025, new accessibility requirements apply to certain digital products and services in the EU. Website teams should treat accessibility as part of maintenance, QA, and relaunch workflows.
Additional transparency requirements under the EU AI Act become relevant in August 2026. Here is what website owners, agencies, and software teams should prepare now.
The first reporting obligations under the EU Cyber Resilience Act apply from September 2026. Software teams should document vulnerabilities, updates, incident paths, and product responsibility now.
The next phases of the EU AI Act increase transparency and documentation expectations. Here's what website owners, agencies, and software teams should prepare today.
When a cookie banner becomes technically relevant, why the answer is not about the banner itself, and which mistakes small businesses often miss.
Maps, fonts, booking tools, tracking, and widgets are useful, but they become risky when nobody checks what they load.
Why website audit prices vary so much, what should actually be included, and when a small scan is enough.
The EU Data Act makes cloud switching and data portability more concrete. For websites, SaaS, and agency projects, exit strategy, data exports, and provider dependencies need documentation.
The EU rules for general-purpose AI models are now in motion. For small software teams, model choice, data flows, and responsibilities need practical documentation.
AI tools accelerate development, but they also introduce new risks to code security and data. What do companies need to consider for ISO 27001 and compliance?
AI tools speed up prototypes, but they also create hidden liabilities. When is AI-generated code worth it — and when does it become a risk?
Start with a technical check. If the findings are minor, you can stop there, hand the report to your existing team, or book targeted fixes later.
Technical audit and implementation, not legal advice. I check visible signals, integrations, and delivery issues; legal texts and binding legal assessments remain the work of lawyers or privacy consultants.