Clean WordPress Redirect Malware

Job ID: 40427075

Budget: $30 – $250 AUD

My WordPress site pushes visitors to random third-party pages. The core pages, posts, and media are all still in place. I have full access to wp-admin, files (FTP/SFTP), and the database, yet I haven’t attempted any fixes, scans, or plugin installs, so the environment is untouched and ready for investigation.

What I need is a thorough malware audit and cleanup:
• Pinpoint and remove every injected script, backdoor, or rogue .htaccess rule causing the redirects.
• Scan theme, plugins, uploads, and database tables for obfuscated code—tools like Wordfence CLI, Sucuri SiteCheck, or equivalent are fine as long as the site leaves 100 % clean.
• Patch the entry point, harden wp-config.php permissions, and tighten file ownership so the issue doesn’t return.
• Deliver a brief report outlining what was found, what was fixed, and any ongoing security steps I should take (plugin updates, weekly scans, backups, etc.).

Acceptance criteria: no further redirects under load testing, Google Safe Browsing shows the domain as clean, and an on-demand Wordfence scan returns zero critical issues.

Ready to grant credentials immediately and keen to get the site stable again today.