WordPress Malware Audit & Cleanup
Budget: $250 – $750 USD
My main concern right now is wiping out every trace of malware or hidden backdoor on Callemout.vip. I need a seasoned WordPress security expert who can dive in, run a full-stack scan, and leave the site spotless and hard-to-break into.
Here’s exactly what I expect you to handle:
• Run comprehensive malware and backdoor scans, then surgically remove anything malicious you uncover.
• Track down and delete any rogue admin accounts or stealth user roles.
• Inspect every plugin, theme, and core file for injected code or unsafe modifications. I’m not sure which component might be compromised, so assume everything is fair game for inspection.
• Hunt for sneaky cron jobs, scripted redirects, or obfuscated payloads that could resurrect the infection.
• Lock down wp-config.php, .htaccess, and any other critical config files.
• Harden the login process—rate-limit brute-force attempts, disable file editing from the dashboard, and apply your go-to best practices.
• Deliver a fully documented report of your findings and each fix you apply. I want to know what you changed and why.
Conditions you must respect:
• Do not create extra admin users unless I give written approval.
• You will be working under restricted access—expect to coordinate with me for credentials or staging.
• No shortcuts: the site must stay clean after your work, with zero persistent access left behind.
Final deliverable: a clean, secure Callemout.vip plus your detailed remediation log so I can keep track of everything done.
Here’s exactly what I expect you to handle:
• Run comprehensive malware and backdoor scans, then surgically remove anything malicious you uncover.
• Track down and delete any rogue admin accounts or stealth user roles.
• Inspect every plugin, theme, and core file for injected code or unsafe modifications. I’m not sure which component might be compromised, so assume everything is fair game for inspection.
• Hunt for sneaky cron jobs, scripted redirects, or obfuscated payloads that could resurrect the infection.
• Lock down wp-config.php, .htaccess, and any other critical config files.
• Harden the login process—rate-limit brute-force attempts, disable file editing from the dashboard, and apply your go-to best practices.
• Deliver a fully documented report of your findings and each fix you apply. I want to know what you changed and why.
Conditions you must respect:
• Do not create extra admin users unless I give written approval.
• You will be working under restricted access—expect to coordinate with me for credentials or staging.
• No shortcuts: the site must stay clean after your work, with zero persistent access left behind.
Final deliverable: a clean, secure Callemout.vip plus your detailed remediation log so I can keep track of everything done.