Secure & Redeploy PHP Real-Time System

Job ID: 40205886

Budget: $250 – $750 USD

My web backend already handles real-time WebSocket traffic and device-to-server messaging, but the client management module now needs immediate attention. The current codebase shows signs of SQL injection issues and server misconfigurations, and an initial scan hints at possible backdoors.

Here’s what I need you to do:

• Conduct a full security audit across the PHP + MySQL stack (running on Apache in a XAMPP-style setup) as well as the Node.js WebSocket layer.
• Isolate and remove any backdoors, patch every SQL-injection entry point you uncover, and fix configuration mistakes that could expose the server.
• Redeploy the cleaned code on a fresh, standard Linux server image, migrate the database where necessary, and confirm that all WebSocket real-time features reconnect flawlessly.
• Stress-test the updated system—especially the client management workflows—to be sure performance and stability match production expectations.
• Deliver a concise report summarising every vulnerability found, the patch applied, and post-deployment test results.

I’ll provide SSH access to a staging machine that mirrors production, along with the existing repositories and deployment scripts. Once your report is approved, we’ll schedule a final production push.

If you’re comfortable diving deep into native PHP, MySQL/MariaDB, Apache configs, and Node.js websockets, let’s lock this down and get everything back online securely.