Clean Hacked WordPress Food Site
Budget: $30 – $250 USD
My WordPress-based food blog has been compromised. Unwanted Google ads now appear across the pages even though I never configured AdSense, so the intruder clearly slipped code into the theme or database. I can no longer log in with confidence—I honestly don’t remember if the admin password was ever changed—and, to make matters worse, I have no recent backups to roll back to. Only a couple of basic security plugins are running, but they clearly weren’t enough.
Here’s what I need:
• Remove every trace of the injected ad code and confirm no rogue plugins, themes, or database entries remain.
• Regain full dashboard access under a fresh, secure admin user.
• Trace and patch the backdoor—whether it’s a vulnerable plugin, weak file permissions, or core modification—so the site stays clean.
• Hard-harden the installation: update WordPress core, themes, and plugins; configure a stronger firewall rule set (e.g., Wordfence, Sucuri, or a solution you trust); enforce strong credentials; disable XML-RPC if appropriate.
• Generate and hand over a clean backup once the job is finished.
I’ll provide hosting credentials as soon as we start. The site must load without ads, warnings, or security flags, and it should pass an external malware scan before we consider the work complete.
Here’s what I need:
• Remove every trace of the injected ad code and confirm no rogue plugins, themes, or database entries remain.
• Regain full dashboard access under a fresh, secure admin user.
• Trace and patch the backdoor—whether it’s a vulnerable plugin, weak file permissions, or core modification—so the site stays clean.
• Hard-harden the installation: update WordPress core, themes, and plugins; configure a stronger firewall rule set (e.g., Wordfence, Sucuri, or a solution you trust); enforce strong credentials; disable XML-RPC if appropriate.
• Generate and hand over a clean backup once the job is finished.
I’ll provide hosting credentials as soon as we start. The site must load without ads, warnings, or security flags, and it should pass an external malware scan before we consider the work complete.