Skip to content
← All posts

Tagged

PHP

13 posts

Engineering3 min read

The N+1 you cannot see

Everyone knows to eager load. The queries that actually take sites down are the ones hiding in an accessor, a Blade partial, or a policy — and there is a one-line switch that finds all of them.

Engineering3 min read

Queues are not optional

If your request handler calls somebody else’s API, you have already built a distributed system. The queue is how you stop their bad day from becoming your bad day.

Engineering3 min read

PHP got good and nobody told you

If your mental image of PHP is from 2014, it is wrong in ways that would change your architecture. Here is what actually landed, and which parts change how you write code.

WordPress3 min read

WP_Query is fast until it is not

WordPress will happily let you write a query that scans a million meta rows. Here is which arguments are expensive, why, and what to do instead.

From The Wire

Adminer patches an RCE hiding behind a UTF-8 byte-order mark

A regex filter meant to block dangerous SQLite commands in Adminer missed statements prefixed with a UTF-8 BOM, letting an authenticated user write PHP straight to a web-accessible directory. Fixed in 6.1.1.

via GitHub Security Advisories (vrana/adminer)