WordPress VPS Malware Cleanup & Hardening
Budget: $250 – $750 USD
My VPS hosts a little over twenty WordPress installations and the whole server is now riddled with spam links and other malware. Even though a firewall, ClamAV-based antivirus, and routine security monitoring are already in place, the intrusion has spread across every site.
What I need first is a thorough, manual cleanup of each WordPress instance—core files, themes, plugins, and database tables—so the sites can return to normal operation without breaking functionality. I do have backups, but I suspect they carry the same infection, so please factor that in when you plan your approach.
If, during your audit, you find that a clean-in-place strategy isn’t realistic, I’m open to spinning up a brand-new server and migrating only verified-clean data. Guidance on the safest migration workflow will be appreciated.
Deliverables
• Detailed scan and removal of all malicious code, spam content, backdoors, and rogue cron jobs across ~20 sites
• Post-cleanup report listing every file and database change, plus the root cause you identify
• Hardening steps applied (wp-config keys, file permissions, updated plugins, Web Application Firewall rules, fail2ban tweaks, etc.)
• Recommendations on using or discarding my current backups and, if needed, a phased migration plan to a fresh VPS
Acceptance Criteria
– All sites load without malware warnings from Google Safe Browsing or security scanners
– No suspicious outbound traffic or reinfections observed after 48-hour monitoring
– Clear documentation so I can maintain the environment going forward
Please outline the tools and methods you’d use (e.g., WP-CLI, ImunifyAV, custom scripts) and an estimated timeline for the full cycle from audit through final sign-off.
What I need first is a thorough, manual cleanup of each WordPress instance—core files, themes, plugins, and database tables—so the sites can return to normal operation without breaking functionality. I do have backups, but I suspect they carry the same infection, so please factor that in when you plan your approach.
If, during your audit, you find that a clean-in-place strategy isn’t realistic, I’m open to spinning up a brand-new server and migrating only verified-clean data. Guidance on the safest migration workflow will be appreciated.
Deliverables
• Detailed scan and removal of all malicious code, spam content, backdoors, and rogue cron jobs across ~20 sites
• Post-cleanup report listing every file and database change, plus the root cause you identify
• Hardening steps applied (wp-config keys, file permissions, updated plugins, Web Application Firewall rules, fail2ban tweaks, etc.)
• Recommendations on using or discarding my current backups and, if needed, a phased migration plan to a fresh VPS
Acceptance Criteria
– All sites load without malware warnings from Google Safe Browsing or security scanners
– No suspicious outbound traffic or reinfections observed after 48-hour monitoring
– Clear documentation so I can maintain the environment going forward
Please outline the tools and methods you’d use (e.g., WP-CLI, ImunifyAV, custom scripts) and an estimated timeline for the full cycle from audit through final sign-off.
Related categories:
Linux
Web Security
WordPress
Education
MySQL
VPS
Documentation
Database Management