Hello world! ;)

Tobias is an entrepeneur and consultant.

Previously he was well regarded as the CTO at Sitewards, who specialized in e-commerce solutions. He has built up a development team at Sitewards that thrives to be at the cutting edge of web development.

With passion of inspiring people he takes part in and speaks at conferences worldwide. He also publishes articles in a wide range of magazines, several blogs and has written books about web security.


  • Defined e-commerce as the new focused company strategy
  • Presented the company on technical subjects to customers
  • Being invited as speaker on conferences worldwide
  • Created and maintained the image of Sitewards in the areas of technique and e-commerce
  • Hired and lead the team of software development and quality assurance
  • Transformed and continuously improved the delivery-workflow to agile methods
  • Architected and written source code of highest quality
  • Took as a product owner responsibility of time and budget of the biggest projects

"Tobias is an exceptionally talented developer but for me his biggest plus side is that he is always willing to ask why and not just simply go with the flow.
This is an amazing important trait for a team lead as it inspires those around them to progress and not stagnate.
He has an attitude of improvement in whatever he does and leads by example throughout."

David Manners 2015

  • Consulted customers in technical decisions
  • Trained developers in coding techniques
  • Architected and written source-code as a ghost-developer for enterprise companys
  • Hired and integrated development teams
  • Full-stack LAMP development
  • Implementation of Propel as the ORM
  • Taken part in technical decisions
  • Training of developers in the use of design patterns and clean code techniques
  • Full-stack LAMP development
  • Refactoring of proprietary CMS solution
  • Hiring and training of new developers
During his education in the information and communication techniques sector, Tobias gained his first professional experience working part-time as a developer for several customers.

Security at e-commerce

Tobias has written a book addressing developers and decision makers, which plan or already maintain an e-commerce-site.
Besides the main attack scenarios like xss, injections and csrf it also covers exotics like pixel perfect timing.
Additionally frameworks and tools have been analyzed which help to secure your application.

Featured in screenguide 23

OWASP Top 10

A shortcut about the OWASP Top 10, focused on PHP developers.


Security Patterns

Three consecutive articles in the german PHP Magazin about security patterns based on the OWASP Top 10.

PHP Magazin / 02.2014, 03.2014, 04.2014


Article in the german t3n Nr. 34 about the usage and implementation of BigPipe.


What's new in Magento 2?

Some thoughts about the current state of Magento 2.

webguys / 2014-12-05

Magento Test-Suites

Article in the german PHP Magazin about Test-Suites in Magento.

PHP Magazin / 05.2013

E-Commerce goes Enterprise

Article in the german PHP Magazin about the installation and configuration of Apache Solr in Magento Enterprise.

PHP Magazin / 02.2013

PHP and Microsoft SQL Server

Guest blog article in the german phphatesme.com blog about the usage of Microsoft SQL Server in PHP.


E-commerce interview

The webmagazin recorded a video interview at the Webinale 2014. Talking about pros and cons of Magento and which alternatives are actually relevant.


From Dev To CTO

Tobias was featured with his "From Dev to CTO" session from the Barcamp Rhein-Main in a following sunday newspaper.

Frankfurter Allgemeine Sonntagszeitung 2014-01-05

About Magento 2.0

An internal interview at Sitewards about Magento 2.0.


Review 2013 / Forecast 2014

The PHP Magazin interviewed Tobias and his colleague Michael about the passed trends and hypes in 2013 and aswell tried to give a forecast for 2014.


OWASP Top 10 for developers

Maintaining the PHP section of the OWASP Top10 for developers.



An implementation of the module management tool modman written in PHP so it runs on every OS.


BigPipe for Magento

Implements a BigPipe option to Magento, so a block can be marked as BigPipe an will be rendered after the first flush appeared. Facebook uses that technique to avoid a blocking of the loading process by some slower components.


FireGento - Admin Monitoring

The admin monitoring logs nearly every save and delete call in the backend of a Magento shop.


Houston - a multi-threading micro-framework

A microframework to create multi-threaded php applications, built before it was cool to do that stuff. ;)


Magento Hackathon - Gamification

The Gamification module allows to track events stored by Hackathon_FrontendMonitoring and release actions like incrementing points, earn badges or cat stickers for a user.



To PHPUnit, Zend Framework, Magento Community and Enterprise, Magento 2, iniscan, Firegento Logger, Mage Setup, Sqlsrv, Typo3 and many more ...

OWASP Top 10

With the latest XSS and CSRF attacks on Twitter, PayPal and Facebook, security is still obviously a very difficult thing to get right.
Every 3 years, the open web application security project (OWASP) releases a new Top 10 vulnerabilities, this talk will walk you through 2013s list.
Presenting you the possible attack scenarios and how you can protect against them.
In addition we'll look at more security issues which are not part of the Top 10, but that you should definitely keep in mind.



@AndreCedik: Best slide of #dchh so far. By @airbone42 @t3sec: OWASP Top 10 - this session is fun joind.in - IPC @iDocIt: Sehr angenehmer Vortragsstil :).Vielen Dank @airbone42 #dchh @phpmagazin: Kudos @airbone42 für die tolle Session über OWASP

XSS and SQL Injections: The Tip of the Web Security Iceberg

You might know about XSS and usual SQL injection, but time has changed and we have to keep up-to-date with the latest attack scenarios.
Do you also know what clickjacking is? If not I'll show you how to protect against it.
I'll also present techniques like Perfect Pixel Timing and a combination of xss/time-based-sql-injection to access intranet sites, which are not even compromised.



@gallamine: Great talk from @airbone42 on crazy internet security attacks. Evaluation: Many new learnings Evaluation: excellent talk ... very enjoyable, best session I've attended so far Evaluation: Really interesting and informative ...

The myth of the 10x programmer

Recently on the net there was a lot of chatter surrounding the myth of the 10x programmer.
It claims that some individuals are 10x more efficiently than some of their colleagues.
In this talk we'll look into this species of superproductives!
How can we measure efficiency of a programmer at all? Is it the lines of code, amount of fixed bugs or number of empty Red Bull cans per hour?
After that we'll have a look if it's actually possible to achieve 10x productivity and if so what's needed to get there.


From Dev to CTO

After beeing a freelancer for several years Tobias joined 2011 Sitewards as CTO.
He recognized very fast that the job in a full management position is some kind of different than developers think of it.
In this talk he talks about challenges and problems, but also which steps and solutions helped to build a highly motivated and successful team.
Besides the technical and disciplinary leadership it's also about recruiting, motivation and team-development.


Magento 2

Magento 2 was first announced way back when in 2010, but a lot can change in IT over four years.
There was not a lot of noise from the Magento camp until October 2013. Now there is a public repository with updates published weekly.
In this talk we'll have a look at the current technical status, make a comparison to the first version of Magento and review the road ahead.



joind.in / php[world] joind.in / PHPUG @nickweisser: ... motivational and refreshing talk ... @neoshops: Very nice presentation ... @fbrnc: ... That was very interesting and well done!

Software quality in e-commerce projects

An e-commerce project has to be extremely fast, requires a lot of features, and needs to be easily maintainable.
That is what we all know, but what does that actually mean in relation to the code?

In this session we'll not only show you how to build code of very high quality, but how to also measure it.

It covers not only not only how to start, but also what it needs to have a long-term success with your system.



@drlrdsen: Good overview of code quality principles and tools ... Featured in @magetalk episode 8 @brentwpeterson: YES! @airbone42 Rocks! ...

Enterprise Search

The Magento search is usually set up with MySQL Fulltext, which is not only limited in amount of features, but also known as a performance bottle neck.
This talks shows from a technical point of view, how easy it is to set up a fast and efficient search incl. autosuggest-capabilities based on Apache Solr in Magento Enterprise with the integrated Enterprise_Search module.



@sheepfred: Good talk on apache solr by @mannersd and @airbone42 ... @bobbyshaw: Thanks very much for your talk this morning! Great stuff :) @avstudnitz: I like those new slides by @airbone42 and @mannersd :-) @wiktorjarka: #devparadise good job with Solr presentation! Enjoyed it! Magento: ... great presentations were given on Solr integration by Tobias Zander

Magento 101

An overview of the Magento ecosystem, Magento features and technical pros and cons.



The loading time of a website is one of the most important factors for its success. The amount of abandoned page loads raises dramatically, the longer the user has to wait for the content.
Facebook invented a new technology called BigPipe which allows the user to already see the essential parts of a website, while long-loading content is still being rendered. This delivers a better user experience and less abandoned page loads.
This talk will show you the technical details of BigPipe and how it can help you to speed up your site and what you need to know to implement it.



@SenseException: #bigpipe is an interesting piece of JS.


Stack Overflow

When there's some free time left, Tobias is an active member on the Stack Exchange network.

profile for Tobias Zander on Stack Exchange, a network of free, community-driven Q&A sites


Besides the private profile, you have to checkout the sitewards and firegento profiles.

Tobias Zander
Schillerstr. 80
63329 Egelsbach
+49 6103 270 10 98
+49 151 404 171 98