Abdisalan Osman Ibrahim Product Builder & Developer Paris, France

I build digital products with AI.

From SaaS platforms and marketplaces to business systems and web applications, I turn ideas into working products using AI-assisted development.

Idea to production07 stages

  1. 01Idea
  2. 02Architecture
  3. 03Design
  4. 04 AI-assisted development Directed by me
  5. 05Test
  6. 06Deploy
  7. 07Live product

Selected work07 live products

Things I’ve built.

Real products, platforms, systems, and experiments — each one running in production, each one built end to end.

SmartMenu brand mark — a menu card beside a fork and knife, above the wordmark ‘Smartmenu — smart menu, better service’
smartmenu.so

01SaaS platformLive

SmartMenu

A multi-tenant digital menu platform for restaurants. Each venue manages its own menu, generates QR codes for tables, and updates prices in real time without reprinting anything.

Problem
A price change means reprinting every menu — and the digital alternatives are priced for chains.
I built
Tenant isolation, roles & permissions, the menu editor, per-table QR generation, subscription billing, the venue dashboard, and the public menu.
How
Multi-tenant schema designed first, then built outward. AI-assisted implementation; tenancy boundaries and the security review reviewed by hand.

PHP · MySQL / MariaDB · JavaScript · REST API · Nginx

Visit smartmenu.so Read the case study

Shaqodoon.net brand mark — the wordmark for the Somali jobs platform
shaqodoon.net

02Jobs platformLive

Shaqodoon

A jobs platform for the Somali market that brings listings scattered across social posts and noticeboards into one searchable destination.

Problem
Openings are posted everywhere and indexed nowhere, so seekers miss them.
I built
The aggregation pipeline, category and location search, employer submissions, and automated freshness checks that retire dead listings.
How
WordPress as the publishing layer, a Python collector feeding it over the REST API.

WordPress · PHP · REST API · Python

Visit shaqodoon.net
Maanta We keep Somali businesses running
maantatech.com

03IT servicesLive

Maanta Tech

The platform for a Mogadishu IT company serving businesses across Somalia and East Africa — service lines, coverage, and support commitments, with enquiries routed straight to the engineers.

I built
Network infrastructure and ISP failover offers, custom business systems, security and access control, managed support and monitoring.

HTML · CSS · JavaScript · Nginx · Linux

Visit maantatech.com
Salaada brand mark — the wordmark for the prayer times platform
salaada.com

04Web applicationLive

Salaada

Prayer times and daily practice tools built around accurate, location-aware information rather than a single national timetable.

I built
Per-mosque timetables, location-aware calculation, and Qibla direction.

JavaScript · PHP · API integration

Visit salaada.com
Faras Online Market brand mark — the wordmark for the e-commerce marketplace
farasmarket.com

05E-commerce · marketplaceLive

Faras Market

A marketplace where independent sellers list products and buyers order through a single checkout — built around the payment and delivery habits of the local market, not a generic storefront template.

Problem
Sellers had reach through chat apps but no order trail, no catalogue, and no checkout.
I built
Seller accounts and product listings, cart and checkout, the order management dashboard, payment integration, and seller administration.
How
WooCommerce as the transaction core, extended in PHP where the local flows diverge from the default.

WordPress · WooCommerce · PHP · MySQL

Visit farasmarket.com

06Telecom platformLive

VOIP.SO

A complete VoIP carrier platform: public site, customer self-service portal, admin back office, prepaid billing engine, and a FusionPBX provisioning layer. Registration is provisioning — creating an account allocates the extension, SIP secret, and voicemail box before the confirmation email sends.

Problem
Selling SIP service means running billing, provisioning, and support as one system — not three.
I built
Customer portal, admin back office, prepaid billing with wallet and invoices, automated FusionPBX provisioning, SIP accounts and extensions, voicemail, IVR, ring groups, call routing, and the REST API tying them together.
How
PHP 8.3 against MariaDB, driving FusionPBX through its API. Deployed on Linux with Nginx, SSL, and SIP transport configured by hand.

PHP 8.3 · MariaDB · FusionPBX · REST API · Nginx

Visit voip.so
VOIP.SO brand mark — a speech bubble with signal waves around a letter V, above the wordmark ‘VOIP.SO — VoIP service simplified’
voip.so
Signal path — sign-up to dial tone
VOIP.SO platform architecture A customer signs up in the portal. The platform writes the account to MariaDB and opens a prepaid wallet, then calls the provisioning service, which creates a SIP extension, voicemail box, IVR, and call routing in FusionPBX. The registered handset then carries calls out through the SIP trunk to the PSTN. Customer Sign-up in the portal Platform — PHP 8.3 Customer portal Admin back office Prepaid billing MariaDB Accounts · CDR Invoices · balances Provisioning — REST API Registration allocates the extension before the email sends FusionPBX SIP extension Voicemail IVR Ring groups Call routing · business hours SIP trunk Carrier interconnect Calls to the PSTN
SomaliGate Magazine brand mark — the wordmark for the Somali lifestyle and community magazine
somaligate.com

07Publishing platformLive

SomaliGate

A Somali lifestyle and community magazine, built to put more Somali-language writing online across health, family, and personal development — with a multi-author pipeline from draft to published issue.

I built
Editorial workflow and author roles, category verticals, SEO and structured data, performance tuning, and the newsletter.
How
WordPress on PHP 8.3 and MySQL, served by Nginx and tuned for Core Web Vitals.

WordPress · PHP · MySQL · Nginx

Visit somaligate.com

Built with AI.
Directed by me.

I use AI throughout the development process to move faster — from architecture and UI design to implementation, debugging, testing, automation, and iteration.

AI does not decide what to build. I do.

  1. 01

    Think

    Product idea and requirements — what this is for, and who it is for.

  2. 02

    Architect

    Database, APIs, infrastructure, and system structure.

  3. 03

    Design

    UX, interface, responsive layouts, and interactions.

  4. 04

    Build

    AI-assisted implementation across frontend and backend.

  5. 05

    Test

    Debugging, validation, security, and quality control.

  6. 06

    Deploy

    Servers, DNS, SSL, hosting, monitoring, and production.

  7. 07

    Improve

    Iteration based on real-world use.

What I actually use it for.

Concrete work, not a revolution — these are the places AI earns its keep on a normal build day.

What none of it decides: the architecture, the product decisions, the security model, what passes testing, and what reaches production. Those stay mine, and so does the result.

  • Exploring architecture
  • Generating implementation ideas
  • Writing repetitive code
  • Debugging
  • Refactoring
  • Testing
  • Documentation
  • Automation
  • Data processing
  • API integration
  • UI iteration
  • Problem solving

What I build

Six kinds of work, all of it shipped to production and maintained afterwards.

SaaS

Multi-tenant applications, dashboards, subscriptions, accounts, and business systems.

Marketplaces

Listings, sellers, buyers, payments, orders, administration, and workflows.

Web Applications

Custom systems designed around real business requirements.

AI-Powered Products

Products using AI for automation, workflows, and user experiences.

Business Systems

Internal tools, management platforms, and operational software.

Infrastructure

Linux servers, Nginx, Apache, DNS, deployment, SSL, security, and server management.

When it breaks.

Fifteen screens that mean a site is down. What each one is actually telling you, and what I do about it — on the server, not in the dashboard.

Server — Apache & Nginx

500 Internal Server Error
Internal Server Error

The server encountered an internal error or misconfiguration
and was unable to complete your request.

Additionally, a 500 Internal Server Error error was encountered
while trying to use an ErrorDocument to handle the request.
What it is
A fatal PHP error, an .htaccess directive the server does not support, a missing Apache module, or files the web server is not allowed to read. That second paragraph is its own clue — the custom error page is broken too, so the real message never reaches the browser.
What I do
Read the server error log instead of the browser. Take .htaccess out of the path to isolate it, switch PHP error logging on, check ownership and permissions — 644 for files, 755 for directories — then fix the one failing line and put the error page back.
403 Forbidden
Forbidden

You don't have permission to access this resource.

Additionally, a 403 Forbidden error was encountered while
trying to use an ErrorDocument to handle the request.
What it is
Ownership or permissions left wrong by a migration, an index file missing while directory listing is switched off, a deny rule in .htaccess that is broader than it was meant to be, or a ModSecurity rule blocking a request that was perfectly legitimate.
What I do
Find the rule ID or the path in the log, restore correct ownership for the web user, put the index file or the Options directive back, and whitelist the single rule that fired rather than switching the firewall off.
502 / 504 Bad Gateway, Gateway Time-out
502 Bad Gateway
nginx

504 Gateway Time-out
nginx
What it is
Nginx is healthy; the PHP-FPM pool behind it is not. It has crashed, run out of workers, or is taking longer to answer than fastcgi_read_timeout allows. The cause is almost always a memory ceiling or a slow query, not the web server.
What I do
Size the pool against the memory the machine actually has, turn on the FPM slow log to find what is hanging, fix that query or background job, and raise the timeout only where it is genuinely justified.
HOST Error. Page cannot be displayed.
Error. Page cannot be displayed. Please contact your service
provider for more details.
What it is
The hosting platform’s own error page, shown in place of the real one. It is hiding a 500, an account resource limit, a suspended account, or a process the host killed — the vagueness is the whole point of the page.
What I do
Get the real status code and the real log: request the URL headers directly, then open the account error log. From there it stops being a mystery page and becomes whatever it actually is.

WordPress

WP There has been a critical error on this website.
There has been a critical error on this website.

Learn more about troubleshooting WordPress.
What it is
A PHP fatal error inside a plugin or a theme, with WordPress catching it and showing this generic page instead. It turns up right after an update, a PHP version change, or a migration that was not finished cleanly.
What I do
Switch on WP_DEBUG_LOG and read the actual fatal in debug.log, disable the offending plugin from the filesystem or WP-CLI to bring the site back, then repair or replace it on a staging copy before it goes anywhere near production again.
PHP Your server is running PHP version 7.3.33
Your server is running PHP version 7.3.33 but WordPress
requires at least 7.4.
What it is
PHP that has reached end of life. 7.3 stopped receiving security fixes in December 2021, so the site is unpatched at the language level, and new WordPress and plugin releases will simply refuse to install.
What I do
Check every plugin and the theme for compatibility first, take a full backup, move a staging copy to PHP 8.1 or newer, clear the deprecations that surface there, then switch production over with the old version kept available for one rollback window.
DB Error establishing a database connection
Error establishing a database connection
What it is
Credentials in wp-config.php that no longer match, a MySQL or MariaDB service that has stopped or hit max_connections, or a table that crashed during an unclean shutdown.
What I do
Verify the database user, password and host, bring the service back and read why it went down in the first place, repair the crashed tables, then set connection and memory limits so the same traffic does not take it down again.
MEM White screen — allowed memory size exhausted
Fatal error: Allowed memory size of 268435456 bytes exhausted
(tried to allocate 20480 bytes) in /home/site/public_html/wp-
includes/wp-db.php on line 2056
What it is
A single request asked for more memory than PHP is allowed to hand it — an oversized query, an image being resized, or an import running in one pass. With display_errors off you never see that line; you get a blank white page.
What I do
Raise the limit to something sane to restore service, then profile the request that caused it and fix the cause. A permanently high limit does not solve this, it just moves the crash further down the road.
LOCK Briefly unavailable for scheduled maintenance
Briefly unavailable for scheduled maintenance.
Check back in a minute.
What it is
An update that failed part way through and left the .maintenance file sitting in the site root. Nothing is updating any more, and nothing is going to clear that file on its own.
What I do
Remove the file, establish whether the update actually completed, repair any core, plugin or theme files left half written, and then run the update again properly.
AUTH Login redirect loop, locked out of wp-admin
example.com redirected you too many times.
ERR_TOO_MANY_REDIRECTS
What it is
siteurl and home no longer matching the domain or the scheme after a move to HTTPS or a new host, a corrupted .htaccess, or cookies still pinned to the address the site used to have.
What I do
Correct siteurl and home directly in the database, regenerate the rewrite rules, clear the object and page cache, and confirm the redirect chain now ends on exactly one canonical URL.
HACK Spam redirects, injected pages, login floods
POST /wp-login.php    401    x 4,812
POST /xmlrpc.php       200    x 1,190
GET  /?p=1             302 -> pills-cheap.example
What it is
Either an outdated plugin that has already been exploited — redirects to spam, pages nobody published, admin users nobody created — or the relentless brute force and XML-RPC traffic that usually comes first.
What I do
Clean the site back to a known good copy, rotate every credential, patch whatever let them in, then harden it: rate limiting, fail2ban, two-factor on admin accounts, file editing disabled, XML-RPC closed.

SSL, DNS & email

SSL Your connection is not private
Your connection is not private
Attackers might be trying to steal your information from
example.com (for example, passwords, messages or credit cards).
NET::ERR_CERT_DATE_INVALID
What it is
The certificate expired. The renewal almost always stopped quietly weeks earlier — a changed vhost, a cron job removed during a cleanup, or a validation path that no longer resolves.
What I do
Reissue the certificate, repair the renewal so it runs unattended again, and add expiry monitoring so the next one is caught by a machine rather than by a customer.
MIX Not secure — mixed content
Mixed Content: The page at 'https://example.com/' was loaded
over HTTPS, but requested an insecure resource
'http://example.com/wp-content/uploads/logo.png'.
This request has been blocked.
What it is
The page is served over HTTPS while assets are still hardcoded to http — normally left behind by a migration, or by a theme that stored absolute URLs in the database.
What I do
Rewrite the stored URLs in the database, fix the hardcoded ones in the theme, and have the browser upgrade anything remaining, so the padlock stays and nothing silently fails to load.
DNS Site not resolving after a move
This site can't be reached
Check if there is a typo in example.com.
DNS_PROBE_FINISHED_NXDOMAIN
What it is
Nameservers that were never switched, a missing A or CNAME record, or an old TTL still handing the previous IP address to part of the world while the rest already sees the new one.
What I do
Set the records at the nameservers that are genuinely authoritative, verify from several resolvers rather than from one browser, and lower TTL ahead of the next migration so cutover takes minutes instead of days.
MAIL Site email lands in spam, or never arrives
550 5.7.26 Unauthenticated email from example.com is not
accepted due to the domain's DMARC policy. Please contact the
administrator of example.com domain.
What it is
Mail sent straight from the server with nothing the receiving side can verify — no SPF alignment, no DKIM signature, and a DMARC policy that now rejects exactly that.
What I do
Send over authenticated SMTP, publish SPF, DKIM and DMARC correctly, and then confirm placement with real test sends rather than assuming the problem is solved.

Seeing one of these right now? Send me the exact wording and the URL. That is usually enough to say what it is before I touch anything.

Send me the error

Technology

What I actually use — nothing listed here that I have not shipped with.

Frontend
HTML · CSS · JavaScript · jQuery · Bootstrap · Responsive design
Backend
PHP · WordPress · Node.js · Python · REST APIs
Database
MySQL · MariaDB
Infrastructure
Linux · Nginx · Apache · DNS · SSL · Hosting · Server management · FusionPBX · SIP
AI
AI-assisted development · AI coding workflows · Automation

I take ideas and turn them
into products that run.

cabdisalaan.net personal mark — a letter A containing the Eiffel Tower

I’m Abdisalan Osman Ibrahim. I build SaaS platforms, marketplaces, web applications, business systems, and the infrastructure they run on.

I work across the stack — data models and backend systems, frontend interfaces, and the production servers underneath. Most of what I ship, I ship alone, which is why the architecture has to be right before the first screen gets built.

AI is part of my development workflow because it lets me move faster: drafting architecture, generating implementation, catching bugs, writing tests, automating deployment. What stays deliberate is the architecture, the product decisions, the security, the testing, and what finally goes into production.

Alongside client and product work I run experiments — marketplace concepts, domain projects, infrastructure automation — because building the thing is how I find out whether the idea holds.

Based in
Paris, France
Focus
Product development, SaaS, marketplaces, AI-assisted development
Infrastructure
Linux, Nginx, DNS, deployment, server management
Education
IUT de Troyes — Diploma in Networking

The lab

Smaller things — some half-built, some still only a hunch worth testing.

  • Domain Marketplace Listing, valuing, and selling domain names with the transfer handled end to end Building
  • AI Content Tools Internal utilities for drafting, editing, and scheduling content at volume Building
  • Server Automation Provisioning, backup, and monitoring scripts for the servers I run Experiment
  • Domain Portfolio Domain research, acquisition, and portfolio management Experiment

Think clearly.
Build quickly.
Test everything.
Ship what works.

AI shortens the distance between an idea and a working product. It does not decide what to build, how it should be structured, whether it is good enough, or when it ships. Those stay deliberate.

ContactOpen to new projects

Have an idea?
Let’s build it.

Have a product, platform, marketplace, or business idea? Let’s turn it into something real.