WordPress Malware Removal & Hardening

Job ID: 39793675

Budget: $2 – $8 USD

My WordPress site has been hit by a malware infection that is causing redirects and triggering security warnings with Google. I installed a new plugin a few days ago and I’m almost certain that is where the breach began, but I have not yet traced the exact files that were compromised.

What I need now is a thorough, professional cleanup followed by solid hardening so this doesn’t happen again. I’ve already taken the site offline temporarily and have a cPanel backup ready to restore if required. SSH, SFTP, phpMyAdmin and wp-admin access will be provided immediately when we start.

Deliverables
• Complete malware removal from all files and database tables, with a final clean scan report (Wordfence, Sucuri or a comparable tool).
• Identification of the entry point — please document the infected plugin/theme file(s) and the exploit used.
• Core, theme and plugin updates performed safely, along with removal of any abandoned or vulnerable code.
• Hardening actions: secure wp-config, correct file permissions, lockdown of xml-rpc if advisable, strong login protection (2FA, reCAPTCHA, rate limiting), and .htaccess tweaks.
• Installation and basic configuration of an ongoing monitoring solution with daily automated scans and email alerts.
• A concise post-engagement report summarising work done, recommendations for best practices, and confirmation that the site is malware-free.

No design work is needed — just security expertise that gets the site back up fast and keeps it safe long-term.