Independent web applications

Web applications,
from interface
to infrastructure.

Wizard Stack brings together my work on web applications. Some began with a practical problem; others with something I wanted to use. I build the interfaces, the application logic and the systems that keep them running.

Selected projects

The work

Independent applications, the tools behind them, and a larger project in application security.

01Shared visual workspace

BoardRoom

Some work needs more room than a list of tasks.

BoardRoom is a shared visual workspace for diagrams, notes, drawings and images. It is built for planning, explaining and reviewing things together, whether that means mapping a system or working through an idea on a smartboard.

Inside BoardRoom

Boards can be organised with grouping, locking and filters. Member roles, feedback and branching support the work around the canvas, while saved changes can reach other people viewing the same board.

A phone-pairing flow lets a signed-in user connect a shared display without typing their credentials on it. Notification preferences let members choose which events they hear about.

BoardRoom canvas showing styled text, shapes, arrows, a note and an image, with drawing and editing controls across the top.
BoardRoom · the canvas and its editing tools

02 Software-remediation research

CVE-wizard

Finding a vulnerability and finding the relevant fix are two different jobs.

CVE-wizard helps with the second. Give it a CVE identifier, a software name and the installed version, either manually or in a CSV. It searches vendor and public sources for information about a likely remediation version.

Inside CVE-wizard

The results can include patch links or commands, a match-quality grade and version mentions to review in context. Results can be copied or downloaded as CSV.

A lookup assistant, not an automatic updater. Results need to be checked against their sources; an empty patched-version field does not mean that no update exists.

CVE-wizard input interface, with fields for a CVE identifier, software and installed version, alongside the CSV-upload option.
CVE-wizard · manual input and CSV upload

03 Personal music archive

(An) Idea of Sharing

The DJing ended. The recordings stayed.

(An) Idea of Sharing gives that archive a home: a browser-based player for sets recorded over more than twenty years. Listen to the radio stream when you would rather not choose, or use on-demand playback to pick a mix.

Inside (An) Idea of Sharing

Track information includes its source and a verification status, so an automated match does not quietly pass itself off as a certainty.

There is also a Bathroom Wall: a shared guestbook for writing and drawing.

(An) Idea of Sharing music player, showing radio and on-demand controls, the upcoming playlist and track information.
(An) Idea of Sharing · the listening interface

04 Private administration tool

Wizard Control

Building an application also means building a way to look after it.

Wizard Control is the private dashboard behind the app collection. It brings together application settings, logs, user administration and operational controls for the supporting services.

Inside Wizard Control

Its tools range from managing the music archive and CVE response schemas to inspecting containers, working with databases and managing secrets. The less visible parts of a system need usable tools, too.

Internal software, shown here as part of the work. Not available for public access.

Private tool
Wizard Control administration interface with application and service navigation and the log-search controls, without live log records.
Wizard Control · administration and log inspection

05 Web and API assessment platform

CapableScannerMan

In development

A scanner that follows the application beyond the login screen.

CapableScannerMan is my most extensive application project: a web and API assessment platform with its own frontend, authentication workflows and route-based scanning engine.

It brings browser behaviour, requests, frontend analysis and vulnerability intelligence into a connected assessment, with separate workflows for Page, Domain, API and UI scans.

Four scan workflows

Page Scan
In-scope routes and signed-in workflows within a web application.
Domain Scan
Eligible subdomains and their reachable application routes.
API Scan
Request-based testing from API definitions, collections or captured traffic.
UI Scan
Browser interaction, frontend behaviour and interface quality.
Inside CapableScannerMan

Getting beyond sign-in

Authenticated scanning combines automatic form/TOTP login, recorded browser journeys and Scan Helper, a companion browser extension for real-browser OAuth, OIDC, SAML and redirected SSO. Page Recorder lets a user demonstrate a setup or login journey without writing automation.

A connected assessment

The route-based engine combines custom testing logic with specialist tools including Playwright, Nuclei, Katana and OpenGrep. Browser states, requests, APIs, WebSockets and technology fingerprints inform subsequent tests; CVE intelligence can help guide another bounded pass through a route.

The platform around the scanner

The frontend covers scan preparation and scheduling, organizations, member roles, verified domains, subscription capacity and results. The product work also includes an implemented Lemon Squeezy subscription integration.

Evidence and scope

Findings distinguish suspicious candidates from confirmed behaviour, confirmed execution and cases requiring manual review. Severity and confidence remain separate. Page, Domain and API scans operate within verified scope; UI Scan has a narrower browser-focused remit.

No sign-in needed for this page.

BoardRoom, CVE-wizard and (An) Idea of Sharing use the shared Wizard Stack sign-in. Wizard Control is private; CSM is a separate platform. This portfolio needs no account.

How I build

The interface is part of the job.

So are the decisions behind it: where data lives, who has access, how services talk to each other, and what happens when a request fails.

I build the application and configure the services around it: identity providers, databases, web servers and the connections between them. The work includes getting them running, tracing problems across them and building the tools to look after them.

Application development

From browser interfaces and interactive canvases to backend logic and administrative tools, I build across the application. My main stack is HTML, CSS and vanilla JavaScript, with Node.js on the server.

Identity and cloud integrations

I implement shared sign-in, provider logins and role-based access, including Keycloak integration and custom authentication themes. My work includes OAuth2/OIDC flows, Microsoft and Google sign-in, and the application configuration behind them in Microsoft Azure and Google Cloud.

Servers and deployment

I set up Linux/Ubuntu services, containerise applications with Docker, and configure Apache or Nginx in front of them. DNS, SSL/TLS certificates, reverse-proxy routing and service troubleshooting are part of that work; my server experience also includes Windows Server.

Data and secrets

I work with SQL databases including MariaDB/MySQL and PostgreSQL, use Redis for application state and caching, and manage secrets with HashiCorp Vault. I also build the interfaces needed to inspect and administer those services.

Integrations and automation

I connect services to application workflows: provider APIs, automated email, Playwright browser automation and subscription integration with Lemon Squeezy. My media applications also involve audio processing and streaming with FFmpeg and Icecast.

Application security and testing

My IT-security work includes investigating reported vulnerabilities, supporting remediation and testing web applications. I’ve installed and worked with tools including Burp Suite, OWASP ZAP, Nuclei and Nmap, and brought that experience into CSM’s scan orchestration and evidence handling.

My main development tools are JavaScript and Node.js. I use AI throughout learning and development, including for supporting work in Python and PHP.

About

The person behind the apps

I’m Marko Tralić, a web-application builder based in Zagreb.

My route into development ran through sociology, DJing and IT security. A website for a music project led me to JavaScript, and from there to building applications of my own.

What I enjoy is being able to follow an idea through the whole process: deciding what it should do, working out how the pieces fit, and making something I can actually use.

Contact

About the work, or a related idea.

For questions about the projects, a related idea or a possible collaboration, you’re welcome to get in touch.

Get in touch