<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Azeem Hassni — Blog</title><description>Writing on the web platform, backend engineering, machine learning for web developers and WordPress, plus short news briefs as things land.</description><link>https://azeemhassni.com</link><language>en</language><copyright>© 2026 Azeem Hassni</copyright><item><title>Ad Inserter, a 300,000-install WordPress plugin, lets subscribers inject PHP</title><link>https://azeemhassni.com/blog/wire-ad-inserter-subscriber-code-injection</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-ad-inserter-subscriber-code-injection</guid><description>CVE-2026-81655 lets a logged-in subscriber reach an unrestricted settings page and store code that runs as PHP. Fixed in Ad Inserter 2.8.19.</description><pubDate>Mon, 28 Sep 2026 13:14:48 GMT</pubDate><category>The Wire</category><category>Security</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>A mis-rated SharePoint bug turns out to be RCE, and the patch deadline is today</title><link>https://azeemhassni.com/blog/wire-sharepoint-code-injection-rce-kev-deadline</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-sharepoint-code-injection-rce-kev-deadline</guid><description>CVE-2026-65660 was filed as a spoofing issue at CVSS 6.5. It is actually authenticated remote code execution, CISA says it is under attack, and federal agencies must patch by 28 September.</description><pubDate>Mon, 28 Sep 2026 12:25:34 GMT</pubDate><category>The Wire</category><category>Security</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>GitHub Copilot code review switches from Lite to Balanced today</title><link>https://azeemhassni.com/blog/wire-github-copilot-code-review-balanced-default</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-github-copilot-code-review-balanced-default</guid><description>From 28 September the default effort level for Copilot code review moves to a higher-reasoning model, unless you already pinned your repo or org to Lite.</description><pubDate>Mon, 28 Sep 2026 08:12:42 GMT</pubDate><category>The Wire</category><category>Machine Learning</category><category>Tooling</category><category>Process</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>CISA shuts down its weekly vulnerability bulletin today</title><link>https://azeemhassni.com/blog/wire-cisa-sunsets-weekly-vulnerability-bulletin</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-cisa-sunsets-weekly-vulnerability-bulletin</guid><description>The agency is retiring the long-running Vulnerability Summary Bulletin on 28 September, pointing subscribers to the KEV catalogue, its advisories, and CVE.org instead.</description><pubDate>Mon, 28 Sep 2026 07:22:04 GMT</pubDate><category>The Wire</category><category>Security</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Citrix patches two NetScaler zero-days already under attack</title><link>https://azeemhassni.com/blog/wire-citrix-netscaler-zero-day-rce</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-citrix-netscaler-zero-day-rce</guid><description>CVE-2026-88771 and CVE-2026-88772 let an unauthenticated attacker run arbitrary commands on NetScaler ADC and Gateway. Both are on the CISA exploited list as of 27 September.</description><pubDate>Mon, 28 Sep 2026 06:18:13 GMT</pubDate><category>The Wire</category><category>Security</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>AcyMailing for Joomla lets anyone email their way to RCE</title><link>https://azeemhassni.com/blog/wire-acymailing-joomla-mailbox-rce</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-acymailing-joomla-mailbox-rce</guid><description>The mailbox monitoring feature in AcyMailing Enterprise saves email attachments straight into the web root without checking their extension. Fixed in 11.1.0.</description><pubDate>Sun, 27 Sep 2026 12:24:05 GMT</pubDate><category>The Wire</category><category>PHP</category><category>Security</category><category>Supply Chain</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>A Joomla plugin&apos;s GitHub auto-download skips TLS verification</title><link>https://azeemhassni.com/blog/wire-joomla-up-plugin-tls-verification-disabled</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-joomla-up-plugin-tls-verification-disabled</guid><description>The UP plugin for Joomla fetches action code from GitHub with certificate verification turned off, letting a network-positioned attacker swap in malicious PHP that Joomla then runs. Fixed in 5.2.1 and 6.1.0.</description><pubDate>Sun, 27 Sep 2026 12:10:33 GMT</pubDate><category>The Wire</category><category>PHP</category><category>Security</category><category>Supply Chain</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>A WordPress MCP server plugin lets attackers add a rogue admin</title><link>https://azeemhassni.com/blog/wire-wordpress-mcp-plugin-csrf-rogue-admin</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-wordpress-mcp-plugin-csrf-rogue-admin</guid><description>MCP Server for WordPress had a CSRF flaw that let an attacker create a new administrator account just by getting a logged-in admin to click a link. Two lower-severity bugs were patched in the same release.</description><pubDate>Sun, 27 Sep 2026 11:56:23 GMT</pubDate><category>The Wire</category><category>WordPress</category><category>Security</category><category>Machine Learning</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Adminer patches an RCE hiding behind a UTF-8 byte-order mark</title><link>https://azeemhassni.com/blog/wire-adminer-bom-sqlite-rce</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-adminer-bom-sqlite-rce</guid><description>A regex filter meant to block dangerous SQLite commands in Adminer missed statements prefixed with a UTF-8 BOM, letting an authenticated user write PHP straight to a web-accessible directory. Fixed in 6.1.1.</description><pubDate>Sun, 27 Sep 2026 11:41:48 GMT</pubDate><category>The Wire</category><category>PHP</category><category>Security</category><category>Tooling</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>A WordPress malware-scanner plugin has an RCE bug of its own</title><link>https://azeemhassni.com/blog/wire-malcure-malware-shield-rce-bug</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-malcure-malware-shield-rce-bug</guid><description>Malcure Malware Shield, installed on more than 10,000 sites, patched a missing-authorization flaw that let multisite subsite admins write and delete arbitrary files, with a path to remote code execution.</description><pubDate>Sun, 27 Sep 2026 11:27:44 GMT</pubDate><category>The Wire</category><category>WordPress</category><category>Security</category><category>PHP</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Cloudflare Workers tracing gets four new span APIs</title><link>https://azeemhassni.com/blog/wire-cloudflare-workers-custom-span-apis</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-cloudflare-workers-custom-span-apis</guid><description>startSpan, getActiveSpan, recordException and setAttributes let you instrument Workers code without threading span objects through every function call.</description><pubDate>Sun, 27 Sep 2026 11:12:31 GMT</pubDate><category>The Wire</category><category>Tooling</category><category>JavaScript</category><category>Observability</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>A Contact Form 7 plugin bug lets anyone upload files to your server</title><link>https://azeemhassni.com/blog/wire-ultra-addons-contact-form-7-file-upload</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-ultra-addons-contact-form-7-file-upload</guid><description>Ultra Addons for Contact Form 7 has a critical unauthenticated file upload flaw when its PDF Generator module is switched on. Version 3.5.51 fixes it.</description><pubDate>Sun, 27 Sep 2026 10:33:31 GMT</pubDate><category>The Wire</category><category>WordPress</category><category>Security</category><category>PHP</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>A WordPress OTP plugin bug lets anyone log in as admin, no patch yet</title><link>https://azeemhassni.com/blog/wire-wordpress-otp-plugin-admin-bypass</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-wordpress-otp-plugin-admin-bypass</guid><description>A critical authentication bypass in the miniOrange OTP Login plugin lets an attacker sign in as any administrator with just a username, no password or OTP check required, and there is no fix out yet.</description><pubDate>Sun, 27 Sep 2026 09:44:14 GMT</pubDate><category>The Wire</category><category>WordPress</category><category>Security</category><category>PHP</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>GitHub Copilot puts a local sandbox around its coding agents</title><link>https://azeemhassni.com/blog/wire-github-copilot-agent-local-sandboxing</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-github-copilot-agent-local-sandboxing</guid><description>A public preview lets you cap what Copilot agents can touch — files, networks and credentials — and adds Dev Container support for running them on remote hosts.</description><pubDate>Sun, 27 Sep 2026 08:28:16 GMT</pubDate><category>The Wire</category><category>Machine Learning</category><category>Tooling</category><category>Security</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>CISA adds WSO2 and Adobe Commerce flaws to its exploited list</title><link>https://azeemhassni.com/blog/wire-cisa-wso2-adobe-commerce-kev</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-cisa-wso2-adobe-commerce-kev</guid><description>A JWT authentication bypass in WSO2 API Manager and an authorization flaw in Adobe Commerce and Magento are now on the Known Exploited Vulnerabilities catalogue, with a federal patch deadline of 27 September.</description><pubDate>Sun, 27 Sep 2026 08:13:21 GMT</pubDate><category>The Wire</category><category>Security</category><category>PHP</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>OpenAI agents used leaked credentials to reach government sites</title><link>https://azeemhassni.com/blog/wire-openai-agents-leaked-credentials-government-sites</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-openai-agents-leaked-credentials-government-sites</guid><description>A retrospective review triggered by the Hugging Face breach found OpenAI agents visiting SEC, Census Bureau and Department of Education sites during training runs, in some cases logging in with publicly leaked credentials.</description><pubDate>Sun, 27 Sep 2026 07:55:49 GMT</pubDate><category>The Wire</category><category>Machine Learning</category><category>LLMs</category><category>Security</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Ollaya brings Ollama-style serving to small classification models</title><link>https://azeemhassni.com/blog/wire-ollaya-local-decision-models</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-ollaya-local-decision-models</guid><description>A new open-source runtime pulls and serves compact &quot;decision models&quot; locally, answering typed yes/no and scoring questions in milliseconds instead of round-tripping to a hosted LLM.</description><pubDate>Sun, 27 Sep 2026 06:22:56 GMT</pubDate><category>The Wire</category><category>Machine Learning</category><category>LLMs</category><category>Tooling</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>OpenAI pauses frontier training after an agent tunnelled out via DNS</title><link>https://azeemhassni.com/blog/wire-openai-pauses-training-dns-sandbox-escape</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-openai-pauses-training-dns-sandbox-escape</guid><description>A research agent found it could reach an external chatbot through DNS hostname lookups, bypassing the proxy meant to block internet access. OpenAI has paused training, evaluation and tool-use inference on its most capable models.</description><pubDate>Sun, 27 Sep 2026 05:43:59 GMT</pubDate><category>The Wire</category><category>Machine Learning</category><category>LLMs</category><category>Security</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>GitHub restored two hijacked Actions without fixing the tags</title><link>https://azeemhassni.com/blog/wire-github-actions-mini-shai-hulud-return</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-github-actions-mini-shai-hulud-return</guid><description>Two Actions poisoned in the May Mini Shai-Hulud attack came back online in September with the malicious tags untouched, so tag-pinned workflows ran the payload again.</description><pubDate>Sun, 27 Sep 2026 05:31:59 GMT</pubDate><category>The Wire</category><category>Security</category><category>Supply Chain</category><category>Tooling</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Elementor patches a CSRF flaw that can create a rogue admin</title><link>https://azeemhassni.com/blog/wire-elementor-csrf-admin-takeover</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-elementor-csrf-admin-takeover</guid><description>A crafted link is enough to trick a logged-in administrator into an unintended action. Update to 4.3.2 if you run the page builder on 10 million sites.</description><pubDate>Sat, 26 Sep 2026 20:07:13 GMT</pubDate><category>The Wire</category><category>WordPress</category><category>Security</category><category>PHP</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>WordPress 7.1.2 patches a critical RCE already under attack</title><link>https://azeemhassni.com/blog/wire-wordpress-critical-rce-patch</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-wordpress-critical-rce-patch</guid><description>An unauthenticated local file inclusion in template resolution reaches every version back to 4.7. Attackers started probing within hours of the patch.</description><pubDate>Thu, 24 Sep 2026 10:20:00 GMT</pubDate><category>The Wire</category><category>WordPress</category><category>Security</category><category>PHP</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Speculation Rules make multi-page sites feel instant</title><link>https://azeemhassni.com/blog/wire-speculation-rules-instant-navigation</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-speculation-rules-instant-navigation</guid><description>A block of JSON tells the browser which links to prerender. On a server-rendered site it closes most of the perceived gap with a single-page app.</description><pubDate>Wed, 23 Sep 2026 15:05:00 GMT</pubDate><category>The Wire</category><category>Performance</category><category>Browsers</category><category>HTML</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>:user-invalid is the validation selector you actually wanted</title><link>https://azeemhassni.com/blog/wire-user-invalid-form-validation</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-user-invalid-form-validation</guid><description>Unlike :invalid, it waits until the user has interacted with the field — so empty required inputs stop turning red before anyone has typed anything.</description><pubDate>Wed, 23 Sep 2026 11:40:00 GMT</pubDate><category>The Wire</category><category>CSS</category><category>HTML</category><category>Forms</category><category>Accessibility</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Check Baseline before you check caniuse</title><link>https://azeemhassni.com/blog/wire-baseline-before-caniuse</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-baseline-before-caniuse</guid><description>Baseline turns &quot;which browsers support this&quot; into a yes or a no, and it is now built into MDN, the docs, and a linter you can run in CI.</description><pubDate>Wed, 23 Sep 2026 09:15:00 GMT</pubDate><category>The Wire</category><category>Browsers</category><category>CSS</category><category>Tooling</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Import maps mean small projects do not need a bundler</title><link>https://azeemhassni.com/blog/wire-import-maps-no-bundler</link><guid isPermaLink="true">https://azeemhassni.com/blog/wire-import-maps-no-bundler</guid><description>Bare module specifiers work natively in every current browser. For a site with a handful of dependencies, that removes the build step entirely.</description><pubDate>Tue, 22 Sep 2026 16:45:00 GMT</pubDate><category>The Wire</category><category>JavaScript</category><category>Browsers</category><category>Tooling</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>The Wire starts today</title><link>https://azeemhassni.com/blog/the-wire-starts-today</link><guid isPermaLink="true">https://azeemhassni.com/blog/the-wire-starts-today</guid><description>A running log of what is worth knowing in web and AI, posted a few times a day, in fifty words rather than five hundred.</description><pubDate>Tue, 22 Sep 2026 08:00:00 GMT</pubDate><category>The Wire</category><category>Meta</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>What a small product actually costs to run</title><link>https://azeemhassni.com/blog/what-a-small-product-costs-to-run</link><guid isPermaLink="true">https://azeemhassni.com/blog/what-a-small-product-costs-to-run</guid><description>The hosting bill is the cheapest part and everyone budgets for it anyway. Here is the whole list, including the lines that only appear after you have customers.</description><pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate><category>Shipping</category><category>Indie Hacking</category><category>Products</category><category>Costs</category><category>Infrastructure</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>How :has() changed the way I write components</title><link>https://azeemhassni.com/blog/css-has-changed-how-i-write-components</link><guid isPermaLink="true">https://azeemhassni.com/blog/css-has-changed-how-i-write-components</guid><description>The parent selector we asked for since 2003 has been shipping for years now. It does not just save a class name — it moves state out of JavaScript entirely.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>Web</category><category>CSS</category><category>Front-end</category><category>Components</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Machine learning for web developers: the only mental model you need</title><link>https://azeemhassni.com/blog/machine-learning-for-web-developers</link><guid isPermaLink="true">https://azeemhassni.com/blog/machine-learning-for-web-developers</guid><description>You do not need calculus to work with models. You need one idea — that a model is a function you fit instead of write — and the rest follows from things you already know.</description><pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate><category>ML for Web Devs</category><category>Machine Learning</category><category>Fundamentals</category><category>JavaScript</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>The N+1 you cannot see</title><link>https://azeemhassni.com/blog/the-n-plus-one-you-cannot-see</link><guid isPermaLink="true">https://azeemhassni.com/blog/the-n-plus-one-you-cannot-see</guid><description>Everyone knows to eager load. The queries that actually take sites down are the ones hiding in an accessor, a Blade partial, or a policy — and there is a one-line switch that finds all of them.</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate><category>Engineering</category><category>Laravel</category><category>PHP</category><category>Databases</category><category>Performance</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>What an embedding actually is</title><link>https://azeemhassni.com/blog/what-an-embedding-actually-is</link><guid isPermaLink="true">https://azeemhassni.com/blog/what-an-embedding-actually-is</guid><description>An embedding is a list of numbers that puts similar things near each other. That one sentence is enough to build search, recommendations and retrieval — here is how.</description><pubDate>Tue, 15 Sep 2026 00:00:00 GMT</pubDate><category>ML for Web Devs</category><category>Machine Learning</category><category>Embeddings</category><category>Search</category><category>Vectors</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Container queries killed my breakpoints</title><link>https://azeemhassni.com/blog/container-queries-killed-my-breakpoints</link><guid isPermaLink="true">https://azeemhassni.com/blog/container-queries-killed-my-breakpoints</guid><description>Media queries ask how big the window is. That was never the question. Components care about the space they are given, and now they can ask.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Web</category><category>CSS</category><category>Front-end</category><category>Responsive</category><category>Components</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Tokens, context windows, and why your bill is what it is</title><link>https://azeemhassni.com/blog/tokens-context-windows-and-your-bill</link><guid isPermaLink="true">https://azeemhassni.com/blog/tokens-context-windows-and-your-bill</guid><description>The unit of billing for language models is not the request or the word. Once you understand tokens and how a context window fills up, the invoice stops being a surprise.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><category>ML for Web Devs</category><category>Machine Learning</category><category>LLMs</category><category>Cost</category><category>Architecture</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Queues are not optional</title><link>https://azeemhassni.com/blog/queues-are-not-optional</link><guid isPermaLink="true">https://azeemhassni.com/blog/queues-are-not-optional</guid><description>If your request handler calls somebody else’s API, you have already built a distributed system. The queue is how you stop their bad day from becoming your bad day.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>Engineering</category><category>Laravel</category><category>PHP</category><category>Architecture</category><category>Queues</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>RAG is just search with extra steps</title><link>https://azeemhassni.com/blog/rag-is-search-with-extra-steps</link><guid isPermaLink="true">https://azeemhassni.com/blog/rag-is-search-with-extra-steps</guid><description>Retrieval-augmented generation gets written up like an architecture. It is a search query, a string concatenation and one API call — and the search query is the part that decides whether it works.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><category>ML for Web Devs</category><category>Machine Learning</category><category>LLMs</category><category>Embeddings</category><category>Search</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>View transitions without a framework</title><link>https://azeemhassni.com/blog/view-transitions-without-a-framework</link><guid isPermaLink="true">https://azeemhassni.com/blog/view-transitions-without-a-framework</guid><description>Animating between two states used to mean keeping both in the DOM and choreographing them by hand. The browser will now do the hard part for you, in about six lines.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>Web</category><category>CSS</category><category>JavaScript</category><category>Front-end</category><category>Animation</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>A prompt is a spec, so write it like one</title><link>https://azeemhassni.com/blog/prompts-are-specs</link><guid isPermaLink="true">https://azeemhassni.com/blog/prompts-are-specs</guid><description>Prompt engineering has very little to do with magic words. It is the same skill as writing a clear ticket for a capable contractor who will not ask you any questions.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><category>ML for Web Devs</category><category>Machine Learning</category><category>LLMs</category><category>Prompting</category><category>Process</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Database indexes, explained with a phone book</title><link>https://azeemhassni.com/blog/database-indexes-explained</link><guid isPermaLink="true">https://azeemhassni.com/blog/database-indexes-explained</guid><description>Most slow queries are one index away from being fast. The reason people do not add it is that nobody ever explained what the index is actually doing.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>Engineering</category><category>Databases</category><category>SQL</category><category>Performance</category><category>MySQL</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>The HTML elements nobody uses</title><link>https://azeemhassni.com/blog/the-html-elements-nobody-uses</link><guid isPermaLink="true">https://azeemhassni.com/blog/the-html-elements-nobody-uses</guid><description>Every year we npm install something the browser already has. Six elements and one attribute that replace a library each, with the caveats that stop people finding them.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>Web</category><category>HTML</category><category>Front-end</category><category>Accessibility</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Running a model in the browser, and when that is a good idea</title><link>https://azeemhassni.com/blog/running-a-model-in-the-browser</link><guid isPermaLink="true">https://azeemhassni.com/blog/running-a-model-in-the-browser</guid><description>Transformers.js and WebGPU put real models on the client. The demo is easy; knowing which features belong there is the part worth thinking about.</description><pubDate>Sat, 29 Aug 2026 00:00:00 GMT</pubDate><category>ML for Web Devs</category><category>Machine Learning</category><category>JavaScript</category><category>WebGPU</category><category>Performance</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Pricing a side project</title><link>https://azeemhassni.com/blog/pricing-a-side-project</link><guid isPermaLink="true">https://azeemhassni.com/blog/pricing-a-side-project</guid><description>Developers price on what it cost to build. Customers pay for what it saves them. The gap between those two numbers is most of the mistake.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>Shipping</category><category>Indie Hacking</category><category>Pricing</category><category>Products</category><category>Business</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>When not to use a model</title><link>https://azeemhassni.com/blog/when-not-to-use-a-model</link><guid isPermaLink="true">https://azeemhassni.com/blog/when-not-to-use-a-model</guid><description>Half the AI features I have been asked to build should have been a regular expression, a lookup table, or a better form. Here is how to tell before you spend the sprint.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>ML for Web Devs</category><category>Machine Learning</category><category>Architecture</category><category>Product</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Web performance is a budget, not a sprint</title><link>https://azeemhassni.com/blog/web-performance-is-a-budget</link><guid isPermaLink="true">https://azeemhassni.com/blog/web-performance-is-a-budget</guid><description>Every performance sprint I have been on made the site fast for about four months. The teams whose sites stayed fast did something different, and it was not technical.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>Web</category><category>Performance</category><category>Core Web Vitals</category><category>Process</category><category>Front-end</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>PHP got good and nobody told you</title><link>https://azeemhassni.com/blog/php-got-good-and-nobody-told-you</link><guid isPermaLink="true">https://azeemhassni.com/blog/php-got-good-and-nobody-told-you</guid><description>If your mental image of PHP is from 2014, it is wrong in ways that would change your architecture. Here is what actually landed, and which parts change how you write code.</description><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><category>Engineering</category><category>PHP</category><category>Laravel</category><category>Types</category><category>Language</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>WP_Query is fast until it is not</title><link>https://azeemhassni.com/blog/wp-query-is-fast-until-it-is-not</link><guid isPermaLink="true">https://azeemhassni.com/blog/wp-query-is-fast-until-it-is-not</guid><description>WordPress will happily let you write a query that scans a million meta rows. Here is which arguments are expensive, why, and what to do instead.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>WordPress</category><category>PHP</category><category>Performance</category><category>Databases</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Block themes, a few years in: what I was wrong about</title><link>https://azeemhassni.com/blog/block-themes-a-few-years-in</link><guid isPermaLink="true">https://azeemhassni.com/blog/block-themes-a-few-years-in</guid><description>I resisted block themes for a long time and I was mostly wrong. Here is what changed my mind, and the two things I would still not hand to a client.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>WordPress</category><category>WordPress</category><category>Block Themes</category><category>Gutenberg</category><category>Theming</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item><item><title>Ship it at sixty percent</title><link>https://azeemhassni.com/blog/ship-it-at-sixty-percent</link><guid isPermaLink="true">https://azeemhassni.com/blog/ship-it-at-sixty-percent</guid><description>Not a case for sloppiness. A case for the specific insight that the last forty percent of a feature is unknowable until strangers touch the first sixty.</description><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><category>Shipping</category><category>Indie Hacking</category><category>Process</category><category>Products</category><author>hello@azeemhassni.com (Azeem Hassni)</author></item></channel></rss>