I’m a security-focused full-stack developer and systems integration specialist based in South Africa.
I build practical web applications, e-commerce platforms, business systems, and secure digital products.
I contribute tested improvements to public software projects, working across unfamiliar codebases, automated testing, documentation, CI and technical review.
My recent contribution work demonstrates the ability to:
- investigate existing architecture and project conventions;
- implement focused fixes without unnecessary scope expansion;
- write regression tests and validation checks;
- work with Python and JavaScript/TypeScript project tooling;
- use Git branches, forks and pull requests safely;
- respond constructively to technical review feedback;
- diagnose edge cases and refine an implementation;
- deliver changes that pass real project CI pipelines.
| Project | Contribution | Status |
|---|---|---|
| Beets | Improved the Tidal metadata plugin so search_limit counts distinct album and track candidates, with regression coverage for duplicate handling, generator continuation and early stopping. |
PR #6896 — in review, CI passing |
| gettext-tstrings | Added multilingual documentation link-target parity checks and corrected translated-page link defects. | PR #26 — merged |
| AirMCP | Delivered four merged contributions covering testing documentation, contributor workflow, template-drift validation and deterministic security-audit report testing. | #406, #412, #415, #417 — merged |
These contributions complement my broader experience in software delivery, systems integration, QA and release governance, cybersecurity, telecommunications and technical leadership.
Mzansi Select is a South African e-commerce storefront project focused on creating a clean, trustworthy online shopping experience for curated products.
Skills shown: Shopify, e-commerce, storefront UX, product catalogue planning, QA, release control, customer-facing copy.
V-Property is a property/rental platform project focused on helping users browse, manage, and work with property-related information through a web application.
Skills shown: full-stack development, database-backed apps, product delivery, Git workflow, deployment planning, stakeholder preview readiness.
- Full-stack web application development
- Secure-by-design development
- QA-aware engineering
- Business systems and API integration
- E-commerce and product platforms
- Cybersecurity learning and authorised security research
I also practise authorised security research through bug bounty and vulnerability disclosure programmes.
My current focus areas include:
- OWASP Top 10 awareness
- access-control review
- IDOR/BOLA methodology
- information-disclosure analysis
- scope validation
- low-noise testing
- evidence minimisation
- clear vulnerability reporting
Some reports have been accepted or closed as informational, which I treat as learning evidence rather than confirmed high-impact findings.
Private programme details, report contents, target names, screenshots, request/response data, and reproduction material are not published unless disclosure is explicitly approved.
This profile only includes public, recruiter-safe project summaries. Private client work, security research evidence, credentials, supplier details, and confidential project material are intentionally excluded.
I’m open to software development, full-stack, QA-aware engineering, systems integration, and security-focused development opportunities.
- Email: Fhatuwani.Sikhwari@sikhwarigroup.co.za
- GitHub: github.com/Fhatu12
- LinkedIn: linkedin.com/in/fhatuwani-sikhwari-60013a1a
- Website: sikhwarigroup.co.za
Built by SG Digital | A division of Sikhwari Group (Pty) Ltd