Backend engineer. Laravel at home, curious everywhere else.
I've been building for the web professionally for 5 years, mostly production systems: APIs, integrations, internal tools, and the Linux servers they run on. I like the parts of software that get ugly once it's live, and I'm good at making them boring.
Who's behind this
I'm Ali, a backend engineer based in Lahore. I started in 2022 building WordPress sites and Shopify themes, and that grew into Laravel, APIs and the servers they run on.
What I do
Laravel and PHP are my core, but the job usually reaches further than one framework.
Systems that stay changeable
Inventory platforms, CMS backends for mobile apps, internal tools. Built to be debugged and extended long after launch.
Integrations & pipelines
Shopify GraphQL, ServiceTitan, Twilio, Oracle sync, and ETL on Azure Data Factory. Messy third-party data, made dependable.
Legacy rescue
Laravel 5 to 12, Symfony 3, Ubuntu 16 to 24. Schema and permission overhauls that keep data and consumers intact.
Servers & deployment
Linux, Apache, MariaDB, firewalls, automated security updates, backup automation, and server migrations. A Linux daily driver since 2017.
Selected work
Client names stay private; the engineering doesn't. Open any of these for the detail.
Shopify product import & lifecycle
About 32,000 variants across 2,000 products, imported from FTP-delivered CSVs without two jobs ever colliding.
The problem. A catalogue arrived as CSVs on an FTP server and had to become Shopify products, variants and collections, then be retired on schedule.
What I built. An hourly pipeline that processes files deterministically by modification time, isolates failed rows and re-uploads them for retry, and cleans up what succeeded. It uses GraphQL bulk mutations, paces image uploads by the API's reported cost, stores Shopify IDs locally to skip redundant calls, creates rule-based collections on first use, and handles drop dates through scheduled jobs. A full mutual-exclusion lock means only one import or deletion runs at a time.
Result. Handles ~32,000 variants in production. I was the sole developer.
Two legacy Laravel apps, modernised
A CRM and a support platform taken to Laravel 12 with a rebuilt permission model, no unintended data loss.
The problem. Two production apps talking over APIs: one on Laravel 5, one on 9, with years of data debt and a permission model that no longer matched the client's needs.
What I did. Led the upgrades to Laravel 12, the schema changes and legacy-data cleanup, all proven on staging first. I redesigned access around a company-level hierarchy with fine-grained permissions. One requirement shaped the design: roles are permission templates, so editing a role never silently changes the access of people already assigned to it.
Result. Both apps run on Laravel 12 with their functionality and API link intact, and a far easier base to extend. Removed data was only what the client asked to have cleaned up.
B2B mobile app backend & CMS
The Laravel API and admin CMS behind a React mobile app for product discovery and sample ordering.
The problem. More than a product catalogue: admin-configurable product data, approval-based onboarding, fine-grained access control, ordering, notifications, and constant sync with the client's in-house Oracle system.
What I built. The API and domain model, including properties admins can define as filters, sliders or info fields without a developer. Sign-up works with email, Google or Apple, with admin approval before access. Auth runs on Sanctum and Fortify, with RBAC covering both the CMS and individual API actions. Notification templates are CMS-managed, rendered with Mustache and sent via queues. I also configured the production Linux server and later migrated the app to a replacement.
Result. Live, in public use, and still evolving without needing a new architecture.
Warehouse inventory system
My largest build: raw materials and finished goods across a multi-warehouse manufacturer, with 80+ domain models.
The problem. Track stock, cost and pricing for a manufacturing client, and keep the books honest as requirements kept growing.
What I built. A voucher-based model for movement and accounting (purchases, receipts, deliveries, adjustments), with warehouse bins, factory allocation, stock transfers and reconciliation. It evolved heavily as the client's needs expanded.
Servers too. I set up and ran the in-house Linux server: Apache, MariaDB, access controls, firewall rules and automated security updates.
Legacy Symfony system & server upgrade
A Symfony 3 admin panel and API, plus the Ubuntu 16 server underneath it. I'd never heard of Symfony before this.
The server. Upgraded Ubuntu 16 LTS to 24 LTS and moved PHP to the newest version the app supports. Infrastructure only, by client choice, which kept things stable and extended the server's life.
The app. Replaced hard-coded, enum-like types with a normalised, CRUD-managed model, changing schema, admin workflows and API responses without breaking existing consumers. Added hierarchical roles (chief-level roles managing agencies in scope) with access control enforced in the backend, and extended the domain models for new business workflows.
The outage. A production failure traced to a deprecated S3 integration. I upgraded the obsolete AWS SDK to v3, which stabilised asset handling in a codebase untouched by updates for years.
Pace. Phase one, the enum-to-CRUD refactor, shipped in under a week.
ServiceTitan appointment SMS
Syncs customers, jobs and appointments by polling (the webhooks weren't ready), without overlapping runs, then texts customers a tracking link through Twilio while respecting opt-outs. ServiceTitan sent dates outside what MySQL can store, so I kept them as signed 64-bit integers behind a custom Laravel cast instead of patching around each oddity.
Data Feed Creator
A custom Shopify app: Flask handles install, auth, GDPR and uninstalls; Laravel syncs store data and serves CSV and TSV feeds with an admin panel. I took it over a week in and carried it to the finish.
Cybersecurity SaaS data pipelines
On a multi-tenant Django platform, I worked on schema design and ETL with Azure Data Factory, feeding third-party threat data into a separate reporting database. I reshaped client-supplied ERDs to match what the real APIs return.
Desktop release pipeline
A CI/CD pipeline that builds a Flutter app for every desktop platform, publishes the builds to the storage directory of a Laravel backend, and updates a JSON manifest as it goes. I owned the deployment side of a project that was otherwise someone else's.
Config-driven GFS backups
A generic shell script that automates grandfather-father-son backup rotation from a configuration passed to it. Written to get GFS backups running for several apps on one client's server, and reusable for the next one.
How I work
Remote-friendly, comfortable with distributed teams, and happy to own a feature end to end.
I ask first
Before building, I ask as many questions as it takes. Getting what the client actually wants into reality beats polishing the wrong thing.
And I know when to ship
All that asking can stretch a timeline, and I know it. When the picture is clear enough or the deadline is real, I make the call, write down the assumption and move.
Staging before production
Risky changes get proven on staging first. Schema changes, upgrades and migrations land without surprises.
Built for the next person
Maintainable, debuggable, safe to change once it's live. On long-running accounts I also guide teammates on architecture and planning, and step in when something's stuck.
Range
Grouped by how deep I go, not by how many logos fit.
- Daily
- Laravel, PHP, MySQL / MariaDB, Linux administration, shell scripting, API development, production deployment
- Comfortable
- Livewire, Alpine, Tailwind, Shopify GraphQL, Python (Django, Flask), Symfony, Azure Data Factory, AWS S3, CI/CD pipelines (GitHub Actions)
- Earlier career
- WordPress, WooCommerce, Shopify Liquid, Vue.js, jQuery
- Learning
- Rust (not proficient yet)
New stack? Fine. I hadn't heard of Symfony before a Symfony project landed on my desk, and the first phase shipped in under a week. I picked up a half-built Flask and Laravel project mid-flight and finished it. These days I'm learning Rust, aiming to be reasonably proficient in a few months.
BSc Computer Science, Forman Christian College, graduated 2026
Let's talk
Full-time, contract or a one-off project: all fine. Tell me what you're building, and expect a few good questions back. Based in Lahore (UTC+5), working remotely.