Beginner guides.
No background assumed. What a database, a domain or an environment variable actually is, and how to get an app you built with AI online and keep it there.
276 posts · page 5 of 12
How to Transfer a Domain to Another Registrar (Without Breaking Your Site or Email)
A step-by-step domain transfer guide: what moves and what doesn't, the transfer lock and auth code, how long it takes, copying DNS records first so your site and email keep working, and the difference between transferring a domain and just changing nameservers.
Subdomain vs Subdirectory: blog.example.com or example.com/blog?
Should your blog, docs or app live on a subdomain (app.example.com) or a subdirectory (example.com/app)? The technical differences, what it means for SEO, cookies and hosting, and sensible defaults for a small product.
Stripe vs Paddle vs Lemon Squeezy: Which Should You Use to Get Paid?
The real difference between Stripe and Paddle or Lemon Squeezy is who handles sales tax: you, or a merchant of record. What a merchant of record is, fees compared, Stripe Managed Payments, and how to choose for a SaaS or digital product.
SQL Joins Explained Simply: INNER, LEFT, RIGHT, and FULL JOIN
A beginner's guide to SQL joins with one small example database: what a join does, INNER JOIN vs LEFT JOIN with real output, RIGHT and FULL joins, joining three tables, and the classic mistakes — duplicated rows and WHERE clauses that cancel a LEFT JOIN.
robots.txt and sitemap.xml Explained: A Beginner's Guide
Two small files that tell search engines (and AI crawlers) what to crawl and what exists on your site. How robots.txt and sitemap.xml work, examples, the robots.txt mistake that hides your whole site, why Disallow doesn't remove pages from Google, and how to generate both in Next.js.
React App Shows a Blank Page After Deploying? Here's How to Fix It
Works locally, white screen in production. The usual causes of a blank page after deploying a React or Vite app — wrong base path, missing environment variables, a JavaScript crash, routing, caching — and how to diagnose each in two minutes with DevTools.
Python vs JavaScript: Which Should a Beginner Choose?
Python and JavaScript are the two most popular first languages. How they differ in what they're for, how they look, speed, jobs and AI support — and a simple way to choose based on what you actually want to build.
Python Virtual Environments Explained: venv, pip, and uv for Beginners
Why every Python project needs its own virtual environment, how to create and activate one with venv on Windows, Mac and Linux, requirements.txt, the "externally-managed-environment" error, and why many people now use uv instead.
Primary Key vs Foreign Key: What's the Difference?
Primary keys identify each row; foreign keys link rows between tables. What each one does, examples in SQL, composite and unique keys, what ON DELETE CASCADE really means, and why AI-generated schemas sometimes skip foreign keys — and why you shouldn't.
PostgreSQL vs MySQL: Which Database Should You Choose?
Postgres and MySQL are the two most popular open-source databases. How they differ on features, JSON, extensions, performance, hosting and ecosystem — and why most new apps (and AI app builders) default to Postgres.
Postgres Connection Strings Explained: Format, Examples, and Common Errors
What every part of a PostgreSQL connection string (DATABASE_URL) means, how to write one, special characters in passwords, sslmode options, pooled vs direct connections (including Supabase's ports), and how to fix the errors people hit most.
The OWASP Top 10 (2025) Explained for Beginners and App Builders
The OWASP Top 10 is the most widely used list of web application security risks. All ten 2025 categories in plain English — from broken access control to supply chain failures — with what each looks like in an AI-built app and how to prevent it.
How to Optimize Images for the Web: Formats, Sizes, and Lazy Loading
Images are usually the heaviest part of a page. Which format to use (WebP vs AVIF vs JPEG vs PNG vs SVG), how big to make them, responsive images with srcset, lazy loading done right, and the one image you should never lazy-load.
npm vs pnpm vs Yarn vs Bun: Which Package Manager Should You Use?
Four JavaScript package managers install the same packages in different ways. How npm, pnpm, Yarn and Bun differ on speed, disk space, lockfiles and safety, which lockfile belongs to which, and why mixing them breaks things.
npm ERESOLVE "Unable to Resolve Dependency Tree": What It Means and How to Fix It
npm ERR! code ERESOLVE means two packages disagree about which version of a third they need. How to read the error, what peer dependencies are, the safe fixes in order, and when --legacy-peer-deps or --force are (and aren't) acceptable.
npm audit Explained: What the Warnings Mean and What to Actually Do
"found 14 vulnerabilities (3 moderate, 2 high)" — should you panic? How npm audit works, what the severity levels mean, why npm audit fix sometimes does nothing, why --force is risky, and how to tell real risks from noise.
Node.js vs Bun vs Deno: Which JavaScript Runtime in 2026?
Three runtimes run JavaScript outside the browser. How Node.js, Bun and Deno differ on speed, compatibility, TypeScript support, security and built-in tools — and why most apps should still start on Node.js.
Next.js Hydration Errors: What They Mean and How to Fix Them
"Hydration failed because the server rendered HTML didn't match the client" — what hydration is, the usual culprits (dates, random values, window, browser extensions, invalid HTML, theme switchers), and the correct fix for each.
Mixed Content Errors: Why Your HTTPS Site Loads Things Over HTTP (and How to Fix It)
"Mixed Content: The page was loaded over HTTPS, but requested an insecure resource." What mixed content is, why browsers block it, how to find every http:// URL, and the fixes — including apps behind a proxy that generate http links.
Magic Link Login: How Passwordless Email Sign-In Works (and Its Pitfalls)
Magic links let people log in by clicking a link in their email — no password. How they work, when they're a good fit, the security details that matter (expiry, single use, token hashing), and the real-world problems: spam filters, email scanners and phones vs laptops.
Linux File Permissions Explained: chmod 755, 644, and "Permission Denied"
What rwxr-xr-x means, how chmod numbers like 755, 644 and 600 work, chmod +x for scripts, chown, the correct permissions for SSH keys, and why chmod 777 is never the right fix for "Permission denied".
"JavaScript Heap Out of Memory": Why It Happens and How to Fix It
FATAL ERROR: Reached heap limit — JavaScript heap out of memory. What Node's heap limit is, why builds and servers hit it, how to raise it safely with --max-old-space-size, when the real problem is a memory leak, and the difference from exit code 137.
What Is IDOR? The Security Bug Where Users Can See Each Other's Data
IDOR (insecure direct object reference) is when changing an ID in a URL shows you someone else's data. How it happens, why it's the most common serious bug in AI-built apps, how to test for it in five minutes, and the one-line habit that prevents it.
Horizontal vs Vertical Scaling: How Apps Handle More Users
Vertical scaling means a bigger server; horizontal scaling means more servers. How each works, what load balancers do, why databases are the hard part, what has to change in your app to scale out, and why most small apps should scale up first.