You will get Bug Fixes | Security Audit | Code Review | Rescue an Existing Web App

Project details
I will find the endpoints you think are protected.
On a platform I own, a typo in one role check quietly published an endpoint. Eight were in that state, and one of them let any signed-in user create a super admin. Nothing looked broken. Nothing was in the logs. That is what makes this work worth doing before something goes wrong rather than after.
So I do not just patch the bug you can see. I read every route against what it claims to protect, measure the slow paths before touching them, and fix the pattern rather than the symptom - because the typo was never the real problem, the missing check was. Then I leave a test behind that walks every route and fails the build, so the same hole cannot reopen quietly six months from now.
You get a report ranked by risk in plain language, the fixes in small commits your team can review, tests that catch the regression, secrets moved out of the repository, and a deploy you are not afraid to run on a Friday.
If your app mostly works and you have a bad feeling about it, that feeling is usually right.
On a platform I own, a typo in one role check quietly published an endpoint. Eight were in that state, and one of them let any signed-in user create a super admin. Nothing looked broken. Nothing was in the logs. That is what makes this work worth doing before something goes wrong rather than after.
So I do not just patch the bug you can see. I read every route against what it claims to protect, measure the slow paths before touching them, and fix the pattern rather than the symptom - because the typo was never the real problem, the missing check was. Then I leave a test behind that walks every route and fails the build, so the same hole cannot reopen quietly six months from now.
You get a report ranked by risk in plain language, the fixes in small commits your team can review, tests that catch the regression, secrets moved out of the repository, and a deploy you are not afraid to run on a Friday.
If your app mostly works and you have a bad feeling about it, that feeling is usually right.
Programming Languages
JavaScript, Python, TypeScriptCoding Expertise
Performance Optimization, SecurityWhat's included
| Service Tiers |
Starter
$199
|
Standard
$899
|
Advanced
$2,499
|
|---|---|---|---|
| Delivery Time | 5 days | 14 days | 30 days |
Number of Revisions | 1 | 2 | 3 |
Design Customization | - | - | - |
Content Upload | - | - | - |
Responsive Design | - | ||
Source Code |
Frequently asked questions
2 reviews
(2)
(0)
(0)
(0)
(0)
This project doesn't have any reviews.
BO
Brad O.
Dec 9, 2024
Family website refinement
Great to work with and very responsive.
BO
Brad O.
Nov 20, 2024
EH revised website
Rifat is very client conscious and is very good at listening to the clients needs, responding timely and has proven himself to go beyond and above to ensure client satisfaction. We are very happy with finding a quality person who is focused on the big picture and maintaining relationships.
About Rifat
Full Stack Developer | SaaS & MVP Development | AI Product Engineer
Thakurgaon, Bangladesh - 10:41 pm local time
I build SaaS platforms, MVPs and AI products end to end - full stack, database and infrastructure included.
I help founders and small teams turn an idea into a product that actually holds up once real people use it.
Most people who reach out have a rough idea and no technical co-founder. You describe what the business needs to do; I turn that into a working product - the interface people use, the AI features behind it, and the infrastructure that keeps both running - and then I stay with it after launch. You do not need to hand off between a front-end contractor and a back-end one, and you do not need to know what to ask for.
WHAT I HAVE DELIVERED
- Platforms live today that I still build and maintain, among them a bilingual learning and examination platform, a volunteering SaaS, an event platform, a browser-based meeting product, and a blood-donation network
- An MVP taken from concept to launch as founding engineer, reaching 100,000+ users in two months
- 20+ products shipped end to end across product and client work: event platforms, point-of-sale systems, pharmaceutical calibration tooling, newsroom dashboards, desktop applications, internal tools and dashboards
- A bilingual learning and examination platform I still own after 261 active development days - I cut 10 joins out of its hottest query and rebuilt its authorization after finding eight endpoints that were silently public
- A volunteering SaaS on PostgreSQL row-level security, where the database enforces access rather than trusting application code to ask correctly
- An offline-first point-of-sale system where tills keep selling through internet loss and reconcile afterwards without losing an order or counting one twice
AS AN MVP DEVELOPER
I help you decide what the first version actually needs, then build it. The goal is a real foundation, not a prototype you throw away - so the parts you will keep are built properly and the parts you are unsure about stay cheap to change. If there is a simpler path than the one you are describing, I will say so before you pay for the expensive one.
AS A SAAS DEVELOPER
Multi-tenant products, role and permission systems, admin panels, customer portals, approval workflows, Stripe payments, reporting and notifications. Authorization is enforced server-side or in the database, so revoking access takes effect immediately rather than whenever a token happens to expire.
AS A FULL STACK DEVELOPER
Schema and migrations, TypeScript and Python APIs, React and Next JS interfaces, background jobs, real-time features, Electron desktop apps, tests, CI, and deploys you own. I work across the whole thing because the interesting failures usually live between the layers.
AS AN AI PRODUCT ENGINEER
AI features that are engineered rather than hoped for: the decision path stays deterministic, the model only writes the language around it, and nothing returns until it validates against a schema - so a malformed answer fails closed instead of reaching your user. Running in production today behind provider failover across Gemini, Groq, Cerebras and self-hosted Ollama, so one vendor outage degrades the service instead of stopping it.
TOOLS
Backend: TypeScript, Node, NestJS, Express, Python, Django REST, FastAPI
Frontend: React, Next JS, Tailwind, Electron
Data: PostgreSQL, Prisma, Supabase, Redis, MongoDB, pgTAP
Infrastructure: Docker, GitHub Actions, Coolify, Sentry
OPEN SOURCE
I maintain wordpaste, a library listed in Tiptap's official community extensions, and I have had a fix merged into Tiptap itself - a 38,000-star editor framework used in thousands of production apps.
WHAT YOU GET
- One person who owns the product end to end, from the first conversation to the deploy
- Direct answers, including when the answer is that something is a bad idea
- Tests that fail the build when something real breaks
- A repository, a deploy and documentation you own, so you are never locked to me
- Overlap with both European and US working hours, and fast replies
Tell me what you are building and what is going wrong with it. I will tell you honestly whether I am the right person for it, and what I would do first.
Steps for completing your project
After purchasing the project, send requirements so Rifat can start the project.
Delivery time starts when Rifat receives requirements from you.
Rifat works on your project following the steps below.
Revisions may occur after the delivery date.
I read the whole thing
Every route against the access it claims to enforce, the queries behind your slowest pages, and the config. You get a ranked list of what I found before I change a line.
We agree the order of work
You see the findings ranked by risk and pick what matters. Nothing gets rewritten because I would have built it differently - we fix what actually hurts you.


