WordPress Security · 11 min read
Securing WordPress Uploads Beyond File Extensions
A defence-in-depth approach to WordPress media uploads covering validation, storage, execution controls, authorization, observability, and incident response.

FAHADBIN SHAKIR
Engineering Notes
Practical technical articles by Fahad Bin Shakir on web security, WordPress, infrastructure, performance, deployment, migrations, and production debugging. These authored resources are separate from the portfolio assistant and advertising surfaces.
WordPress Security · 11 min read
A defence-in-depth approach to WordPress media uploads covering validation, storage, execution controls, authorization, observability, and incident response.
Web Performance · 12 min read
How to move from field symptoms to reproducible fixes for LCP, INP, and CLS without optimizing a synthetic score in isolation.
Architecture · 12 min read
A practical model for cache keys, freshness, invalidation, private data, and observability across browsers, CDNs, reverse proxies, and applications.
DevOps · 12 min read
A release workflow for WordPress code, configuration, database changes, media, rollback, verification, and operational ownership.
Production Debugging · 11 min read
A layered method for diagnosing WordPress outbound request failures across application code, DNS, TLS, proxies, firewalls, and remote APIs.
Infrastructure Security · 12 min read
A maintainable baseline for identity, patching, network exposure, service isolation, secrets, logging, backups, and recovery on a small production server.
Web Security · 12 min read
How TLS, canonical redirects, HSTS, CSP, framing, MIME, referrer, and permissions policies work together without breaking the application.
DevOps · 13 min read
A staged migration method covering inventory, URL mapping, data integrity, DNS, redirects, observability, rollback, and search continuity.
Application Security · 11 min read
A contact-form architecture covering browser UX, server validation, abuse controls, origin checks, email delivery, privacy, logging, and truthful failure states.
Frontend Engineering · 12 min read
A route-focused workflow for measuring JavaScript cost, splitting bundles, controlling rendering, optimizing assets, and validating real user outcomes.
Technical SEO · 12 min read
A production-first audit method for crawl access, status codes, canonicals, rendering, sitemaps, structured data, internal links, and legacy URL cleanup.