WordPress Maintenance

robots.txt and sitemap.xml Basics — What They Tell Crawlers, and Which One Wins

When a search engine crawler visits a site, it usually doesn’t jump straight to your articles. It first checks robots.txt to learn where it may go, and it reads sitemap.xml to learn what pages exist. Both files are “notes for crawlers,” so they get confused a lot — but they say different things and matter at different moments. The last few posts (hreflang, JSON-LD, OGP) were about how a page should be interpreted. This one is about the step before that: how a crawler gets to the page at all. Note: crawlers are also called bots or spiders. Googlebot and Bingbot are the best-known examples. Each identifies itself with a …

Read more
Engineering Notes

gzip/Brotli Compression Basics — How HTTP Responses Get Smaller, and Why the Server Gets to Choose

Fast-loading websites often share a trick you never see: the server compresses HTML, CSS, and JavaScript right before sending them, using a format like gzip or Brotli, and the browser decompresses them before rendering the page. None of this exchange shows up on screen, but it has a large effect on how much data actually crosses the wire. Following the last two posts on OGP and HTTP cache headers — both things that live in HTTP response headers rather than <head> — this one covers how compression works. Note: gzip has been around since 1992 and is supported almost everywhere, by both browsers and servers. Brotli is newer, published by …

Read more
WordPress Maintenance

OGP (Open Graph Protocol) Basics — How Social Media Decides What a Shared Link Looks Like

Paste a URL into X (formerly Twitter) or Facebook, and a card appears: a title, a description, and an image, neatly assembled. That is not automatic guesswork — the page itself publishes metadata called OGP (Open Graph Protocol), and the platform’s crawler reads it to build the card. Following the previous post on JSON-LD, this one covers OGP, another piece of metadata that lives in <head>, using this blog’s implementation (wpmm.jp/blog and en.wpmm.jp/blog) as the example. Note: OGP was proposed by Facebook in 2010. The name reflects the idea of treating a page as part of a graph — a network of connected nodes. Today it has become a de …

Read more
WordPress Maintenance

JSON-LD Structured Data Basics — How Rich Results Get Generated

You have probably seen search results that show more than a blue link and a snippet: a publish date, an author, or a breadcrumb trail of the site’s hierarchy. These are called rich results, and the raw material behind them is structured data embedded in the page. This post covers JSON-LD, today’s most common format: what it describes and how to verify it, using the implementation on this blog (wpmm.jp/blog and en.wpmm.jp/blog) as the example. Note: structured data is an annotation that presents a page’s meaning in a machine-readable form. Writing it does not guarantee any particular display. It is a hint that helps a search engine understand the content. …

Read more
WordPress Maintenance

hreflang Basics — How Search Engines Recognize a JP/EN Article Pair

If you run a site in both Japanese and English, a few questions come up quickly. Will a search engine treat the two versions of the same article as unrelated pages? Will someone searching in Japanese be shown the English page? The hreflang annotation, placed in the HTML <head>, exists to address exactly this. This post covers what hreflang says, how it needs to be written, and how it works in practice on this blog (wpmm.jp/blog and en.wpmm.jp/blog). Note: hreflang tells search engines that a page has counterparts in other languages or regions. It does not translate anything. It only declares which URLs are language variants of the same content. …

Read more
WordPress Maintenance

The Basics of esc_html() and esc_attr() — WordPress’s “Escape on Output” Approach to XSS

Read enough WordPress theme or plugin code and you’ll notice that values are almost never echoed directly. Instead you see echo esc_html( $title ); or <a href=”<?php echo esc_url( $url ); ?>”>. These are WordPress’s escaping functions, the core tools for preventing XSS (cross-site scripting). This post looks at why there are several of them and, more importantly, when escaping should happen. Note: XSS is a broad term for problems where a value shown on a page contains text that the browser interprets as HTML or script rather than as plain text. The root cause is a blurred boundary between “a value” and “the structure of the HTML.” It’s the …

Read more
WordPress Maintenance

The Basics of $wpdb->prepare() — Why You Should Never Build SQL Queries With String Concatenation

When a WordPress plugin or theme needs to talk to the database directly, it uses the core-provided global object $wpdb. The one thing to absolutely avoid when doing so is dropping user input straight into a SQL string through concatenation. The tool WordPress provides instead is $wpdb->prepare(). This post looks at why that matters and what the function actually does under the hood. Note: SQL injection is a broad term for attacks where unexpected input gets mixed into a SQL statement an application builds, rewriting what that statement actually tells the database to do. Any value coming from outside the application — form fields, URL parameters, and so on — …

Read more
WordPress Maintenance

WordPress Hooks Explained: How Plugins and Themes Extend Core Without Editing It

WordPress plugins and themes change what gets displayed and how data gets processed without ever touching WordPress core’s own files (the code under wp-includes / wp-admin). What makes that possible is a mechanism called hooks, which come in two flavors: actions and filters. This blog’s own theme, wpmm-blog, uses both extensively in its functions.php, so this article walks through real code from it. Note: a hook is a point WordPress core deliberately builds in for outside code to plug into. At specific points in core’s own source, calls like do_action() and apply_filters() are already embedded. Plugins and themes “hook” their own functions onto those points to intercept what core does …

Read more
Engineering Notes

Timezone Conversion Pitfalls: Where UTC/JST Bugs Actually Come From

Japan Standard Time (JST) is a fixed UTC+9 offset with no daylight saving time to complicate it. That simplicity makes it tempting to assume timezone handling is “just add or subtract nine hours.” In practice, most timezone bugs don’t come from getting that arithmetic wrong — they come from losing track of which basis a given timestamp is even using in the first place. This article walks through three real examples, drawn from actual code, logging, and this very blog’s own publishing workflow. Pitfall 1: values that don’t carry their own timezone Note: a “naive” datetime is a date/time value with no timezone information attached at all. An “aware” datetime …

Read more
Engineering Notes

Optimistic vs. Pessimistic Locking: Two Ways to Stop Database Updates From Colliding

When two people or processes update the same piece of data at nearly the same time, one can end up overwriting the other’s change without ever knowing it happened. This is the classic “lost update” problem, and it shows up anywhere a database, or any multi-process application, allows concurrent writes. There are two broad strategies for handling it: pessimistic locking and optimistic locking. The names are opposites, and so is the approach each one takes. The “silent overwrite” problem Say a table tracks inventory, and two processes, A and B, both read the same row at nearly the same moment. Both see “10 units in stock” and both compute “subtract …

Read more