WordPress & GSC Security Cleanup

Job ID: 40403035

Budget: $250 – $750 AUD

Our WordPress/Elementor install and its connected Google Search Console property were compromised this week. I have already spotted an unfamiliar user account in Google, but I have not yet determined the full extent of the damage.

Here is what I need from you:

• Conduct a full security audit of both WordPress (core, themes, plugins, database, file system) and our Search Console settings.
• Remove every malicious file, backdoor and rogue user you uncover, then bring WordPress, plugins and themes up-to-date.
• Review Google’s warning emails with me, reverse any unauthorised edits they reference and request re-indexing when clean.
• Activate and configure two-factor authentication for WordPress logins and for the Search Console account, plus recommend any additional hardening steps (firewall rules, login rate-limiting, reCAPTCHA, etc.).
• Verify whether a clean backup exists; if not, create a fresh, tested backup once the site is fully secured.
• Configure automated site backups on a schedule once the site has been secured.
• Provide a concise report that lists what you found, what you removed or fixed, and concrete steps I should follow to keep the site locked down.

I’m unsure whether customer or financial data was exposed, so please treat all information as potentially sensitive and document any indicators of data leakage you find.

I’ll supply admin credentials and Google messages as soon as we start.

Deliverables are considered accepted when the site scans clean, no unwanted users remain, Search Console no longer flags issues, and 2FA is working for all admin accounts.