Jennifer J Simpson: it’s about the work

Jennifer J Simpson's website

Jennifer Simpson paints mostly with oil and cold wax and exhibits in the lively arts scene of Ottawa’s west end. And she needed a website.

She’s fairly technical but mostly wants to be painting, not keyboarding.

So this was a project where I provided more direction than one where there’s a creative brief, a design direction and a branding kit.

I enjoyed putting this site together because her work does most of the design talking. Which, I think is as it should be.

WooCommerce is just too much

Hippos by Timon Cornelissen

There needs to be a lightweight alternative to WooCommerce for people, small organizations and businesses that want to run their own stores.

I’m not talking about its complexity. I’m not talking about the whacky ecosystem of plugins, extensions, partial solutions and subscriptions required to make a complete online store.

I’m talking about the just plain computational overhead of the thing.

Of late I’ve had a couple of clients with hitherto simple cash register setups that they suddenly outgrew and replaced with WooCommerce.

Then all of a sudden their previously snappy websites were throwing up 503 errors, timeouts and treating their visitors to an endless vista of spinner icons.

I suppose it shouldn’t really come as a surprise — WooCommerce is presented as a full-fledged e-commerce system — but to a site admin down in the trenches it’s just another plugin and heck we add those all the time to scratch this or that itch.

How would this be different?

Well, it is. And if your site is on some cheap shared host, WooCommerce will bring it to its knees. And if — to milk your cheap shared host for all its worth — you’ve done as much caching, CDN-ing and overclocking of various sorts to keep your site zippy, be prepared to panic. Because you can’t cache shopping carts and checkout pages.

Some of it might be its connection to WordPress.com. That sort of interconnectivity always adds some latency. Maybe it needs this, maybe it doesn’t. It makes other connections too: address lookups, Google Fonts etc etc. None of these on their own are fatal.

But the developers do seem to rely on at least VPS-level hosting to hide the fact that WooCommerce is a hippo.

So if you think you really need it, think again. And ask yourself if there isn’t some other way to make your current set up go a little further.

Check your old code: if it’s old enough even the most innocuous cruft can be a problem

Photo by Markus Spiske: https://www.pexels.com/photo/coding-script-965345/

Over on my personal site I keep write-ups and photo galleries of all the canoe trips I’ve done. It helps me (and possibly others) plan for the next one and avoid past mistakes etc etc.

Time was when I also used it to teach myself things. Like CSS and PHP and the Javascript DOM. I figured these reports would be evergreen and wouldn’t need much maintenance as they were more or less static. Nope. I’ve updated them over the years, changing DOCTYPEs, getting rid of old MSIE/Netscape CSS work-arounds (yes, they are that old), but I didn’t anticipate what happened last week.

I got an email from a security researcher the other day telling me that one of the PHP scripts on one of these old trip reports could be used to inject malicious code into the browser window.

I do get a lot of unsolicited emails about all sorts of problems with my sites — my domain’s expiring, I’m not ranking on the first page of Google, I have million dollars coming to me from an octogenerian in Nigeria who has throat cancer etc etc.

But this one actually was legit. He was building sweat equity as part of Open Bug Bounty and had found something on my site amongst these sometimes 20 year old, hand-coded trip reports.

It was the sort of thing that would allow a remote attacker to enlist my site in building phishing links or credential/info stealing pages. So there was no leaving it around.

The fix was relatively simple. And now that I’ve deployed it across all those reports, I think they are safe again.

Thanks to Security Researcher Imtiaz Ahmed for being clear and polite in pointing out my lassitude. Here’s his OpenBugBounty profile.

The Pearson Centre: rethinking an overthink

The Pearson Centre is a progressive think tank whose founders had a grand vision for the organization’s areas of endeavour. And they were going to be busy. And they built a site with containers, metadata and gismos for all that content. It was going to be a newspaper. A symposium. An investigation. A campus. A town hall.

Years on, the producers realized that what it really needed to be was a website. That captured what the institute was actually doing. And that helped them get that work done.

So the institute’s leadership contracted me to audit a decade of content, pull together a set of plugins and apps that offered a website that helped get the centre’s business done. A contact database. A cash register. Bulk email. Webinars.

And with the help of Christina Muxlow, who produced an excellent logo for the centre I also redesigned the site to put their current efforts front and centre with a fresh look.