Dictionary

Every way a software project gets stuck, and how to get it live.

61 plain-language answers to what people search when their app is broken, abandoned, unsafe, or never launched. Each one says what's wrong, why, and how to fix it.

Live but broken

All 8 →

It's online, but visitors see an error, a blank page, or nothing at all.

My website is down. How do I fix it? Find which layer failed first: the domain, the hosting account, the server, or the app. What the browser shows tells you where to start. A checklist, in order. My website says "Not secure". How do I fix it? The browser can't confirm a private (HTTPS) connection: no certificate, an expired one, one that doesn't cover this address, or insecure content on the page. 500 Internal Server Error after deploying. What does it mean? Your server code hit an error it didn't handle. The page won't say what; the server logs will. After a deploy it's usually a missing setting, database or file. 502 Bad Gateway: what does it mean, and how do I fix it? The server in front of your app asked your app for the page and got no proper answer. Usually the app has crashed, never started, or is on the wrong port. 503 Service Unavailable on my site. What's wrong? The server is reachable but refusing work: it's overloaded, in maintenance, or has no running copy of your app to hand requests to. How to tell which. My app can't talk to its own backend (CORS error). How do I fix it? The browser blocked your frontend from reading your backend's reply, because the backend didn't list your site as allowed. The fix goes on the server. Heroku says "Application Error". How do I fix it? Heroku's generic page for an app that crashed, didn't start in time, or has nothing running. The code in heroku logs (H10, R10, H14, R14) says which. My app crashes as soon as it opens. Why? The crash report names the line. Usually the release build lacks something the test build had: a setting or key, code stripped to save space, or a live backend.

Is it safe?

All 12 →

Logins, user data, keys and databases: the holes that matter before real users arrive.

How do I check my app is secure before launch? Check what attackers try first: who can see whose data, logins, open keys and databases, injection, payments, rate limits, HTTPS and old dependencies. My website has been hacked. What do I do? Take it offline, change every password, find how they got in, restore a clean backup, update, and ask Google to review. Then check if customer data was taken. I leaked an API key. What do I do? Revoke it and create a new one now, before anything else. Deleting it from the code doesn't help: it's still in the history. Then check what it was used for. Do I have to report a data breach? (Australia) If the Privacy Act covers you and the breach is likely to cause serious harm, yes: tell the OAIC and those affected. Suspected breaches: assess within 30 days. My database is open to the internet. How do I close it? Turn off public access, let only your app's servers through the firewall, and require a strong login. Then check the logs: it may already have been copied. Supabase RLS is disabled. Is my data public? A table in an exposed schema without Row Level Security is readable and writable through your public key, which is in your app. Turn RLS on for every table. Is my Firebase database open to anyone? If it was set up in test mode and never locked down, possibly. The API key being public is normal: the security rules are what protect the data. How to check. Are my app's uploaded files public? (S3) New S3 buckets are private by default, but a policy can open them. Turn on Block Public Access, and serve private files through short-lived signed links. Are my environment variables public? Anything your frontend can read, every visitor can read. Settings prefixed VITE_ or NEXT_PUBLIC_ end up in the browser. Secrets belong on the server. Is it safe to keep login tokens (JWTs) in localStorage? It's a risk: any script on your page can read localStorage, so one injected script can steal every logged-in session. HttpOnly cookies can't be read by scripts. My project shows dozens of security warnings (npm audit). Should I worry? Some, not all. npm audit lists known holes in the packages you use; many are in build tools that never reach users. Fix what ships, and test before forcing. How much does a penetration test cost in Australia? Australian testing firms publish indicative prices from a few thousand dollars for a small web app to tens of thousands for bigger scopes. What sets the price.

It used to work

All 11 →

Nothing changed, but now it won't install, build or start. Software rots when it sits.

Everything in my project is years out of date. How do I update it? Get it running exactly as it is first. Then update in small steps (runtime, then framework, then the rest), testing between each, and replace what's abandoned. npm install fails on my old project. How do I fix it? Usually Node is too new for the project, the lockfile and package.json disagree, or a package needs build tools or no longer exists. Check each, in this order. My project only runs on an old version of Node. What do I do? Run it on its old version with a version manager so it works again, then upgrade one long-term-support release at a time. Node 20 and older are end of life. Create React App is deprecated. What now? Your app still works: Create React App is in maintenance mode but has no active maintainers. React recommends moving to a framework or a build tool like Vite. npm ERESOLVE: unable to resolve dependency tree. What does it mean? Two packages want different versions of a shared one, often React. --legacy-peer-deps forces the install but hides the conflict. Update the odd one out instead. My site needs a newer PHP version. How do I upgrade safely? PHP versions get four years of support, then none. Check what your code and plugins support, test on a copy, step up one version at a time, then switch live. How do I upgrade an old Laravel app? One major version at a time, following each official upgrade guide, upgrading PHP as you go. Laravel versions get security fixes for two years after release. My Python project won't install its dependencies. How do I fix it? Use a fresh virtual environment, the Python version the project was built for, and its pinned requirements. Most errors on old projects are version mismatches. My Docker build fails. How do I fix it? Find the Dockerfile step that failed. Old projects usually fail on an outdated base image, a file outside the build context, or installing dependencies. My Docker container won't start. Why? The container's logs say why. Usually the app crashed on start: a missing setting, a database it can't reach, the wrong command, or listening on localhost. A database migration failed in production. What now? Stop deploying, back up, and find out exactly which steps ran. Then either roll back and fix, or finish the steps by hand and mark it resolved. Never reset.

Can't find yours?

Tell us what you built and what's stopping it. We'll go through it and tell you in writing what's broken, what it takes, and whether it can be saved. Free.

Submit your project