The ones that cause real problems.
EDITING FILES DIRECTLY ON PRODUCTION
Changes exist nowhere else and are lost at the next deployment.
LEAVING DEBUG MODE ON
Exposes environment variables, file paths and stack traces to anyone who triggers an error.
SERVING THE PROJECT ROOT INSTEAD OF THE PUBLIC DIRECTORY
Makes .env, source code and vendor directories publicly reachable. The most serious framework deployment error.
LEAVING THE .GIT DIRECTORY IN THE WEB ROOT
Exposes the entire source history, including any credentials ever committed.
COMMITTING CREDENTIALS
They remain in history even after removal. Rotate them if it has happened.
NOT SETTING TIMEOUTS ON EXTERNAL CALLS
Your site becomes as slow as someone else's server.
QUERIES INSIDE LOOPS
The single most common performance problem.
USING 777 PERMISSIONS
Because a tutorial said so. It is never the right answer.
NOT CONFIGURING THE CRON JOB
WordPress scheduled tasks silently stop, since HTTP wp-cron is blocked.
NO BACKUP BEFORE A MIGRATION
Discovered at the worst possible moment.