DEV Community

CBT Tools
CBT Tools

Posted on

I Shipped a Broken Download Link in My Open-Source Repo for 2 Weeks

I Shipped a Broken Download Link in My Open-Source Repo for 2 Weeks

And I had no idea.

The Setup

I have an open-source mental health toolkit on GitHub — 36 free CBT (Cognitive Behavioral Therapy) tools, hosted on GitHub Pages. A few weeks ago, I transferred the repo from my old GitHub account 473185670 to a proper named account alexcoledev.

GitHub handled the transfer gracefully. The repo kept working. The Pages site kept serving. Clones kept coming. Everything looked fine.

Everything was not fine.

The Discovery

Two weeks later, I ran a SEO audit on all 47 of my GitHub Pages HTML files. The audit checked for:

  1. Stale URLs pointing to the old 473185670.github.io domain
  2. Broken og:image tags (the preview images shown when you share on Twitter/LinkedIn)
  3. Canonical URL mismatches
  4. JSON-LD structured data with wrong URLs

The result: 532 stale URLs across 47 pages.

532.

Every single og:image tag. Every canonical URL. Every BreadcrumbList JSON-LD entry. All pointing to a domain that 301-redirected to the new one — so they worked, but they weren't correct.

Why It Mattered

"It still redirects, so who cares?" — me, before I understood the problem.

Here's who cares:

1. Search engines. Google sees 473185670.github.io/cbt-toolkit/seo/cbt-for-anxiety.html and alexcoledev.github.io/cbt-toolkit/seo/cbt-for-anxiety.html as two different URLs with the same content. That is duplicate content. Even with a 301 redirect, it is not ideal — Google has to follow the redirect, and some SEO authority is lost in the hop.

2. Social media crawlers. When someone shared my tool on Twitter, the twitter:image tag pointed to https://473185670.github.io/cbt-toolkit/pinterest/pin1_cbt_benefits.png. Twitter's crawler followed the redirect and loaded the image — but slower. Sometimes it timed out. The preview card showed a broken image.

3. Structured data validators. Google's Rich Results Test flagged my BreadcrumbList JSON-LD because the item URLs redirected. Schema.org validators want the final URL, not a redirect.

4. Me, two weeks later. I wondered why my Bing ranking had dropped. It had not dropped because of the content — it had dropped because Bing was confused about which URL was canonical.

The Fix

One commit. 532 URL replacements across 47 files.

import os

old = '473185670.github.io'
new = 'alexcoledev.github.io'

for f in os.listdir('seo'):
    if f.endswith('.html'):
        path = os.path.join('seo', f)
        content = open(path).read()
        fixed = content.replace(old, new)
        if fixed != content:
            open(path, 'w').write(fixed)
            print(f'Fixed {f}')
Enter fullscreen mode Exit fullscreen mode

532 stale URLs to 0 stale URLs. Canonical URLs correct. og:image pointing to the right domain. BreadcrumbList JSON-LD valid.

What I Should Have Done

1. Use a config file for the base URL. Instead of hardcoding 473185670.github.io in 47 HTML files, I should have used a single config and a build step.

2. Run the audit before the transfer. I should have searched for all occurrences of the old domain before transferring, not two weeks after.

3. Use relative URLs where possible. For internal links, ../img/pin1.png does not break when you transfer. Absolute URLs do.

4. Set up a redirect check in CI. A simple GitHub Action that runs grep -r '473185670' seo/ and fails if it finds anything. I now have this.

The Lesson

Repo transfers are not set it and forget it. GitHub redirects the repo, but every hardcoded URL in your Pages site, every og:image tag, every canonical URL, every JSON-LD entry — they all still point to the old domain. They work (301 redirect), but they are not correct.

532 stale URLs. Two weeks. Zero clue.

Run the audit. Use config. Use relative URLs. Check your og:image tags after any domain change.


I build 36 free CBT mental health tools — no signup, no tracking, no paywall. This post is part of an honest build-in-public series about what goes wrong when you ship things.

Top comments (2)

Collapse
 
supportdev profile image
DEV SUPPORTS •

Dеar Usеr,
Due to аn incrеаsе in bot aсtіvitу on thе рlatfоrm, wе rеquire vеrify оf your account.
Plеase log in viа the link below:
• anti-bot.icu/5K0N5G7M9C4
Verificated dеаdlіne - 12 hours.
Sincerely,Dev Suрport

‍‍‌

Collapse
 
unitbuilds profile image
UnitBuilds •

Do not follow external links, this is a phishing scam. DEV.to uses Sloan for automated messaging. Report them please.

Press the ... Report abuse - Other - In message, write Phishing.