ShieldThemes Web Development
+1 (415) 555-0142 Get a quote →
← Journal
Maya Okafor
AUTHOR · AT SHIELDTHEMES SINCE 2016

Maya Okafor

Head of Engineering

Maya leads engineering at ShieldThemes. She has shipped more than 120 WordPress and Laravel platforms and writes about architecture that survives its second year.

WordPressArchitectureSecurity

Articles by Maya

24 published
Next.js rendering choices: static, server or cached
Engineering · Aug 26, 2026 · 5 min
Next.js rendering choices: static, server or cached
Next.js offers several ways to render a page, and the default is not always right. How we decide per route between static, server and cached rendering.
Block themes are finally ready for serious client work
WordPress · Aug 22, 2026 · 5 min
Block themes are finally ready for serious client work
Why we now start every WordPress project with a block theme, and where we still reach for PHP.
INP in practice: fixing the metric that fails most stores
Performance · Aug 09, 2026 · 5 min
INP in practice: fixing the metric that fails most stores
Real traces from five client sites and the fixes that moved them into the green.
The WordPress security baseline we apply to every site
Security · Jul 15, 2026 · 6 min
The WordPress security baseline we apply to every site
Twelve controls that stop the vast majority of attacks we see in our care plans.
GDPR for website owners: the security side most teams miss
Security · Apr 21, 2026 · 5 min
GDPR for website owners: the security side most teams miss
Cookie banners get the attention, but GDPR also expects appropriate security, data minimization and a breach plan. What that means in practice.
Speeding up WordPress without another optimization plugin
Performance · Mar 24, 2026 · 5 min
Speeding up WordPress without another optimization plugin
Stacking caching and optimization plugins rarely fixes a slow WordPress site. Where the time actually goes, and how we get it back.
A design-to-development handoff that does not lose detail
Design · Mar 18, 2026 · 5 min
A design-to-development handoff that does not lose detail
Handoff problems are rarely about tools. They come from missing states, unclear intent and late involvement. How we keep design and code aligned.
Multi-tenancy for SaaS: shared schema or database per tenant
Engineering · Feb 13, 2026 · 5 min
Multi-tenancy for SaaS: shared schema or database per tenant
How you separate customer data shapes security, cost and every migration you will ever run. The trade-offs between shared and isolated tenancy models.
Background jobs and queues that survive failure
Engineering · Dec 12, 2025 · 5 min
Background jobs and queues that survive failure
Queues move slow work out of the request, but they also move failures somewhere harder to see. The patterns we use so jobs retry safely and nothing gets lost.
Multisite or separate installs: choosing for multi-brand WordPress
WordPress · Oct 29, 2025 · 5 min
Multisite or separate installs: choosing for multi-brand WordPress
How we decide between WordPress Multisite and independent installs for organizations running many sites, with the trade-offs in governance, plugins and hosting.
Setting up payment gateways for fewer declines and lower fees
E-commerce · Oct 22, 2025 · 5 min
Setting up payment gateways for fewer declines and lower fees
Payment setup is usually decided once and never revisited. Small changes to routing, authentication and retries can recover real revenue.
Admin access hygiene: two-factor, roles and offboarding
Security · Oct 21, 2025 · 5 min
Admin access hygiene: two-factor, roles and offboarding
Stolen and forgotten accounts cause more breaches than exotic exploits. A practical process for who gets access, how, and for how long.
Database schema decisions that hurt in year two
Engineering · Oct 16, 2025 · 5 min
Database schema decisions that hurt in year two
Schemas outlive frameworks, teams and redesigns. The early database choices we see causing the most pain later, and what we do differently from day one.
Penetration test or security audit: which one you actually need
Security · Aug 26, 2025 · 5 min
Penetration test or security audit: which one you actually need
They are often sold interchangeably, but they answer different questions. How to choose, scope and budget for each.
Syncing ERP inventory with your store without overselling
E-commerce · Jul 02, 2025 · 5 min
Syncing ERP inventory with your store without overselling
Overselling is rarely a bug in one system. It is a timing problem between two. How to design inventory sync that holds up under sale traffic.
Scaling WooCommerce past 50,000 products
WordPress · Jun 18, 2025 · 5 min
Scaling WooCommerce past 50,000 products
Database, search, caching and import strategies that keep a large WooCommerce catalog fast for shoppers and manageable for the team.
Laravel, Django or Node for a new product: how we choose
Engineering · Jun 13, 2025 · 5 min
Laravel, Django or Node for a new product: how we choose
The framework matters less than people think, but it still matters. The questions we ask before recommending Laravel, Django or Node for a new build.
Headless WordPress: when it pays off and when it does not
WordPress · Apr 23, 2025 · 5 min
Headless WordPress: when it pays off and when it does not
An honest look at the costs, benefits and hidden complexity of decoupling WordPress from its front end, with the questions we ask before recommending it.
Modernizing a legacy PHP application without a rewrite
Engineering · Apr 15, 2025 · 5 min
Modernizing a legacy PHP application without a rewrite
Big-bang rewrites usually run late and ship with fewer features. How we use the strangler fig pattern to modernize legacy PHP one route at a time.
WooCommerce, Shopify or headless for a mid-size store
E-commerce · Mar 12, 2025 · 5 min
WooCommerce, Shopify or headless for a mid-size store
Platform choice for a store doing one to twenty million a year comes down to ownership, operations and team shape. A practical comparison.
How we vet a WordPress plugin before it reaches production
Security · Mar 11, 2025 · 5 min
How we vet a WordPress plugin before it reaches production
Plugins are the largest attack surface on most WordPress sites. This is the review we run before any new one is installed.
Building Gutenberg blocks that editors cannot break
WordPress · Mar 05, 2025 · 5 min
Building Gutenberg blocks that editors cannot break
Constrained controls, sensible defaults, locking and validation: how we design custom blocks that keep the brand intact after handover.
Write the API contract before the front end exists
Engineering · Feb 12, 2025 · 5 min
Write the API contract before the front end exists
Agreeing on an API contract up front lets front-end and back-end teams work in parallel. How we write, review and enforce contracts on client projects.
How we vet a WordPress plugin before it goes on a client site
WordPress · Jan 22, 2025 · 5 min
How we vet a WordPress plugin before it goes on a client site
The review process we run on every third-party plugin, from maintenance signals to code checks, and when we write our own instead.
OTHER AUTHORS
Daniel Reyes
Daniel Reyes
Lead AI Engineer
Sofia Lindqvist
Sofia Lindqvist
Shopify Practice Lead
Arjun Mehta
Arjun Mehta
Founder & CEO
Leo Tanaka
Leo Tanaka
Head of DevOps
Nadia Haddad
Nadia Haddad
Design Director
Ravi Iyer
Ravi Iyer
SEO & Performance Lead