Iqtidar Hadi

Full Stack Developer · Laravel · Python · React · Livewire · Cybersecurity · Peshawar, Pakistan

I build secure, scalable full-stack applications across Laravel, PHP, Python, React, and Livewire — from REST APIs and dashboards to automation and application security. I focus on clean architecture, strong authentication and authorization, secure APIs, and responsible vulnerability research.

7+
Years with Laravel
40%
Faster key queries
4
Production teams
Gov
Live nationwide system
// experience

Professional experience

Backend delivery across SaaS, commerce, and public-sector systems — with clear ownership from design through deployment.

POST/experience/softech-business-services LIVE

Laravel Developer

Softech Business Services · Remote · Jan 2023 – Present
  • Build and maintain Laravel 10/11 full-stack applications supporting day-to-day business operations.
  • Develop interactive interfaces with Livewire, React, JavaScript, and AJAX alongside Laravel backends.
  • Use Python for automation, API integration, security-focused scripts, and repeatable technical workflows.
  • Design secure REST APIs consumed by web and mobile clients.
  • Implement authentication with Sanctum, Passport, and JWT — with least-privilege access in mind.
  • Apply secure coding practices against common web risks (injection, XSS, CSRF, broken auth).
  • Optimize MySQL queries and schema — cutting load times by ~40% on critical modules.
  • Deploy and operate apps on VPS/cPanel with Git-based release workflows.
POST/experience/cartlow 200 OK · closed

Software Engineer

Cartlow · Lahore, Pakistan · Jan 2022 – Dec 2022
  • Shipped SaaS inventory modules with product, design, and engineering stakeholders.
  • Built Trade-in and Buyback flows with Laravel, PHP, MySQL, and AJAX.
  • Integrated third-party payment gateways and logistics APIs.
  • Delivered sprint work on schedule without sacrificing code quality.
POST/experience/kp-govt-innovation-fellowship 200 OK · closed

Web Application Developer

KP Govt Innovation Fellowship · Peshawar, Pakistan · Feb 2021 – Dec 2021
  • Designed and built the Mercy Petition System for the Inspector General of Police (IGP) using PHP, MySQL, and Laravel.
  • Led deployment and maintenance; delivered within a 6-month timeline for a live government workflow.
POST/experience/bitedefender-coding-solution 200 OK · closed

Web Developer

BiteDefender Coding Solution · Jan 2019 – Jan 2021
  • Delivered responsive web applications and CMS sites for client businesses.
  • Maintained production codebases and resolved client-reported issues to improve stability.
// selected_work

Key projects

Systems I can walk through end-to-end — architecture, data model, auth, and operational impact.

Operations · Live data

RTS Dashboard

A real-time status dashboard for monitoring operational KPIs, live activity, and exception alerts in one place — built so managers can act without waiting for manual reports.

  • Live widgets for status, volume, and trend signals
  • Role-based views for ops, supervisors, and admins
  • Filterable history with export-ready summaries
  • Optimized queries for fast refresh under load
LaravelMySQLJavaScriptCharts / AJAX
Delivery · Collaboration

Project Management System

An internal project management platform for planning work, assigning ownership, and tracking progress from kickoff to delivery — replacing scattered sheets and chat updates.

  • Projects, milestones, tasks, and assignees
  • Status workflows with due dates and priorities
  • Team visibility: boards, activity, and progress %
  • Notifications for assignments and blockers
LaravelPHPMySQLREST API
Public sector

Mercy Petition System

Government workflow system for processing death-sentence mercy petitions submitted to the President and Governor — built for the Inspector General of Police, Pakistan.

  • Structured case intake and routing
  • Role-based processing for official users
  • Deployed and maintained in production
LaravelPHPMySQL
Commerce · Inventory

Trade-in Module

SaaS inventory sourcing module that improved conversion and partner intake — covering evaluation, intake, and downstream inventory updates.

  • Partner-facing trade-in workflows
  • Inventory conversion tracking
LaravelPHPMySQLAJAX
Commerce · Revenue

Buyback System

Buyback pipeline for purchasing client devices/products, managing refurbishment status, and feeding resale inventory for revenue recovery.

  • Purchase → refurbish → resell lifecycle
  • Ops-friendly status tracking
LaravelJavaScriptjQuery
Automation · Security

Python Security & Automation

Python-based automation for API workflows, security-focused tooling, data processing, and repeatable web application assessment tasks.

  • Security and web automation scripts
  • REST API integration and testing
  • Data processing and reporting workflows
  • Reusable command-line tooling
PythonREST APIAutomationSecurity
Frontend · Reactive UI

React & Livewire Applications

Interactive web interfaces using React and Laravel Livewire, connected to secure Laravel backends and REST APIs for responsive product experiences.

  • Reusable React components and UI flows
  • Livewire-powered Laravel interfaces
  • AJAX/API-driven interactions
  • Authentication and permission-aware UI
ReactLivewireLaravelJavaScript
// cybersecurity

Security mindset in production code

Application security woven into Laravel delivery — not bolted on after launch. Focused on real risks teams ship every week.

01 · AppSec

Secure application design

Input validation, output encoding, CSRF protection, and framework-safe patterns so common OWASP risks never become production incidents.

02 · AuthN / AuthZ

Authentication & access control

Sanctum, Passport, and JWT setups with role-based permissions — so users only reach the data and actions they are allowed to use.

03 · API security

Hardened REST APIs

Token hygiene, rate awareness, authorization checks on every sensitive endpoint, and clear separation between public and protected routes.

04 · Disclosure

Responsible vulnerability reporting

Experience identifying web application issues and reporting them through ethical disclosure channels — clear impact, clear reproduction, professional follow-up.

05 · Data protection

Safer data handling

Careful handling of credentials, hashed passwords, environment secrets, and least-privilege database access in Laravel deployments.

06 · Ops hygiene

Server & delivery basics

HTTPS, secure headers where applicable, dependency awareness, and disciplined VPS/cPanel releases that reduce exposure from misconfiguration.

07 · Web Security

Web application security testing

Security-focused review of authentication, authorization, input handling, business logic, APIs, and common OWASP risks in web applications.

08 · Vulnerability Research

Vulnerability assessment & reporting

Responsible research with reproducible proof of concept, impact analysis, remediation guidance, and professional disclosure to affected organizations.

09 · API / Access Control

API & authorization testing

Review of protected endpoints, role boundaries, object-level authorization, session/token handling, and privilege separation to identify access-control weaknesses.

10 · Secure Development

Security-aware development

Security integrated into development through validation, output encoding, secure authentication, least privilege, secret management, logging, and dependency awareness.

Principle · Build features that are hard to abuse: validate early, authorize always, log carefully, and disclose responsibly when issues are found.
// stack

Skills & tools

Full-stack and security-focused toolkit for modern web applications, APIs, automation, and production systems.

Backend

Laravel 8–11PHP 7/8 REST API designQueues & jobs

Auth & security

SanctumPassportJWT OWASP Top 10Secure coding RBACCSRF / XSS awareness Responsible disclosure

Python & automation

Python scriptingWeb automation Security toolingData processing API automation

Data & integrations

MySQLPayment gatewaysThird-party APIs

Frontend

JavaScriptjQuery AJAXHTML5CSS3

Cybersecurity

OWASP Top 10Web Security API SecurityAuth / Access Control XSS / CSRFSecurity Testing Vulnerability ResearchResponsible Disclosure

Tools & delivery

Git / GitHubCI/CDDocker VPS / cPanel

Product collaboration

Requirements analysisAgile / sprintsProcess improvement
// education

Education & languages

BSCS — Computer Science
Abdul Wali Khan University, Mardan, Pakistan · 2014 – 2019
CGPA 3.2 / 4.0
EnglishUrduPashto
// contact

Let's build something reliable.

Open to remote Full Stack, Laravel, Python, React, Livewire, backend, and cybersecurity-focused roles, plus focused freelance projects.

POST /contact HTTP/1.1 → awaiting your request