<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Afee Muhammod Wafy</title>
    <description>The latest articles on DEV Community by Afee Muhammod Wafy (@afeemuhammodwafy).</description>
    <link>https://dev.to/afeemuhammodwafy</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4090777%2Fbc7b176a-4c53-4c93-8641-da25f673fff9.jpg</url>
      <title>DEV Community: Afee Muhammod Wafy</title>
      <link>https://dev.to/afeemuhammodwafy</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/afeemuhammodwafy"/>
    <language>en</language>
    <item>
      <title>Building Wafyro Software: Why We’re Focused on Practical Software &amp; Web Applications</title>
      <dc:creator>Afee Muhammod Wafy</dc:creator>
      <pubDate>Sun, 04 Oct 2026 06:03:34 +0000</pubDate>
      <link>https://dev.to/afeemuhammodwafy/building-wafyro-software-why-were-focused-on-practical-software-web-applications-3o0n</link>
      <guid>https://dev.to/afeemuhammodwafy/building-wafyro-software-why-were-focused-on-practical-software-web-applications-3o0n</guid>
      <description>&lt;p&gt;Software does not always need to be complicated to be useful.&lt;/p&gt;

&lt;p&gt;Sometimes, the best software is the one that solves a small, real-world problem reliably—and stays out of the user's way.&lt;/p&gt;

&lt;p&gt;That idea is one of the reasons I’m building &lt;strong&gt;Wafyro Software&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Wafyro Software is a software development initiative focused on building practical &lt;strong&gt;software products and web applications&lt;/strong&gt; that solve real problems rather than adding complexity for the sake of complexity.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Wafyro Software?
&lt;/h2&gt;

&lt;p&gt;There are countless software products that are technically impressive but unnecessarily complicated for their target users.&lt;/p&gt;

&lt;p&gt;Our approach is different.&lt;/p&gt;

&lt;p&gt;We want to build software around a few principles:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Solve a real problem first.&lt;/li&gt;
&lt;li&gt;Keep the user experience simple.&lt;/li&gt;
&lt;li&gt;Make important data understandable and portable.&lt;/li&gt;
&lt;li&gt;Minimize unnecessary dependencies.&lt;/li&gt;
&lt;li&gt;Think about privacy from the beginning.&lt;/li&gt;
&lt;li&gt;Build systems that can evolve without becoming difficult to maintain.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This philosophy became much clearer while building our first public application: &lt;strong&gt;Hishab Ledger&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Hishab Ledger: A Small Problem With Real Users
&lt;/h2&gt;

&lt;p&gt;Hishab Ledger is an Android application designed for personal and small-business &lt;strong&gt;hisab, due, and payment tracking&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The problem is simple.&lt;/p&gt;

&lt;p&gt;People often need to remember:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Who owes them money&lt;/li&gt;
&lt;li&gt;How much is currently due&lt;/li&gt;
&lt;li&gt;When a payment was made&lt;/li&gt;
&lt;li&gt;How much has been added over time&lt;/li&gt;
&lt;li&gt;What the transaction history looks like&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A spreadsheet can solve some of these problems. A generic accounting system can solve many more.&lt;/p&gt;

&lt;p&gt;But both can be unnecessarily complicated for someone who simply wants to track their everyday dues.&lt;/p&gt;

&lt;p&gt;So we focused on the smallest useful system.&lt;/p&gt;

&lt;h2&gt;
  
  
  Offline-First by Design
&lt;/h2&gt;

&lt;p&gt;One of the most important decisions in Hishab Ledger was making the core experience &lt;strong&gt;offline-first&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The application does not require an account for its core functionality. Records are kept locally on the device, allowing users to manage their data without depending on a network connection.&lt;/p&gt;

&lt;p&gt;This changes how we think about application architecture.&lt;/p&gt;

&lt;p&gt;Instead of assuming:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;User → Internet → Server → Database&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;the application can work around:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;User → Local data → Local operations&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That makes the basic experience more predictable.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;No connection?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The core ledger still works.&lt;/p&gt;

&lt;p&gt;This is particularly important for applications that deal with everyday records where availability should not depend on network connectivity.&lt;/p&gt;

&lt;h2&gt;
  
  
  Data Should Be Portable
&lt;/h2&gt;

&lt;p&gt;Local storage alone is not enough.&lt;/p&gt;

&lt;p&gt;If important data exists only inside an application, users can eventually become dependent on that application.&lt;/p&gt;

&lt;p&gt;That's why Hishab Ledger includes data portability features such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;JSON backup and restore&lt;/li&gt;
&lt;li&gt;Replace or Merge restore workflows&lt;/li&gt;
&lt;li&gt;Full CSV export&lt;/li&gt;
&lt;li&gt;Shop-wise CSV export&lt;/li&gt;
&lt;li&gt;PDF statements&lt;/li&gt;
&lt;li&gt;Shareable transaction summaries&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The idea is simple:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Your data should remain useful outside the UI that created it.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This is a principle we want to carry into future Wafyro Software products as well.&lt;/p&gt;

&lt;h2&gt;
  
  
  Keeping the Ledger Simple
&lt;/h2&gt;

&lt;p&gt;The application revolves around a relatively small set of concepts.&lt;/p&gt;

&lt;h3&gt;
  
  
  People and Shops
&lt;/h3&gt;

&lt;p&gt;Users can maintain records for people and shops and keep optional contact information.&lt;/p&gt;

&lt;h3&gt;
  
  
  Due and Payment Transactions
&lt;/h3&gt;

&lt;p&gt;A transaction can represent either money added to the due or a payment.&lt;/p&gt;

&lt;p&gt;Each transaction can include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Amount&lt;/li&gt;
&lt;li&gt;Date and time&lt;/li&gt;
&lt;li&gt;Optional note&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Opening Balance
&lt;/h3&gt;

&lt;p&gt;Real-world records rarely start at zero.&lt;/p&gt;

&lt;p&gt;An opening balance allows users to begin with an existing outstanding amount instead of reconstructing their entire history just to get the current balance right.&lt;/p&gt;

&lt;h3&gt;
  
  
  Statements
&lt;/h3&gt;

&lt;p&gt;A shop's current position can be turned into a PDF statement or a shareable summary.&lt;/p&gt;

&lt;p&gt;The goal is not to expose every internal detail to the user.&lt;/p&gt;

&lt;p&gt;The goal is to make the information useful when they need it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Small Features Matter
&lt;/h2&gt;

&lt;p&gt;Some of the most useful features aren't necessarily the most impressive ones.&lt;/p&gt;

&lt;p&gt;Hishab Ledger includes things such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Undo after deletion&lt;/li&gt;
&lt;li&gt;Recently Deleted records&lt;/li&gt;
&lt;li&gt;Local reminders and notifications&lt;/li&gt;
&lt;li&gt;PIN and biometric app lock&lt;/li&gt;
&lt;li&gt;Today's transaction summary&lt;/li&gt;
&lt;li&gt;Search&lt;/li&gt;
&lt;li&gt;Multiple shops&lt;/li&gt;
&lt;li&gt;Quick phone actions&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These features come from thinking about actual usage rather than simply building a feature checklist.&lt;/p&gt;

&lt;p&gt;For example, deletion is not just a database operation.&lt;/p&gt;

&lt;p&gt;From a user's perspective:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"I deleted something by mistake."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's why undo and Recently Deleted matter.&lt;/p&gt;

&lt;p&gt;Good software often comes from noticing these small moments.&lt;/p&gt;

&lt;h2&gt;
  
  
  Privacy as an Architectural Decision
&lt;/h2&gt;

&lt;p&gt;Privacy is easier to talk about than to implement.&lt;/p&gt;

&lt;p&gt;For applications dealing with financial or personal records, the question should be considered at the architecture level:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Where does the data actually go?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;With an offline-first design, Hishab Ledger can keep its core records locally on the user's device rather than requiring a remote account-based architecture for basic usage.&lt;/p&gt;

&lt;p&gt;That doesn't magically solve every security problem.&lt;/p&gt;

&lt;p&gt;Local data still needs appropriate protection, backup handling, device security, and careful application design.&lt;/p&gt;

&lt;p&gt;But reducing unnecessary data transmission is a meaningful starting point.&lt;/p&gt;

&lt;h2&gt;
  
  
  What We’re Learning
&lt;/h2&gt;

&lt;p&gt;Building a small application has taught us something important:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Constraints improve software.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;When you decide that an application should be:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Simple&lt;/li&gt;
&lt;li&gt;Offline-first&lt;/li&gt;
&lt;li&gt;Private&lt;/li&gt;
&lt;li&gt;Portable&lt;/li&gt;
&lt;li&gt;Easy to understand&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;every architectural decision becomes more meaningful.&lt;/p&gt;

&lt;p&gt;You have to ask whether a feature actually improves the product.&lt;/p&gt;

&lt;p&gt;You have to think about failure cases.&lt;/p&gt;

&lt;p&gt;You have to consider how users recover from mistakes.&lt;/p&gt;

&lt;p&gt;And you have to decide what should happen when the network, server, or external dependency is unavailable.&lt;/p&gt;

&lt;p&gt;These are not just product decisions.&lt;/p&gt;

&lt;p&gt;They are engineering decisions.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Wafyro Software Is Going
&lt;/h2&gt;

&lt;p&gt;Hishab Ledger is only one part of what we want to build.&lt;/p&gt;

&lt;p&gt;The broader direction of &lt;strong&gt;Wafyro Software&lt;/strong&gt; is software products and web applications that are practical, focused, and engineered around real user needs.&lt;/p&gt;

&lt;p&gt;That includes experimenting with different types of software, understanding how people actually use them, and gradually building systems that are more capable without becoming unnecessarily complex.&lt;/p&gt;

&lt;p&gt;We're particularly interested in the intersection of:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Software engineering&lt;/li&gt;
&lt;li&gt;Web applications&lt;/li&gt;
&lt;li&gt;Developer tools&lt;/li&gt;
&lt;li&gt;Privacy-conscious products&lt;/li&gt;
&lt;li&gt;Practical business software&lt;/li&gt;
&lt;li&gt;Offline-first systems&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal is not to build everything.&lt;/p&gt;

&lt;p&gt;The goal is to build useful things well.&lt;/p&gt;

&lt;h2&gt;
  
  
  Building in Public
&lt;/h2&gt;

&lt;p&gt;Wafyro Software is still growing.&lt;/p&gt;

&lt;p&gt;That means there will be experiments that work, experiments that fail, architectural decisions that need to be revisited, and products that evolve over time.&lt;/p&gt;

&lt;p&gt;We'll continue sharing what we learn through the products we build and the engineering problems behind them.&lt;/p&gt;

&lt;p&gt;Because ultimately, software development is not just about writing code.&lt;/p&gt;

&lt;p&gt;It's about understanding a problem deeply enough to build something that people can actually use.&lt;/p&gt;

&lt;p&gt;And that's the direction we're taking with &lt;strong&gt;Wafyro Software&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Build practical.&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Build thoughtfully.&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Keep improving.&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>software</category>
      <category>startup</category>
      <category>android</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Building Hishab Ledger: Designing an Offline-First Personal Ledger with Kotlin and Jetpack Compose</title>
      <dc:creator>Afee Muhammod Wafy</dc:creator>
      <pubDate>Sun, 27 Sep 2026 11:44:01 +0000</pubDate>
      <link>https://dev.to/afeemuhammodwafy/building-hishab-ledger-designing-an-offline-first-personal-ledger-with-kotlin-and-jetpack-compose-2o98</link>
      <guid>https://dev.to/afeemuhammodwafy/building-hishab-ledger-designing-an-offline-first-personal-ledger-with-kotlin-and-jetpack-compose-2o98</guid>
      <description>&lt;h1&gt;
  
  
  Building Hishab Ledger: An Offline-First Personal Ledger with Kotlin and Jetpack Compose
&lt;/h1&gt;

&lt;p&gt;A software project does not always begin with a technical problem.&lt;/p&gt;

&lt;p&gt;Sometimes, it starts with a very ordinary situation.&lt;/p&gt;

&lt;p&gt;For me, it started with a disagreement over a grocery shop's &lt;strong&gt;baki&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The shopkeeper told me that I had a certain amount outstanding. I remembered the amount differently. The shopkeeper had a handwritten ledger, while I was relying mostly on memory and previous transactions.&lt;/p&gt;

&lt;p&gt;The problem was not necessarily the accuracy of either side.&lt;/p&gt;

&lt;p&gt;The bigger problem was &lt;strong&gt;visibility&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The person maintaining the ledger had a record. The customer did not have an equally convenient way to maintain their own record.&lt;/p&gt;

&lt;p&gt;That small observation became the starting point for &lt;strong&gt;Hishab Ledger&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  What Is Hishab Ledger?
&lt;/h2&gt;

&lt;p&gt;Hishab Ledger is an Android application designed for tracking &lt;strong&gt;personal dues, payments, and balances&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The product is intentionally focused on one simple use case:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Keep a clear record of how much you owe, what you have already paid, and what your current balance is across different shops.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Users can add multiple shops as separate records. Each shop can have an opening balance, followed by individual due and payment transactions.&lt;/p&gt;

&lt;p&gt;The core balance calculation is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Current Balance
= Opening Balance
+ Total Due
- Total Payments
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Each transaction can also contain:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Amount&lt;/li&gt;
&lt;li&gt;Transaction type&lt;/li&gt;
&lt;li&gt;Optional note&lt;/li&gt;
&lt;li&gt;Exact date and time&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal was not to build another full accounting system.&lt;/p&gt;

&lt;p&gt;It was to build a small, focused tool for an everyday problem: &lt;strong&gt;helping customers maintain their own record of baki instead of depending entirely on memory, notebooks, or someone else's ledger.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Why Offline-First?
&lt;/h2&gt;

&lt;p&gt;One of the earliest decisions I made was that Hishab Ledger should work without an account, backend, or internet connection.&lt;/p&gt;

&lt;p&gt;For this particular product, the core operation does not require a server.&lt;/p&gt;

&lt;p&gt;A user should be able to open the application, check a balance, record a payment, or add a due even when there is no network connection.&lt;/p&gt;

&lt;p&gt;That led to an &lt;strong&gt;offline-first, local-only architecture&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The application does not depend on a remote database for its primary functionality.&lt;/p&gt;

&lt;p&gt;This also gives the product a clear privacy model: the user's ledger data remains on the device unless the user explicitly chooses to export or back it up.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why JSON Instead of Room or SQLite?
&lt;/h2&gt;

&lt;p&gt;This was one of the more deliberate technical decisions in the project.&lt;/p&gt;

&lt;p&gt;For a larger Android application, a database abstraction such as Room can be an excellent choice.&lt;/p&gt;

&lt;p&gt;For Hishab Ledger, however, I wanted to keep the storage layer small and straightforward.&lt;/p&gt;

&lt;p&gt;The application uses an app-private JSON file for its local data.&lt;/p&gt;

&lt;p&gt;The main data structures are essentially:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Shop
├── id
├── name
├── phone
├── address
└── createdAt

Transaction
├── id
├── shopId
├── amount
├── type
├── note
└── timestamp
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Transaction types include:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;DUE
PAYMENT
OPENING_BALANCE
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The application can reconstruct the current balance from these records rather than maintaining a separate balance value that could become inconsistent with the transaction history.&lt;/p&gt;

&lt;p&gt;This approach also made full backup and restoration simpler.&lt;/p&gt;

&lt;p&gt;The decision was not that JSON is universally better than a database. It was a deliberate choice for the scope and requirements of this particular application.&lt;/p&gt;




&lt;h2&gt;
  
  
  Building the UI with Jetpack Compose
&lt;/h2&gt;

&lt;p&gt;The Android UI was built using:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Kotlin&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Jetpack Compose&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Material 3&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Material Icons&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Android's modern document APIs&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The interface follows a relatively simple navigation model.&lt;/p&gt;

&lt;h3&gt;
  
  
  Home
&lt;/h3&gt;

&lt;p&gt;The home screen provides:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Total due&lt;/li&gt;
&lt;li&gt;Total number of shops&lt;/li&gt;
&lt;li&gt;Shop search&lt;/li&gt;
&lt;li&gt;Shop list&lt;/li&gt;
&lt;li&gt;Add Shop action&lt;/li&gt;
&lt;li&gt;Settings access&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Shop Details
&lt;/h3&gt;

&lt;p&gt;Each shop has its own details screen containing:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Current balance&lt;/li&gt;
&lt;li&gt;Add Due&lt;/li&gt;
&lt;li&gt;Add Payment&lt;/li&gt;
&lt;li&gt;View Summary&lt;/li&gt;
&lt;li&gt;Transaction history&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Transactions are displayed with their date and time, making the history useful as an actual record rather than just a running number.&lt;/p&gt;

&lt;h3&gt;
  
  
  Daily Summary
&lt;/h3&gt;

&lt;p&gt;The summary view provides:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Added Due&lt;/li&gt;
&lt;li&gt;Payments&lt;/li&gt;
&lt;li&gt;Net Change&lt;/li&gt;
&lt;li&gt;Current Due&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This keeps the application useful not only for checking a total balance, but also for understanding recent activity.&lt;/p&gt;




&lt;h2&gt;
  
  
  Backup and Restore
&lt;/h2&gt;

&lt;p&gt;Local storage introduces an important responsibility:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Users need a way to move or recover their data.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Hishab Ledger therefore includes JSON backup and restore functionality.&lt;/p&gt;

&lt;p&gt;The exported backup contains the application's structured data rather than simply exporting a visual report.&lt;/p&gt;

&lt;p&gt;The restore process supports two approaches:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Replace&lt;/strong&gt; existing data&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Merge&lt;/strong&gt; backup data with existing data&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This was particularly important because a local-only application should not make the user feel locked into a single device.&lt;/p&gt;

&lt;p&gt;There is also &lt;strong&gt;CSV export&lt;/strong&gt; for users who want their transaction data in a more universally accessible format.&lt;/p&gt;

&lt;p&gt;For individual records, Hishab Ledger also supports &lt;strong&gt;shop-wise statement export in PDF format&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Keeping the Interaction Model Simple
&lt;/h2&gt;

&lt;p&gt;A major part of the product design was deciding what &lt;strong&gt;not&lt;/strong&gt; to include.&lt;/p&gt;

&lt;p&gt;Hishab Ledger is not intended to replace full accounting software.&lt;/p&gt;

&lt;p&gt;There is no complex chart of accounts, inventory management system, payroll module, or business analytics dashboard.&lt;/p&gt;

&lt;p&gt;The interaction model is intentionally narrow:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Add a shop
    ↓
Set an opening balance
    ↓
Record dues
    ↓
Record payments
    ↓
Check the current balance
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That simplicity is part of the product rather than a limitation I wanted to hide.&lt;/p&gt;

&lt;p&gt;For a personal ledger, the user should not have to understand an accounting system before recording a payment.&lt;/p&gt;




&lt;h2&gt;
  
  
  Data Ownership and Privacy
&lt;/h2&gt;

&lt;p&gt;Another product requirement was keeping the user's records under their control.&lt;/p&gt;

&lt;p&gt;Hishab Ledger does not require:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;An account&lt;/li&gt;
&lt;li&gt;A cloud backend&lt;/li&gt;
&lt;li&gt;An internet connection for normal use&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The application stores its working data locally.&lt;/p&gt;

&lt;p&gt;Backup and export are user-controlled operations.&lt;/p&gt;

&lt;p&gt;The project also has a dedicated privacy policy explaining how the application handles local data and user-initiated exports.&lt;/p&gt;

&lt;p&gt;This approach fits the nature of the application: a personal record should remain useful without requiring a permanent online service behind it.&lt;/p&gt;




&lt;h2&gt;
  
  
  Product Website and Distribution
&lt;/h2&gt;

&lt;p&gt;The project eventually expanded beyond the Android application itself.&lt;/p&gt;

&lt;p&gt;I built a dedicated product website for Hishab Ledger with:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Product information&lt;/li&gt;
&lt;li&gt;Feature documentation&lt;/li&gt;
&lt;li&gt;Screenshots&lt;/li&gt;
&lt;li&gt;How-it-works documentation&lt;/li&gt;
&lt;li&gt;Download section&lt;/li&gt;
&lt;li&gt;Privacy policy&lt;/li&gt;
&lt;li&gt;About page&lt;/li&gt;
&lt;li&gt;Changelog&lt;/li&gt;
&lt;li&gt;Contact page&lt;/li&gt;
&lt;li&gt;SEO metadata&lt;/li&gt;
&lt;li&gt;Sitemap&lt;/li&gt;
&lt;li&gt;Robots configuration&lt;/li&gt;
&lt;li&gt;Responsive layouts&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The website is available at:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://hishabledger.amwafy.xyz" rel="noopener noreferrer"&gt;https://hishabledger.amwafy.xyz&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The Android application is also publicly distributed through APKPure:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://apkpure.com/p/com.afeemuhammodwafy.hishabledger" rel="noopener noreferrer"&gt;https://apkpure.com/p/com.afeemuhammodwafy.hishabledger&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The Android application and its website were treated as one product rather than two unrelated deliverables.&lt;/p&gt;




&lt;h2&gt;
  
  
  What I Learned from the Project
&lt;/h2&gt;

&lt;p&gt;Hishab Ledger was useful to me because it covered much more than UI development.&lt;/p&gt;

&lt;p&gt;The project involved several different layers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Problem Discovery
        ↓
Product Definition
        ↓
UX Design
        ↓
Android Development
        ↓
Local Data Architecture
        ↓
Backup &amp;amp; Restore
        ↓
Data Export
        ↓
PDF Generation
        ↓
Product Website
        ↓
Deployment &amp;amp; Distribution
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;One of the most important lessons was that &lt;strong&gt;scope is a technical decision&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It would have been easy to add accounts, cloud synchronization, a backend, notifications, analytics, and more.&lt;/p&gt;

&lt;p&gt;Instead, I kept asking:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Does this solve the problem Hishab Ledger was created to solve?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;If the answer was no, it did not automatically belong in the product.&lt;/p&gt;

&lt;p&gt;That helped keep the application lightweight and focused.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Bigger Idea Behind Hishab Ledger
&lt;/h2&gt;

&lt;p&gt;The interesting part of this project is not simply that it records numbers.&lt;/p&gt;

&lt;p&gt;It is the perspective from which the problem was approached.&lt;/p&gt;

&lt;p&gt;Digital ledger software often focuses on the person or business maintaining customer accounts.&lt;/p&gt;

&lt;p&gt;Hishab Ledger started from the other side of that relationship:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What if the customer wants to maintain their own record?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That small shift in perspective was enough to turn an everyday problem into a complete product.&lt;/p&gt;

&lt;p&gt;And that is probably my favorite part of building software:&lt;/p&gt;

&lt;p&gt;A simple real-world observation can eventually become a technical system with its own architecture, interface, documentation, and distribution strategy.&lt;/p&gt;




&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;Hishab Ledger is a relatively small application, but it gave me the opportunity to work across the entire product lifecycle.&lt;/p&gt;

&lt;p&gt;From identifying the problem to designing the interaction model, implementing the Android application, choosing a local data architecture, building backup and export workflows, creating the product website, and preparing the project for distribution.&lt;/p&gt;

&lt;p&gt;The project reinforced something I keep finding in software development:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Good products do not necessarily need more features. They need the right features for the problem they are solving.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Hishab Ledger started with a simple question:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;How can someone keep track of their own baki without depending on a notebook, memory, or someone else's ledger?&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The answer became &lt;strong&gt;Hishab Ledger&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  About the Creator
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Hishab Ledger was created by Afee Muhammod Wafy&lt;/strong&gt;, an independent developer focused on building practical software products and turning everyday problems into simple digital solutions.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Creator:&lt;/strong&gt; Afee Muhammod Wafy  &lt;/p&gt;




&lt;h2&gt;
  
  
  Hishab Ledger
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Offline Hisab &amp;amp; Due Ledger&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A focused, offline-first Android application for keeping personal dues, payments, and balances organized across different shops.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Product Website:&lt;/strong&gt; &lt;a href="https://hishabledger.amwafy.xyz" rel="noopener noreferrer"&gt;https://hishabledger.amwafy.xyz&lt;/a&gt;&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Download on APKPure:&lt;/strong&gt; &lt;a href="https://apkpure.com/p/com.afeemuhammodwafy.hishabledger" rel="noopener noreferrer"&gt;https://apkpure.com/p/com.afeemuhammodwafy.hishabledger&lt;/a&gt;&lt;/p&gt;

</description>
      <category>android</category>
      <category>kotlin</category>
      <category>jetpackcompose</category>
      <category>mobiledev</category>
    </item>
    <item>
      <title>About Me: Afee Muhammod Wafy</title>
      <dc:creator>Afee Muhammod Wafy</dc:creator>
      <pubDate>Sat, 12 Sep 2026 14:39:20 +0000</pubDate>
      <link>https://dev.to/afeemuhammodwafy/about-me-afee-muhammod-wafy-1me2</link>
      <guid>https://dev.to/afeemuhammodwafy/about-me-afee-muhammod-wafy-1me2</guid>
      <description>&lt;h1&gt;
  
  
  Hello, I'm Wafy — A Web Developer &amp;amp; Science Student
&lt;/h1&gt;

&lt;p&gt;My name is &lt;strong&gt;Afee Muhammod Wafy&lt;/strong&gt;, though most people call me &lt;strong&gt;Wafy&lt;/strong&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  Quick Facts &amp;amp; Identity
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Full Name:&lt;/strong&gt; Afee Muhammod Wafy&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Location:&lt;/strong&gt; Rangpur, Bangladesh&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Current Status:&lt;/strong&gt; Web Developer &amp;amp; Science Student&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Education:&lt;/strong&gt; Higher Secondary Certificate (HSC), Science&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Main Interests:&lt;/strong&gt; Web Development, Cybersecurity, Python, JavaScript, and AI&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I am a science student and self-taught web developer from Bangladesh. I build web applications, developer utilities, and security-focused tools while learning through practical work and experimentation.&lt;/p&gt;

&lt;p&gt;My interest in technology has always been closely connected to curiosity. I like understanding how things work, why they work the way they do, and what happens behind the scenes.&lt;/p&gt;

&lt;p&gt;Over time, that curiosity led me towards programming and web development.&lt;/p&gt;

&lt;h2&gt;
  
  
  A Little About Me
&lt;/h2&gt;

&lt;p&gt;I have always been interested in understanding things rather than simply using them.&lt;/p&gt;

&lt;p&gt;My background as a science student has influenced the way I approach problems. I naturally try to break a problem into smaller parts, understand the logic behind it, and then work towards a solution.&lt;/p&gt;

&lt;p&gt;Programming gave me a practical way to apply that way of thinking.&lt;/p&gt;

&lt;p&gt;When I started learning web development, I did not want to limit myself to tutorials and examples. I wanted to build things of my own and understand what happens when different parts of an application come together.&lt;/p&gt;

&lt;p&gt;That approach has led me to work with frontend development, backend development, APIs, databases, security concepts, and browser-based applications.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I Do
&lt;/h2&gt;

&lt;p&gt;My work mainly revolves around &lt;strong&gt;web development and practical software projects&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I have worked with technologies such as &lt;strong&gt;HTML, CSS, JavaScript, Python, Flask, C, Git, GitHub, Linux, PostgreSQL, and SQLAlchemy&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I have also worked with REST APIs, responsive interfaces, UI/UX layouts, API integration, and basic web security.&lt;/p&gt;

&lt;p&gt;I enjoy building projects where I can learn something by actually implementing it rather than only studying the theory.&lt;/p&gt;

&lt;p&gt;Some of the areas I have worked with include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Frontend Web Development&lt;/li&gt;
&lt;li&gt;Full-Stack Web Development&lt;/li&gt;
&lt;li&gt;Python &amp;amp; Flask&lt;/li&gt;
&lt;li&gt;JavaScript&lt;/li&gt;
&lt;li&gt;REST API Integration&lt;/li&gt;
&lt;li&gt;PostgreSQL &amp;amp; SQLAlchemy&lt;/li&gt;
&lt;li&gt;Responsive UI Development&lt;/li&gt;
&lt;li&gt;Web Security Basics&lt;/li&gt;
&lt;li&gt;Developer Utilities&lt;/li&gt;
&lt;li&gt;Git &amp;amp; GitHub&lt;/li&gt;
&lt;li&gt;Linux&lt;/li&gt;
&lt;li&gt;UI/UX Layouts&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Projects I Have Built
&lt;/h2&gt;

&lt;p&gt;Building projects has been one of the most important parts of my development journey.&lt;/p&gt;

&lt;p&gt;Each project has helped me explore a different area of development and understand how different technologies and concepts work together.&lt;/p&gt;

&lt;h3&gt;
  
  
  WafyShield
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;WafyShield&lt;/strong&gt; is a web security audit scanner focused on checking common security-related configurations of websites.&lt;/p&gt;

&lt;p&gt;It checks security-related configurations such as HTTPS, TLS, HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and cookie security attributes.&lt;/p&gt;

&lt;p&gt;The application generates a security score along with &lt;strong&gt;PASS, WARNING, and FAIL&lt;/strong&gt; results and provides recommendations for detected issues.&lt;/p&gt;

&lt;p&gt;While working on it, I explored concepts such as web security, request isolation, SSRF protection, security headers, redirects, and privacy-conscious data handling.&lt;/p&gt;

&lt;h3&gt;
  
  
  WafyURL
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;WafyURL&lt;/strong&gt; is a full-stack URL shortening and link management application built with &lt;strong&gt;Python, Flask, PostgreSQL, and SQLAlchemy&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;It includes features such as custom URL aliases, password-protected links, QR code generation, click analytics, visitor telemetry, and bulk processing.&lt;/p&gt;

&lt;p&gt;Working on this project gave me practical experience with backend development, database indexing, connection pooling, HTTP redirects, authentication flows, and handling analytics data without storing raw IP addresses.&lt;/p&gt;

&lt;p&gt;It also helped me understand how different parts of a backend application work together beyond simply creating routes and returning responses.&lt;/p&gt;

&lt;h3&gt;
  
  
  WafyDev
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;WafyDev&lt;/strong&gt; is a privacy-focused developer utility suite that works directly in the browser.&lt;/p&gt;

&lt;p&gt;It includes several browser-based tools such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Password Generator&lt;/li&gt;
&lt;li&gt;QR Generator&lt;/li&gt;
&lt;li&gt;Typing Test&lt;/li&gt;
&lt;li&gt;Study Timer&lt;/li&gt;
&lt;li&gt;Markdown Preview&lt;/li&gt;
&lt;li&gt;Note Taker&lt;/li&gt;
&lt;li&gt;Countdown&lt;/li&gt;
&lt;li&gt;Text Utilities&lt;/li&gt;
&lt;li&gt;Color Palette&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The project is built using &lt;strong&gt;HTML, CSS, and Vanilla JavaScript&lt;/strong&gt; without external libraries.&lt;/p&gt;

&lt;p&gt;While building it, I worked with browser-native APIs, local storage, client-side processing, Markdown sanitization, cryptographically secure random number generation, and timer accuracy.&lt;/p&gt;

&lt;p&gt;The project also gave me a better understanding of how much can be accomplished using the browser itself without depending heavily on external services.&lt;/p&gt;

&lt;h3&gt;
  
  
  AstroWafy
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;AstroWafy&lt;/strong&gt; is an educational astronomy project that integrates NASA's Open APIs to present astronomy-related information in a more accessible way.&lt;/p&gt;

&lt;p&gt;It includes features such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;NASA APOD API integration&lt;/li&gt;
&lt;li&gt;English and Bengali content&lt;/li&gt;
&lt;li&gt;Date-based navigation&lt;/li&gt;
&lt;li&gt;High-resolution image handling&lt;/li&gt;
&lt;li&gt;Download functionality&lt;/li&gt;
&lt;li&gt;Local caching&lt;/li&gt;
&lt;li&gt;Client-side content sanitization&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;While working on AstroWafy, I explored asynchronous JavaScript, API integration, &lt;code&gt;AbortController&lt;/code&gt;, Blob handling, local storage, and bilingual interfaces.&lt;/p&gt;

&lt;p&gt;It was also an opportunity to work with asynchronous requests and handle situations where users interact with an application faster than an API response can complete.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Building These Projects Has Taught Me
&lt;/h2&gt;

&lt;p&gt;Building projects has taught me things that are difficult to fully understand through theory alone.&lt;/p&gt;

&lt;p&gt;While working on different applications, I have encountered problems involving API requests, asynchronous operations, database queries, authentication, browser limitations, security considerations, performance, and user experience.&lt;/p&gt;

&lt;p&gt;Sometimes the solution was simple. Other times, it required reading documentation, testing different approaches, finding bugs, and understanding why something was not working.&lt;/p&gt;

&lt;p&gt;That process has become an important part of how I learn.&lt;/p&gt;

&lt;p&gt;I have also learned that making an application work is only one part of development. Details such as security, privacy, performance, error handling, usability, and maintainability also matter.&lt;/p&gt;

&lt;h2&gt;
  
  
  My Approach to Development
&lt;/h2&gt;

&lt;p&gt;I prefer learning by building.&lt;/p&gt;

&lt;p&gt;When I learn a new concept, I try to understand where it can actually be used and then apply it in a project.&lt;/p&gt;

&lt;p&gt;I also prefer using a simple solution when a simple solution is appropriate. I do not think every problem needs a complicated stack or a large number of dependencies.&lt;/p&gt;

&lt;p&gt;At the same time, working on different types of projects has helped me understand when a more structured approach is necessary.&lt;/p&gt;

&lt;p&gt;For me, development is not only about writing code. It is also about understanding the problem, choosing an appropriate approach, testing it, finding what does not work, and improving the result.&lt;/p&gt;

&lt;h2&gt;
  
  
  Security and Privacy
&lt;/h2&gt;

&lt;p&gt;Security has become an important area of interest in my development work.&lt;/p&gt;

&lt;p&gt;Some of my projects involve security-related functionality, including website security checks, password protection, secure random number generation, authentication, and privacy-conscious telemetry.&lt;/p&gt;

&lt;p&gt;Working on these projects has helped me understand that security is not something that should simply be considered at the end of development.&lt;/p&gt;

&lt;p&gt;Even a relatively small application can involve security considerations when it handles user input, authentication, external requests, or data.&lt;/p&gt;

&lt;h2&gt;
  
  
  Learning Through Building
&lt;/h2&gt;

&lt;p&gt;Alongside practical development, I have completed courses and certifications in areas related to technology.&lt;/p&gt;

&lt;p&gt;Some of my certifications include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Digital Skills: Artificial Intelligence&lt;/strong&gt; — FutureLearn &amp;amp; Accenture, 2026&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Intro to Cyber Security&lt;/strong&gt; — FutureLearn &amp;amp; The Open University, 2026&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Basics of Python&lt;/strong&gt; — UniAthena, 2026&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These have given me additional exposure to artificial intelligence, cybersecurity, and Python alongside my hands-on development work.&lt;/p&gt;

&lt;h2&gt;
  
  
  Education
&lt;/h2&gt;

&lt;p&gt;I am a science student at &lt;strong&gt;Gangachara Govt. College&lt;/strong&gt;, where I have been studying for my Higher Secondary Certificate (HSC).&lt;/p&gt;

&lt;p&gt;Before that, I completed my Secondary School Certificate (SSC) from &lt;strong&gt;Gangachara Govt. Model High School&lt;/strong&gt; in the Science group.&lt;/p&gt;

&lt;p&gt;My academic background and development work have existed alongside each other. Science has influenced my analytical way of thinking, while programming has given me a practical way to apply that thinking.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Person Behind the Code
&lt;/h2&gt;

&lt;p&gt;Technology is an important part of what I do, but I am still a student and a learner.&lt;/p&gt;

&lt;p&gt;I do not consider myself someone who already knows everything about development.&lt;/p&gt;

&lt;p&gt;There are still many concepts I am learning and many problems that take time to understand.&lt;/p&gt;

&lt;p&gt;What matters to me is the process of figuring them out.&lt;/p&gt;

&lt;p&gt;I enjoy starting with something I do not understand, experimenting with it, making mistakes, reading documentation, and eventually developing a clearer understanding of how it works.&lt;/p&gt;

&lt;p&gt;That curiosity remains one of the biggest reasons I enjoy programming.&lt;/p&gt;

&lt;h2&gt;
  
  
  Let's Connect
&lt;/h2&gt;

&lt;p&gt;If you'd like to know more about me and my work, you can find me here:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Portfolio:&lt;/strong&gt; &lt;a href="https://afeemuhammodwafy.com/" rel="noopener noreferrer"&gt;https://afeemuhammodwafy.com/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GitHub:&lt;/strong&gt; &lt;a href="https://github.com/afeemuhammodwafy1" rel="noopener noreferrer"&gt;https://github.com/afeemuhammodwafy1&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;LinkedIn:&lt;/strong&gt; &lt;a href="https://bd.linkedin.com/in/afeemuhammodwafy1" rel="noopener noreferrer"&gt;https://bd.linkedin.com/in/afeemuhammodwafy1&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




</description>
      <category>beginners</category>
      <category>career</category>
      <category>learning</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Build a Lightweight Web Security Scanner with Next.js: Meet WafyShield 🛡️</title>
      <dc:creator>Afee Muhammod Wafy</dc:creator>
      <pubDate>Wed, 09 Sep 2026 15:00:38 +0000</pubDate>
      <link>https://dev.to/afeemuhammodwafy/build-a-lightweight-web-security-scanner-with-nextjs-meet-wafyshield-2lp5</link>
      <guid>https://dev.to/afeemuhammodwafy/build-a-lightweight-web-security-scanner-with-nextjs-meet-wafyshield-2lp5</guid>
      <description>&lt;p&gt;Web security shouldn't be complicated, yet most enterprise-grade security auditing tools lock basic checks—such as SSL validation, security header analysis, and cookie security—behind confusing interfaces or expensive paid subscriptions.&lt;/p&gt;

&lt;p&gt;In order to address this, I created &lt;strong&gt;WafyShield&lt;/strong&gt;, a lightweight, fast, and serverless web security scanner designed to evaluate any public website in seconds with a strong focus on privacy and zero server-side storage.&lt;/p&gt;




&lt;h2&gt;
  
  
  🌐 Live Application &amp;amp; Source
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Live Application:&lt;/strong&gt; &lt;a href="https://shield.amwafy.xyz" rel="noopener noreferrer"&gt;shield.amwafy.xyz&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GitHub Repository:&lt;/strong&gt; &lt;a href="https://github.com/afeemuhammodwafy1/wafyshield" rel="noopener noreferrer"&gt;github.com/afeemuhammodwafy1/wafyshield&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  ⚡ Key Features
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;HTTPS &amp;amp; SSL Security Check:&lt;/strong&gt; Confirms whether a website properly enforces secure transport and inspects TLS certificate details (such as issuer, subject, and expiration dates).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Security Headers Checker:&lt;/strong&gt; Audits OWASP-recommended headers like HSTS, Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cookie Security Audit:&lt;/strong&gt; Detects cookies set by the server and verifies essential flags like &lt;code&gt;Secure&lt;/code&gt;, &lt;code&gt;HttpOnly&lt;/code&gt;, and &lt;code&gt;SameSite&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Instant Security Score &amp;amp; Risk Level:&lt;/strong&gt; Calculates a clear 0–100 score alongside an overall risk tier (Low, Medium, High, or Critical).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Remediation Guides:&lt;/strong&gt; Provides copy-pasteable fix recommendations for every warning or failed check.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Client-Side History &amp;amp; JSON Export:&lt;/strong&gt; Stores recent scan reports locally in the browser (&lt;code&gt;localStorage&lt;/code&gt;) and allows exporting full reports as JSON.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Responsive UI &amp;amp; Dark Mode:&lt;/strong&gt; A clean, green-themed interface built with a built-in dark/light mode toggle.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🛠️ Architecture &amp;amp; Tech Stack
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Framework:&lt;/strong&gt; Next.js 14 (Pages Router) for fast routing and serverless efficiency.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Styling:&lt;/strong&gt; Scoped CSS-in-JS (&lt;code&gt;styled-jsx&lt;/code&gt;) for clean component-level design without heavy UI libraries.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Backend &amp;amp; Compute:&lt;/strong&gt; Next.js Serverless API Routes utilizing Node.js native &lt;code&gt;fetch&lt;/code&gt; and &lt;code&gt;tls&lt;/code&gt; modules.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hosting:&lt;/strong&gt; Vercel Serverless Functions to ensure minimal latency and zero maintenance overhead.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  💡 Engineering Highlights
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Guarding Against SSRF (Server-Side Request Forgery)
&lt;/h3&gt;

&lt;p&gt;Since the server performs fetch requests on behalf of users, malicious inputs could potentially target internal or private network ranges (like &lt;code&gt;localhost&lt;/code&gt; or &lt;code&gt;127.0.0.1&lt;/code&gt;). To prevent this abuse, the URL normalizer strictly blocks private and local IP addresses before making any outbound network calls.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Direct TLS Socket Inspection
&lt;/h3&gt;

&lt;p&gt;Instead of relying on heavy third-party packages to inspect SSL certificates, WafyShield connects directly to port 443 using Node.js's built-in &lt;code&gt;tls&lt;/code&gt; module to extract certificate metadata securely and efficiently.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Lightweight In-Memory Caching
&lt;/h3&gt;

&lt;p&gt;To minimize redundant external requests and speed up response times for repeated lookups, an in-memory cache with a Time-To-Live (TTL) mechanism was implemented directly inside the serverless execution environment.&lt;/p&gt;




&lt;h2&gt;
  
  
  👨‍💻 About the Author
&lt;/h2&gt;

&lt;p&gt;Built by &lt;strong&gt;Afee Muhammod Wafy&lt;/strong&gt;.&lt;br&gt;&lt;br&gt;
For more projects, visit &lt;a href="https://afeemuhammodwafy.com" rel="noopener noreferrer"&gt;https://afeemuhammodwafy.com&lt;/a&gt; or connect on &lt;a href="https://github.com/afeemuhammodwafy1" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>nextjs</category>
      <category>webdev</category>
      <category>programming</category>
    </item>
    <item>
      <title>Building WafyURL: A High-Performance URL Shortener with Real-Time Analytics &amp; Security</title>
      <dc:creator>Afee Muhammod Wafy</dc:creator>
      <pubDate>Mon, 24 Aug 2026 09:14:37 +0000</pubDate>
      <link>https://dev.to/afeemuhammodwafy/building-wafyurl-a-high-performance-url-shortener-with-real-time-analytics-security-3n33</link>
      <guid>https://dev.to/afeemuhammodwafy/building-wafyurl-a-high-performance-url-shortener-with-real-time-analytics-security-3n33</guid>
      <description>&lt;p&gt;Link management shouldn't be complicated since most URL shorteners put essential features—such as custom slugs, password protection, and analytics—behind costly monthly paywalls.&lt;/p&gt;

&lt;p&gt;In order to deal with this, I created &lt;strong&gt;WafyURL&lt;/strong&gt;, a fast, secure and fully featured link management platform which is designed with a focus on speed and privacy.&lt;/p&gt;




&lt;h2&gt;
  
  
  🌐 Live Application &amp;amp; Source
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Live Application:&lt;/strong&gt; &lt;a href="https://url.amwafy.xyz" rel="noopener noreferrer"&gt;url.amwafy.xyz&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GitHub Repository:&lt;/strong&gt; &lt;a href="https://github.com/afeemuhammodwafy1/wafyurl" rel="noopener noreferrer"&gt;github.com/afeemuhammodwafy1/wafyurl&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  ⚡ Key Features
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Custom Slugs:&lt;/strong&gt; Create branded and easy-to-remember links in order to enhance click-through rates.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Detailed Analytics:&lt;/strong&gt; Monitor the total number of clicks, geographic location, device types, operating systems, and referrers without using heavy third-party trackers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Password Protection:&lt;/strong&gt; Include an optional password to secure sensitive destinations using SHA-256 encryption.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auto-Expiration:&lt;/strong&gt; Set links to expire by themselves after 1 hour, 24 hours, 7 days, or 30 days.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bulk Shortening:&lt;/strong&gt; Generate multiple shortened URLs at the same time with just one click.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;QR Code Generation:&lt;/strong&gt; Instantly generate downloadable QR codes on the client side for use in printing and marketing campaigns.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Destination Preview:&lt;/strong&gt; Extract Open Graph metadata on the server side to preview destination links before redirection.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  🛠️ Architecture &amp;amp; Tech Stack
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Backend:&lt;/strong&gt; Python 3.11 together with Flask, which offers a lightweight and modular routing base.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Database:&lt;/strong&gt; PostgreSQL running on Neon Serverless, managed via Flask-SQLAlchemy.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hosting &amp;amp; Compute:&lt;/strong&gt; Vercel Edge Serverless Functions to achieve minimal global latency.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Frontend:&lt;/strong&gt; Semantic HTML5, Vanilla JavaScript, and modern CSS3 Glassmorphism without employing heavy frameworks.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  💡 Engineering Highlights
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Optimising the Database for a Serverless Environment
&lt;/h3&gt;

&lt;p&gt;Since serverless backends tend to open and close connections rapidly, this can cause standard database pools to become exhausted. To make sure response times remain stable during traffic surges, persistent connection pooling, connection recycling, and automated pre-pings were configured.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Zero-Dependency Client Execution
&lt;/h3&gt;

&lt;p&gt;Key frontend features—such as dynamic QR code rendering and the collapsible FAQ accordion—are handled natively instead of relying on large third-party JavaScript libraries. This ensures minimal bundle sizes and faster Time-to-Interactive (TTI).&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Integrated Security &amp;amp; Abuse Prevention
&lt;/h3&gt;

&lt;p&gt;To ensure platform stability, a sliding-window rate limiter based on IP addresses prevents spam and brute-force requests. Furthermore, password-protected endpoints verify SHA-256 hashes prior to executing any redirect logic.&lt;/p&gt;




&lt;h2&gt;
  
  
  👨‍💻 About the Author
&lt;/h2&gt;

&lt;p&gt;Built by &lt;strong&gt;Afee Muhammod Wafy&lt;/strong&gt;.&lt;br&gt;&lt;br&gt;
For more projects, visit &lt;a href="https://afeemuhammodwafy.com/" rel="noopener noreferrer"&gt;https://afeemuhammodwafy.com/&lt;/a&gt; or connect on &lt;a href="https://github.com/afeemuhammodwafy1" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>python</category>
      <category>flask</category>
      <category>webdev</category>
      <category>postgres</category>
    </item>
    <item>
      <title>Why I Built WafyDev: A Zero-Dependency, 100% Client-Side Developer Suite</title>
      <dc:creator>Afee Muhammod Wafy</dc:creator>
      <pubDate>Sun, 23 Aug 2026 17:10:11 +0000</pubDate>
      <link>https://dev.to/afeemuhammodwafy/why-i-built-wafydev-a-zero-dependency-100-client-side-developer-suite-1o9m</link>
      <guid>https://dev.to/afeemuhammodwafy/why-i-built-wafydev-a-zero-dependency-100-client-side-developer-suite-1o9m</guid>
      <description>&lt;p&gt;Every developer knows the struggle of having twenty different browser tabs open just for small daily tasks: generating a quick QR code, formatting a snippet of text, testing typing speed, or checking Markdown rendering. Most existing online tools are bloated with intrusive ads, take ages to load, or send unnecessary requests to external servers.&lt;/p&gt;

&lt;p&gt;To solve this, I built &lt;strong&gt;&lt;a href="https://dev.amwafy.xyz" rel="noopener noreferrer"&gt;WafyDev&lt;/a&gt;&lt;/strong&gt;—a clean, fast, and completely free developer toolbox packed with 9 essential utilities.&lt;/p&gt;




&lt;h3&gt;
  
  
  Why I Built WafyDev
&lt;/h3&gt;

&lt;p&gt;The core idea was simple: build a lightweight workspace where daily developer and productivity utilities live under one roof without unnecessary friction.&lt;/p&gt;

&lt;p&gt;Instead of relying on heavy frontend frameworks, I designed WafyDev with pure &lt;strong&gt;HTML5, CSS3, and JavaScript&lt;/strong&gt;. This ensures instant page loads, zero framework bloat, and minimal resource usage on any device.&lt;/p&gt;




&lt;h3&gt;
  
  
  Key Features &amp;amp; Core Philosophy
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;100% Client-Side &amp;amp; Private:&lt;/strong&gt; Everything runs directly inside your browser. Sensitive actions—like generating passwords or saving local notes—never leave your machine.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ad-Free &amp;amp; Distraction-Free:&lt;/strong&gt; A modern, dark-themed interface built for focus and speed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Zero Latency:&lt;/strong&gt; Tools respond instantly with no server roundtrips required for processing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Responsive Workspace:&lt;/strong&gt; Optimized for seamless usage across mobile, tablet, and desktop screens.&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  The 9 Built-in Utilities
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;🔐 Password Generator:&lt;/strong&gt; Create strong, cryptographically secure passwords with a real-time strength meter.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;📱 QR Code Generator:&lt;/strong&gt; Instantly generate and export custom QR codes for links and text.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;⌨️ Typing Speed Test:&lt;/strong&gt; Measure real-time words per minute (WPM), accuracy, and error rates.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;⏱️ Study Timer:&lt;/strong&gt; A Pomodoro-style productivity timer with customizable focus and break sessions.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;📝 Markdown Preview:&lt;/strong&gt; Live real-time Markdown editor with instant HTML rendering and raw toggle.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;📒 Note Taker:&lt;/strong&gt; A lightweight in-browser scratchpad with instant local storage and search.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;⏳ Countdown Timer:&lt;/strong&gt; Track days, hours, and minutes remaining for events and deadlines.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;🔤 Text Utilities:&lt;/strong&gt; Fast case conversion, whitespace cleanup, and real-time word/line/character counting.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;🎨 Color Palette:&lt;/strong&gt; Pick and inspect colors with instant HEX, RGB, and HSL values.&lt;/li&gt;
&lt;/ul&gt;




&lt;h3&gt;
  
  
  What's Next?
&lt;/h3&gt;

&lt;p&gt;WafyDev is an open-source project licensed under MIT. I am continuously working on adding more tools like JSON formatters, Base64 encoders, and offline PWA support.&lt;/p&gt;

&lt;p&gt;If you are looking for a straightforward, distraction-free utility suite for your daily workflow, check it out:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Live Demo:&lt;/strong&gt; &lt;a href="https://dev.amwafy.xyz" rel="noopener noreferrer"&gt;https://dev.amwafy.xyz&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GitHub Repository:&lt;/strong&gt; &lt;a href="https://github.com/afeemuhammodwafy1/wafydev" rel="noopener noreferrer"&gt;github.com/afeemuhammodwafy1/wafydev&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Feel free to explore the project, star the repo on GitHub, or suggest new features you would love to see added!&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>javascript</category>
      <category>productivity</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
