About β Ahsan Mahmood, full-stack developer in Lahore
Who I am, what I build, and how I work. Eight years shipping production software, twenty-three products live across web, Google Play and the extension stores, and every figure on this page carries its source.
I wire products up to models. I do not train them.
I build interfaces and I care about them. Brand design and illustration are somebody else's craft.
Worth being explicit about
MongoDB and GraphQL. Both are real on my CV and both belong to the Perkforce years β I do not build new products on either.
Yes. Since March 2026 I have been independent, working on my own products full time and taking client projects alongside them. Fixed price, milestone, retainer or fractional β whichever fits the shape of the work.
- Are you available right now?
Because most of it is not mine to publish. The clients that are public β through my CV, npm and the app stores β appear on the projects page with the work attached. An anonymous β15+ happy clientsβ badge proves nothing, so it is not here.
- Why is there no client list on this page?
Things people ask me first
No. I have no Apple Developer account, so nothing I build has gone to the App Store. Android and the web are the surfaces I can genuinely take through to release.
Yes, and it is a common engagement. It starts with an audit β code quality, security rules, performance, dependency health β and produces a prioritised roadmap before a line is changed.
Can you take over a codebase somebody else wrote?
Both. I have led delivery for a small team as a project lead, and I have shipped entire products alone. On a team I am most useful owning a vertical slice end to end rather than a layer across everything.
- Do you work with teams, or only solo?
Pakistan Standard Time, UTC+5. I work asynchronously by default and routinely schedule calls across US, UK, EU and Australian hours.
- What time zone are you in?
- Hi β I'm Ahsan Mahmood.
I'm a full-stack software developer in Lahore, Pakistan. I have been shipping production software since January 2018 β five companies, and since March 2026 my own. I build the whole product: the data model, the security rules, the interface, the Android packaging, the store submission, and the documentation somebody has to read afterwards.
- See the work
- Start a conversation
The person who modelled the data is the person who wrote the security rules, packaged the Android build and answered the store reviewer. Nothing is handed over a wall, so nothing falls off it.
- One person accountable for all of it
Full IP transfer, documentation that matches the code, and a handover that assumes I am not available. If the project only runs while I am on it, I have not finished.
- Leave it maintainable by someone else
How I work
In the store listing, in the docs, and on this page. Every limitation you read here was cheaper to write down than to discover.
A green build is not evidence that a feature works. I exercise the actual flow as a real, non-admin user β which is how the interesting failures get found, because they are invisible to every static check.
- Run it before calling it done
A fixed number attached to an unscoped brief is a number one of us is going to be unhappy about. The call is free and it is where I say whether I am the right person.
- Scoped on a call, before it is quoted
- Read the longer story
The projects page has everything with a link that resolves. If you would rather just describe the problem, the contact form goes straight to me and I reply within one business day.
Have a look, or say hello
- See the projects
- Delivered since 2018
- the numbered CV list
- Professional experience
- since January 2018
Four numbers, four sources
These are the only figures I publish. Two of them are re-probed before every deploy, because they move β and a stale number is the easiest thing on a page to disprove.
- Live today
- web, Play and the extension stores
- Maintained on npm
- registry probe, 2026-08-01
- Asynchronous by default
- Available for work
- Where I am and how I work
- Not taking new work right now
- Read the longer biography
Google Play listings, all packaged with Capacitor from the same web codebase rather than rewritten. That covers the parts people forget: the merged manifest audit, the Data Safety form, the ten App-content declarations, and a listing written to pass review rather than to sell.
There is no iOS half. I have no Apple Developer account, so nothing here has ever shipped to the App Store β and a portfolio that claims a platform it has not shipped to is the first thing a client finds out about.
Documentation sites, one per product that needs one. They are not an afterthought here β a package nobody can work out how to install is a package nobody uses, and the docs site is usually the thing that decides which of those it becomes.
Browser-extension listings across the Chrome Web Store, Firefox Add-ons and Edge Add-ons β Manifest V3, packaged three times from one repository and submitted three times. No remote code, which is both the store rule and the reason these keep passing review.
Where it ships
The same codebase, packaged five ways. Counts come from the July 2026 probe and are re-verified before publish.
Packages published to npm under the `aoneahsan` maintainer.
One caveat I would rather state than have found: that count is what the registry returns for the maintainer, so it includes a package scoped to a client organisation and two legacy pairs that were renamed rather than replaced.
Web applications live today β hiring and health platforms, a laboratory information system, a link-management SaaS, exam preparation, tax compliance, a Slack archiver and several developer toolboxes. React and TypeScript throughout, deployed to Firebase Hosting or Cloudflare Pages.
What I reach for
Where a product needs a server it is Laravel or Cloudflare Workers. Where it needs file storage or transactional email it is FilesHub, a platform I built and operate myself. Where it needs a database it is usually Firebase or Supabase on a free tier, with the query budget treated as a real constraint rather than a formality β an unbounded list read is a bug on the first day and an outage on the day the collection grows.
No iOS. There is no Apple Developer account, so I do not ship to the App Store and do not claim to.
No feature that needs a paid API in the middle of it, unless you are paying for that API and know you are.
No architecture that only works while traffic is small β the free tier is a budget, not an excuse.
A product should cost nothing to run. Free-tier infrastructure, work done in the browser wherever the browser can do it, and no paid service in the critical path. That is not frugality for its own sake β it is what makes it possible for one person to keep twenty-three things alive at the same time without a monthly bill that grows faster than the products do.
It rules things out, and I would rather say which:
- How an engagement usually starts
With a call, before anything is quoted. I would rather tell you on that call that I am the wrong person for the work than discover it together in month two. When I am the right person, you get one accountable person β whoever wrote the security rules is also the one who answers when the store listing is rejected.
What I actually do
If you only read one section, read this one. Everything below it is evidence for what it claims.
That is a claim about maintenance more than about speed. I still maintain products I built years ago, which is a very effective way of finding out which decisions were actually good.
Most of what I ship follows one pattern: a single React and TypeScript codebase that becomes a web app, an Android app and a browser extension. Not three teams and three repositories that drift β one codebase, packaged three ways with Capacitor and Manifest V3, so a fix lands everywhere at once and a feature is not silently missing on the surface nobody checked.
The parts that usually get skipped are the parts I care about: honest store listings, documentation somebody can follow, and links that resolve.
One React and TypeScript codebase becomes a web app, an Android app and a browser extension. {{liveProjects}} of them are live right now. Based in Lahore, Pakistan β working with clients worldwide.
Full-stack developer. I ship products, not prototypes.
https://aoneahsan.com/about