CV

Who you are actually working with.

Most agency about pages are written to sound impressive. This one is written to be checked. Every claim below is backed by a page on this domain: the case studies carry the numbers and the diagnosis behind them, the rate card is published rather than quoted, and the build log for this site lists what is live and what is not. If a line here cannot be pointed at, it should not be here.

Every claim is checkableRates published, not quotedYou deal with me directly

At a glance

The short version.

Alin Boatca

Freelance web developer and technical SEO specialist

Remote, United Kingdom, UK hours

2 slots open

Language
English
Sector experience
Fourteen years, including regulated and restricted sectors
Engagement
Retained or project, minimum four hours
Rate
£95 blended hourly, published on the rate card
You deal with
The person doing the work, not an account manager
Replies in
Under a day, usually the same one

The work

Building and maintaining high-traffic WordPress sites end to end: custom PHP and theme development, performance and caching architecture, structured data, security hardening, and the SEO strategy and copywriting that make the traffic worth having.

The role

Single technical owner on client sites. Diagnosing the problem, building the fix, deploying it, and verifying it live before calling it done. That runs from custom post types and templates through CDN and cache invalidation, schema, Core Web Vitals, accessibility and WAF rules.

The strength

Diagnosis. Finding the actual root cause when a symptom has several plausible explanations, and proving the fix with before and after evidence rather than assumption. Several of the jobs below were originally briefed as something else entirely.

Core skills

What the work actually covers.

Development

  • Custom WordPress: post types, taxonomies, meta, template hierarchy, hooks and filters
  • Sage-based custom themes and bespoke page templates built from scratch
  • PHP, JavaScript (DOM-safe, no framework bloat), CSS, MySQL
  • API integration: Cloudflare API, Geolocation, OpenStreetMap and Nominatim geocoding
  • and more

Technical SEO

  • Structured data: entity consolidation, @id graph design, Rich Results validation
  • Canonicals, indexation and crawl control, cannibalisation prevention
  • Keyword and competitor research, SERP analysis
  • Backlink auditing, disavow decisions, declining paid-link and PBN approaches
  • and more

Performance and infrastructure

  • Multi-layer caching: CDN edge, OPcache, Redis, transients, and correct invalidation across all of them
  • Cloudflare: API-driven targeted purging, cache rules, WAF, Managed Challenge, IP allowlisting
  • Managed hosting deployment, service management and server diagnostics
  • Image pipelines: multi-size generation, AVIF, srcset delivery, bulk regeneration
  • and more

Security, content and accessibility

  • Bot and brute-force mitigation at the edge, honeypots, REST API restriction, HSTS
  • Vulnerability triage on third-party plugins, secrets management discipline
  • SEO copywriting, plus detecting and rewriting machine-spun content
  • WCAG auditing and remediation: labelling, ARIA roles, non-colour affordances
  • and more

Selected achievements

Problems solved, with the numbers attached.

All from live client work, and every figure is measured rather than estimated. Most are written up in full on the case studies page, including the wrong first theories. Clients who asked not to be named are described by sector instead.

21,626 to 0 Login brute force stopped at the edge in fifteen minutes Live traffic analysis showed wp-login.php absorbing roughly 46% of all origin requests. Fixed with a Cloudflare Managed Challenge plus an admin IP allowlist skip rule, then verified the drop and confirmed admin access was unaffected. Also established the attack was not degrading performance, with the server at 7.5% CPU, which prevented an expensive and misdiagnosed "the site is slow" response.
14 to 24 hrs stale, fixed A cache invalidation failure with four independent root causes Availability changes were not propagating. The deployed purge was already a targeted URL list rather than a full purge, and four separate gaps existed: missing URLs, a meta deletion path with no hook, a dual URL form for location terms, and the subtle one, curated pages that query content rather than being taxonomy archives, which no term-based loop could ever reach. All four fixed and verified live.
25 links to 5 A DR 72 domain ranking for nothing, rebuilt hub and spoke Established it was an on-page problem rather than an authority one, since page-one competitors sat at DR 16 to 32. Rebuilt with split commercial and informational intent to stop cannibalisation, fixed a canonical pointing at a redirect, replaced machine-spun copy, and cut a bloated 25-link block to five curated internal links.
One valid entity A broken structured data graph consolidated Removed a duplicate organisation entity, disabled per-item LocalBusiness markup and self-serving review ratings, promoted the remaining node to a correct single type and stripped invalid FAQPage markup, closing a Search Console entity issue. Breadcrumbs and the organisation @id were retained after researching the collision risk, and the result validated in Rich Results.
33k/mo term Two bespoke customer-facing tools built from scratch A geolocation "near me" tool using the Geolocation API, Haversine distance sorting, radius filtering and a self-maintaining geocoding layer so new locations work with no code change, server rendered so it stays crawlable. Plus a three-way comparison tool with bidirectional relationship data, SVG connectors, location-aware pricing and undo/redo.
A live ledger Internal linking governance that survives contributors A documented rule and a live ledger preventing the repetitive templated link footprint that dilutes equity across a site, written down so it holds across sessions and whoever works on the site next.

Measured, not estimated

Numbers from live sites.

Every figure below came off a real client site with a tool anyone can run: Lighthouse, field data from the Chrome UX Report, response headers, or the origin traffic log. None of it is a projection.

CLS 0.00 Across home, gallery and profile templates
372 ms Field LCP at the fastest measured template
51 to 78 ms INP across the same templates
100 / 100 Lighthouse SEO, with 96 best practices
9,676 Images rebuilt into a 3-size AVIF pipeline
22 MB to 1 MB Single video asset, without visible quality loss
21,626 to 0 Daily login attack hits, inside fifteen minutes
~151 hrs Logged on one retained build, itemised and priced

Client work

Who the work was for.

Named where the build is already public, described by sector where the client asked for that. No logo wall of companies that were never clients.

High traffic lifestyle directory DR 72

Sole technical owner: custom Sage theme, two bespoke tools, caching architecture, schema, security, SEO strategy and copy. Around 151 hours logged.

Lamplit London Public build

Theme development, sponsored link compliance and deep-link architecture.

London Guide UK Public build

Plugin stack and full site build.

Search and competitor research Ongoing

A continuing competitor, keyword, backlink and SERP analysis programme.

Tools and technologies

The stack the work runs on.

Not a logo wall either. These are the tools genuinely in daily use, grouped by the job they do. The tool is never the method: the diagnosis decides which one gets opened.

Platform and code

  • WordPress
  • PHP
  • JavaScript
  • CSS
  • MySQL
  • Sage
  • WP-CLI
  • Astro
  • and more

Infrastructure

  • Cloudflare (API, WAF, cache rules)
  • Redis / Object Cache Pro
  • OPcache
  • Nginx / Apache
  • and more

Search and analysis

  • Ahrefs
  • Google Search Console
  • Google Rich Results
  • Yoast SEO
  • Chrome DevTools
  • Lighthouse
  • and more

WordPress stack

  • Secure Custom Fields
  • WP All Import
  • EWWW Image Optimizer
  • ShortPixel
  • Media File Renamer
  • Contact Form 7
  • and more

Hosting and workflow

  • Cloudways
  • DigitalOcean
  • Supabase
  • Git
  • SSH
  • FTP / SFTP
  • Obsidian (documentation)
  • and more

How I work

The operating rules, not aspirations.

Each of these is applied on this site as well as on client work, which is the only way to tell whether someone means them.

Evidence over assumption

Fixes are verified live, before and after. If it cannot be proved it changed, it is not done.

Root cause, not symptom

When several explanations are plausible, the work is isolating which one it actually is before writing any code. Testing origin directly with a cache buster, for instance, proves whether a problem is the file or the cache rather than guessing between them.

Respect the blast radius

A single functions.php edit can white-screen an entire site, and one careless purge can cool a year of image cache. Back up before touching, scope changes tightly, and use targeted purges instead of nuking everything.

Flag the risk up front

If a change carries SEO or ranking risk, you hear it when it is proposed rather than after it ships.

Honest estimates

Time is logged as it is spent, including work that was scrapped or reverted, and the rate card is published rather than quoted per client.

Documented, not in my head

Every project keeps a living knowledge base: architecture, deployed code, gotchas and a changelog. That is what lets a fix survive a handover, a contributor or a year.

Protect the client

Never destructive without a verified rollback path. Credentials and secrets never leave secure storage. Paid link and PBN approaches are declined rather than quietly accepted.

Proof of craft

This site is the portfolio piece.

The quickest way to judge someone who claims to do this work is to look at what they did where it cost them something. This domain is a static build with no CMS, publishing its own build log including the unfinished parts.

Every page carries JSON-LD that parses and validates, checked on each build rather than assumed. The XML sitemaps carry genuine per-URL last-modified dates instead of stamping everything with the build time. There are no third party hosts on the homepage, which you can confirm in your own DevTools in about ten seconds. Enquiries are handled by a function on this domain rather than a third party form service, behind four layers of spam and flood defence, with SPF, DKIM and DMARC at p=reject. llms.txt and llms-full.txt are generated from the same catalogue that builds the sitemaps, so they cannot drift.

None of that is remarkable individually. Together it is the difference between someone who recommends this work and someone who has done it.

The build log

Book me

Want to test any of this?

Send the URL and the symptom. You get a straight read on what is actually causing it and whether it is worth fixing, which is a faster way to judge someone than a CV.

Reply within one working day No obligation Your details stay with us

Takes about 60 seconds. No newsletter and no CRM sequence. Your details are used to reply to this enquiry and nothing else. See the privacy notice.