Hi, I'mIsrael Kouperman

Full-stack engineer with 7+ years building production systems. I help startups and businesses turn ideas into reliable, scalable software.

From prototype to production, let's build something real.
Professional headshot of Israel Kouperman
How to read this site

What you'll find here

xisra.com is Israel Kouperman's workshop: freelance engineering, free browser tools, and notes from shipping production software. No signup. No paywall. If you are an agent, start with /llms.txt or send Accept: text/markdown.

Services

I take prototypes and half-built products to something you can ship. TypeScript, full-stack, Cloudflare and AWS. Scope is agreed before work starts. Read /services or email me@xisra.com.

Tools

JSON editor, markdown, WhatsApp formatting, QR, currency and tax calculators, Open Graph scoring, and more. They run in your browser. No account required. Index at /tools.

Writing and projects

The blog is engineering writeups. Projects include GitNotes, Lofi Generator, and Can't Cure Stupid. Machine-readable copies live at /llms.txt, /openapi.json, and /sitemap.xml.

Writing

Latest posts

Stop One-Shotting Images. Compose Them in Steps.

Stop One-Shotting Images. Compose Them in Steps.

One-shot AI images look fake and inconsistent. Break composition into trusted materials, apply your style in the process, and assemble last.

Axios Compromised on npm: Attack Breakdown and Remediation

Axios Compromised on npm: Attack Breakdown and Remediation

The Axios npm package got hijacked via a compromised maintainer account. Here's how the supply chain attack worked, how to check if you're affected, and how to respond.

I built tools I want to use and maybe you too

I built tools I want to use and maybe you too

A quick tour of the Tools hub — JSON editor, converter, random keys — with links and how I actually use them.

React Server Components RCE: CVE-2025-55182 Is a CVSS 10.0 and You Need to Patch Now

React Server Components RCE: CVE-2025-55182 Is a CVSS 10.0 and You Need to Patch Now

Wiz Research uncovered a critical unauthenticated RCE in React's RSC Flight protocol. Default Next.js apps are vulnerable. Here's what to do.

Easy Static GitHub Pages Blog Website with Next.js & Tailwind CSS

Easy Static GitHub Pages Blog Website with Next.js & Tailwind CSS

How I created this blog website using Next.js and Tailwind CSS and deployed it to GitHub Pages.

Welcome to my site!

Welcome to my site!

Hello and welcome to my site! This is my initial post welcoming you to join me on my journey.

Get in touch

Let's work together

Have a project in mind? I'd love to hear about it.