WordPress Malware Removal & Hardening
Budget: $2 – $8 USD
My WordPress site has been hit by a malware infection that is causing redirects and triggering security warnings with Google. I installed a new plugin a few days ago and I’m almost certain that is where the breach began, but I have not yet traced the exact files that were compromised.
What I need now is a thorough, professional cleanup followed by solid hardening so this doesn’t happen again. I’ve already taken the site offline temporarily and have a cPanel backup ready to restore if required. SSH, SFTP, phpMyAdmin and wp-admin access will be provided immediately when we start.
Deliverables
• Complete malware removal from all files and database tables, with a final clean scan report (Wordfence, Sucuri or a comparable tool).
• Identification of the entry point — please document the infected plugin/theme file(s) and the exploit used.
• Core, theme and plugin updates performed safely, along with removal of any abandoned or vulnerable code.
• Hardening actions: secure wp-config, correct file permissions, lockdown of xml-rpc if advisable, strong login protection (2FA, reCAPTCHA, rate limiting), and .htaccess tweaks.
• Installation and basic configuration of an ongoing monitoring solution with daily automated scans and email alerts.
• A concise post-engagement report summarising work done, recommendations for best practices, and confirmation that the site is malware-free.
No design work is needed — just security expertise that gets the site back up fast and keeps it safe long-term.
What I need now is a thorough, professional cleanup followed by solid hardening so this doesn’t happen again. I’ve already taken the site offline temporarily and have a cPanel backup ready to restore if required. SSH, SFTP, phpMyAdmin and wp-admin access will be provided immediately when we start.
Deliverables
• Complete malware removal from all files and database tables, with a final clean scan report (Wordfence, Sucuri or a comparable tool).
• Identification of the entry point — please document the infected plugin/theme file(s) and the exploit used.
• Core, theme and plugin updates performed safely, along with removal of any abandoned or vulnerable code.
• Hardening actions: secure wp-config, correct file permissions, lockdown of xml-rpc if advisable, strong login protection (2FA, reCAPTCHA, rate limiting), and .htaccess tweaks.
• Installation and basic configuration of an ongoing monitoring solution with daily automated scans and email alerts.
• A concise post-engagement report summarising work done, recommendations for best practices, and confirmation that the site is malware-free.
No design work is needed — just security expertise that gets the site back up fast and keeps it safe long-term.