Oxwyn Studio

Engineering Notes

Field reports from the studio.

20 reports on how we actually build: AI-first discovery, sub-300ms cached performance, security engineering and honest commercial models. No fluff, no fabricated numbers.

Security24 Aug 2026Latest report

Your plugin list said you were patched. For most of these sites it was lying.

Read the report

Security

20 Aug 2026

Two WordPress form plugins in three days, both handing over the server

CVE-2026-32475 in Elementor Pro scores 9.0 and needs nothing but a public form with a file upload field. It is the second critical unauthenticated RCE in a WordPress form plugin this week, and the pattern matters more than either bug.

Read

Security

17 Aug 2026

A critical flaw in one form plugin exposed 600,000 sites. The plugin was not the problem.

CVE-2026-15748 scores 9.8 and lets an unauthenticated stranger upload a PHP file to your server. The vendor patched it in seventeen days, which was good. Here is how to check whether you are exposed, and why the interesting question is not about WordPress.

Read

GEO

17 Aug 2026

The CMA won an AI Overviews off switch. If you are not a publisher, leave it alone.

On 3 June 2026 the CMA made Google give sites a way out of AI Overviews. It was won for news publishers, it is appearing in every UK Search Console, and for most businesses flipping it would be a straightforward mistake. Here is what it does and the three controls people keep confusing.

Read

Commercial

17 Aug 2026

Nearly half of UK businesses use AI. Almost none of them have an agent.

Official figures say 41% of UK businesses use AI, and the top two uses are researching and drafting. That is a chat box, not an agent. The real difference, three worked examples with the sums shown, and the four questions that decide whether it is worth building.

Read

Security

10 Aug 2026

Anyone can send an email that looks like it came from your company

Unless you have published two records in your domain settings, strangers can send email that appears to come from your address. Across 73.3 million domains, 83.9% have no DMARC record at all. Here is the three-minute check, and the honest limit of what it protects.

Read

Security

5 Aug 2026

Your website is not a purchase. It is a decay curve.

Around 36 new vulnerabilities are disclosed against common website software every day, and exploitation typically begins within five hours. That single fact is the honest answer to why a website plan is monthly, and it is the one most providers never give.

Read

Commercial

5 Aug 2026

Your web designer will not hand over your website. Here is what you actually own.

Check the domain, then the hosting, then the contract. Under UK law paying somebody to build something does not transfer the copyright in it, which is the part almost nobody is told. A practical twenty minute guide, plus the five questions that prevent it happening again.

Read

Commercial

5 Aug 2026

We checked 12 UK pay monthly website providers. Three mention a DPA.

A pay monthly website is a contract, not a purchase. We checked what twelve UK providers publish before you sign, and set out the ten questions to ask any of them, including us.

Read

Commercial

5 Aug 2026

What a UK dental practice website costs, and the GDC rules most of them breach

A practice website is a regulated advertisement holding patient data. Here is what it should cost, the GDC advertising rules a general web designer will not know, and the ten questions to ask whoever builds it.

Read

Case Study

23 Jul 2026

Case study: engineering oxwynstudio.com from blank repo to live in production

How we engineered our own site, from default-deny database rules to consent-gated analytics, and why it is the standard we hold client work to.

Read

AEO

23 Jul 2026

Why GPTBot now reads your sitemap before Google does

AI crawlers now hit new sites within hours. Blocking them makes you invisible in AI answers, so here is the robots.txt we actually ship and why.

Read

GEO

23 Jul 2026

llms.txt: a field guide to the newest file in your web root

A curated map of your site written for language models. What llms.txt is, what it is not, honest adoption numbers, and why we ship one anyway.

Read

AEO

23 Jul 2026

JSON-LD that AI engines can actually use

Which schema.org types earn their keep for AI answers, the XSS trap nobody mentions, and the structured-data lies that get sites ignored.

Read

Performance

23 Jul 2026

The 287ms budget: how we ship sub-300ms LCP routinely

Google calls 2.5 seconds good. We budget for 300 milliseconds, and the discipline of that number changes every build decision that follows.

Read

Security

23 Jul 2026

Honeypots beat CAPTCHAs on contact forms

A hidden field and a three second timer stop most form spam without making your best leads identify traffic lights. Here is the pattern we ship.

Read

Engineering

23 Jul 2026

Geo-aware pricing with no IP lookup, no cookies, no consent banner

Showing a Texan prices in pounds sterling costs you the enquiry. Here is how we localise currency using only signals the browser already offers.

Read

Privacy

23 Jul 2026

Consent-gated analytics that still tell you the truth

Most cookie banners are theatre bolted onto trackers that already fired. Ours is a gate, and the analytics behind it are better for it.

Read

Architecture

23 Jul 2026

Composable beats CMS for marketing sites under 200 pages

Most small marketing sites pay CMS costs for CMS problems they do not have. Components in a repo plus one thin data layer usually wins.

Read

Commercial

23 Jul 2026

What a website should cost: the economics behind Website-as-a-Service

Why one-off agency builds quietly depreciate, what a monthly plan really buys, and where Website-as-a-Service margins honestly come from.

Read

Technical newsletter

One field report. Every other Friday.

No fluff. Real numbers from real systems we ship.