8 ms·
Web Developer Checklist
- codegeek 14y agoThx for sharing. For a newbie in web dev (like me), it is a great resource. Bookmarked.
- drinchev 14y agoYou might want to link your href-s to new tab/window.
- malachismith 14y agoGreat start. Wish it were set up to be collaborative so we could suggest some of the missing elements.
- mikle 14y agoI have a sublist of that, that I built over the last ~year of hacking on web projects. One of my biggest to dos in each project is automate stuff like validating. I still haven't really found a good way so I either go to w3c and check everything once in a while or I just don't. Usually I just don't. This to me is like a checklist of things to automate. Is there any "build" system for the web?
- jiggy2011 14y agoCustom 404 page under usability? hmm. I'm sure just about anyone who has used the web for any length of time has hit the standard apache "Not found" page hundreds of times now and pretty much knows what it means. Custom 404 pages of often quite confusing as they will try to be clever and redirect you to other content that may be interesting. Sometimes these aren't clear and give the impression that the link was not broken and that this is where the site designer intended you to go which leaves you looking around the page for the content you thought you were going to get.
- bittermang 14y ago"Custom 404 pages of often quite confusing as they will try to be clever and redirect you to other content that may be interesting." I agree, however I also believe that is the intent of filing it under "usability". It isn't usability as you would commonly define it, a good UX, but rather keeping the UX of the site consistent across all states, even failure, and giving the user an entry point back in to the rest of the site. A default Apache 404 does not do this, it's just a flat white page, with your only option being to go back from whence you came. If that wasn't your site, then the perception is you've lost a potential visitor, and that potentially could've been avoided with a custom 404 page.
- caseysoftware 14y agoI prefer the 404 pages that something to the effect of "Sorry, that is broken" and then include the results of a site search of the keywords or friendly url that was provided. It's less confusing and keeps people on site.
- rplnt 14y agoIf you do this (which you should in my opinion), please return the 404 code. For example Facebook used to return 200 on error. Very confusing.
- caseysoftware 14y agoAbsolutely, I assumed that was a given.
- kylelibra 14y agoGood stuff, I'll probably use this for clients who say, "What have you been doing? It looks done to me!"
- pestaa 14y agoThis drives me nuts. On the surface there is very little difference between `just functional' and `production ready'. And it's a hard sell if the client is not aware of the benefits.
- pdog 14y agoWould be nice to have this automatically generated for a given URL.
- javajosh 14y agoSolid functionality that I'll personally use. Good work.
- eranation 14y agoLiked the favicon part, very often forgotten... Would be nice if this was open sourced so more items could have been added by the community (also framework specific checklists) but I like the concept One thing I would add which is driving me crazy on mobile / tablet sign up pages - make sure your email fields are annotated with type="email" Another common issue is with SSL mixed content waring, so I would also add - make sure to use protocol relative / https only URLs (with a reminder to NOT use protocol relative URLs in email templates, your outlook users will appreciate it)
- rickmb 14y agofavicon is only forgotten by those that never check their logs. (Which should be part of the checklist, check your friggin' logs instead of assuming you never miss anything.)
- ajessu 14y ago> Would be nice if this was open sourced so more items could have been added by the community (also framework specific checklists) but I like the concept Just to share, since you mention framework specific, a similar concept exists since a while ago for the PHP symfony (version 1) framework (not official, but I quite liked it back then) http://symfony-check.org/ http://symfony-check.org/
- loosepackets 14y ago> Would be nice if this was open sourced so more items could have been added by the community https://github.com/ligershark/webdevchecklist.com https://github.com/ligershark/webdevchecklist.com
- BCM43 14y agoIt is open source, but I can't seem to find a license on that page, so it may not be free software. I would be reluctant to modify and redistribute copies of it.
- madskristensen 14y ago
- alexanderclose 14y agoBig time bookmark. Thanks!
- xer0x 14y ago+1 thanks for this!
- r0s 14y agoNo clean URLs? How about setting up automated backups?
- fragsworth 14y agoClean URLs aren't really necessary and can be difficult with some frameworks. Automated backups also aren't necessary for all sites, particularly if the entire site is in a source repository somewhere and doesn't have users.
- r0s 14y agoClean URLs are just as useful and visible as the favicon, or custom error pages, or many other "unnecessary" features. You need to backup production sites. A repo could do that, but it's just another backup system that needs to be implemented and verified.
- fduran 14y agoAnother nice list: http://www.boxuk.com/blog/the-ultimate-website-launch-checklist http://www.boxuk.com/blog/the-ultimate-website-launch-checkl...
- vasco 14y agoInterestingly enough this website doesn't have: 1) Custom 404 page 2) robots.txt 3) PICS label 4) viewport meta-tag 5) Google Rich Snippets 6) Fails the recommended CSS validator
- Flimm 14y agoI would add one: Make sure your log-in form is uncomplicated so that browsers can remember passwords correctly.
- steerpike 14y agoI did something similar - a checklist for prelaunch which you might find some useful things to add to your list: https://bitbucket.org/steerpike/checklist https://bitbucket.org/steerpike/checklist
- soitgoes 14y agoI'd add: check your SSL certificate installation using a tool like this: http://certlogik.com/ssl-checker/ http://certlogik.com/ssl-checker/
- lost-theory 14y agoCool, I haven't seen that one before. I also like this one: https://www.ssllabs.com/ssltest/ https://www.ssllabs.com/ssltest/
- furyofantares 14y agoThis is cool, I expect a lot of people could get use out of this. The security section is kind of amusing, though.
- prodigal_erik 14y agoA document that bills itself as "The ultimate checklist for all serious web developers" should not hide most of its content (via CSS) and require trusting some unknown author's javascript to display it.
- danso 14y agoSo "SEO" has four different checkboxes but "Security" has just one: "Implement best practices" Uh...I think that can be broken down to at least two different things...
- pestaa 14y agoThe second being 'cross your fingers'...?
- ahallock 14y agoThe spellcheck item didn't have a link. Any good spellchecker bots out there?
- zxcdw 14y agoIt's sad how "Security" there's only one very generalizing item. "Implement best practices". Right. Is the author just ignorant, or am I a fool thinking that if anything it should be "Security" which has the most elaborate items?
- critium 14y agoYes, having robots and favicon is nice, but there are few items on this list that can embarrass / kill a company like bad security.
- Joeri 14y agoSecurity checklist: https://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project https://www.owasp.org/index.php/Category:OWASP_Application_S... Lowest level 1a has 22 things to verify, highest level 4 has 121 things to verify. That's a lot of checkboxes.
- SquareWheel 14y agoSecurity is much more dependent on the site itself though, it's not as "general". Do you have forms? Then watch out of SQL injection. Do you have user input of any type? Watch for XSS. Admin login page? Consider HTTPS. Something like a favicon can apply to every site, not so much with security practices. The idea of just having a "security checklist" is a bit worrisome in itself. The developer in charge should be familiar with the potential dangers as they program a feature, it shouldn't be an afterthought from a checklist.
- bencevans 14y agoNice work, I use this at the moment http://lite.launchlist.net/ http://lite.launchlist.net/ as it has more checks and well a prettier interface.
- tokenadult 14y agoI see that Jakob Nielsen's venerable "Top 10 Mistakes in Web Design" checklist http://www.nngroup.com/articles/top-10-mistakes-web-design/ http://www.nngroup.com/articles/top-10-mistakes-web-design/ just got new styling the other day, as I work on updating my seventeen-year-old personal website. There are still a LOT of websites that make several of those top ten mistakes. They are higher priority than many of the other issues mentioned on the checklist kindly submitted here. As other comments here have pointed out, it's desirable in a checklist to establish priorities.
- benjoffe 14y agoNo. 5 on that list is not valid any longer, fixed font sizes were only an issue with IE6 where fonts specified in pixels wouldn't respond to the user's font size setting.
- halfninety 14y agoNice list, but I think it can be condensed into one: Use your own site and make sure you don't hate it yourself.
- onlyup 14y agoSimple but effective advice.
- johnpowell 14y agoSecurity > Cross-site scripting > XSS cheat sheet link is broken. Funny considering the first item in the checklist.
- karolisd 14y agoWhat would be the best approach to automate this so I could put in a URL and it detects as much as it can about the website?
- jstanley 14y agoI was thinking about this a couple of days ago. The way I would do it is to submit it individually to each of the checks (e.g. W3C validator) and scrape the results. There may be APIs available for some, I've not looked into that.
- Achshar 14y agoWhat do people here think of no-www? I personally hate www and see no reason to unnecessarily increase my url length by 4 characters.
- franze 14y agosorry, saw this too late, please see my comment above https://news.ycombinator.com/item?id=5025293 https://news.ycombinator.com/item?id=5025293
- franze 14y agosorry but that Remove 'www' subdomain is just harmful. force 'www.' instead. why? shitty URL parsers, marketing people and DDOS attacks, that's why. let's imagine you write a - blog post - blog comment - press release (distributed via free and paid press release services) - mail - word - forum post - ... - ... if you have a non-www URL it's a game of chance, your in text "whatever.tld" domain will get transformed into a clickable link. yes, a lot of modern URL parses will transform whatever.com into a clickable link, some will even transform whatever.in into a useable link, but a lot of old, shitty, idiotic, strange URL parsers won't. and well, a big part of the web, i would say most of it, is not up to date. so using non WWW will lead to a loss of inlinks and to a poor user experience of users who want to reach your site, but can't click on the in-text-domain (they need to copy/paste instead) and the situation will get worse with the new commercial TLDs to come. yes, you can - in most cases - force a domain to link conversion in most CMS if you write http:// http:// in front of it. but well, in a promo text most marketing/pr people will not write "and http://whatever.tld http://whatever.tld has a new feature to give people endless bliss" they will write "whatever.tld has a new ....". oh, and by the way. whenever a journalist will write a piece about you, in print or online, they will always (or at least in a lot of cases) write www in front of your domain anyway. yeah, that's not an issue if you have redirects in place, just annoying if you have an non-www webproperty. plus having a subdomain is another layer of defenses agains DDOS attacks. see this discussion on hacker news from may 18 2011 (my birthday by the way) http://news.ycombinator.com/item?id=2575266 http://news.ycombinator.com/item?id=2575266 go for www.
- mokash 14y ago301 redirects.
- franze 14y agodoes solve only the annoyance part (wrong www URLs by journalists), not the shitty URL parser & marketing people and DDOS issues.
- SquareWheel 14y agoAnd yet, I find no-www so much cleaner. With 301s it's generally not a problem, and link parsers will look for the protocol anyway. I think the only valid point is mitigating DDOS attacks, but I don't know enough about that subject to comment.
- tiedemann 14y agoReally good for showing customers/bosses/coworkers why a site need those extra hours of love after the proof-of-concept stage.
- jacobwyke 14y agoI have a template project in Basecamp that contains a similar kind of list of tasks that I use to launch all projects. Just have to create a new project with the template for each launch and then work your way down.
- bwblabs 14y agoA no-www domain might not be the best solution if you ever want a 'Cookie-free Domain' (static.) for images etc. which speeds up your site. If you start with a no-www domain you have to setup a different domain (no subdomain) for it: like sstatic.net for SO, ytimg.com for YT and yimg.com for Yahoo. When the browser makes a request for a static image and sends cookies together with the request, the server doesn't have any use for those cookies. So they only create network traffic for no good reason. You should make sure static components are requested with cookie-free requests. Create a subdomain and host all your static components there. If your domain is www.example.org, you can host your static components on static.example.org. However, if you've already set cookies on the top-level domain example.org as opposed to www.example.org, then all the requests to static.example.org will include those cookies. In this case, you can buy a whole new domain, host your static components there, and keep this domain cookie-free. http://developer.yahoo.com/performance/rules.html#cookie_free http://developer.yahoo.com/performance/rules.html#cookie_fre...
- retube 14y agoI never considered this before. A great tip, thanks
- ZoFreX 14y agoBear in mind that making sure requests for static content don't send cookies is pretty far down the front-end optimisation ladder - there are normally a lot of things you can do first that are quicker, easier, and have a bigger impact.
- bwblabs 14y agoWell another thing is that it's easier to setup GEO-ip stuff in a CNAME (so www) instead of the root A records, for now at least in PowerDNS (used by Wikipedia etc.). You're completely right, but if your sites ever scales to something big you're not in the best position with a no-www, in my view having a www record (and no-www redirect) has more benefits that a no-www.
- 14y ago
- Yaggo 14y agoNice list. Missing: HiDPI images.
- marknutter 14y agoAnd people say web development isn't difficult.
- zupa-hu 14y agoWoW I am building an automated tool right now for exactly that. It is in private beta. Anyone interested in test riding it drop me a line! http://site-analytics.org/ http://site-analytics.org/ The intro is already outdated, I'll make a new one very soon.
- jacalata 14y agoI built a public trello board from this list: not quite sure if that's the best presentation (should it be one card for each heading?), but ideally people would clone it to work on their own sites, and make contributions of new cards/info for existing cards on the main board. https://trello.com/b/hkC4B6HA https://trello.com/b/hkC4B6HA
- mskierkowski 14y agoIs it time for feature requests? It'd be great to get integration with common management tools (e.g. Github Issues, Trello), so that the list can automatically be imported for a given milestone.