Clean Hacked WordPress, Remove Redirects

Job ID: 40199755

Budget: $30 – $250 AUD

My WordPress site (scottportelli.com) is currently redirecting visitors to spam domains. The defacement is limited to my blog page (scottportelli.com/blog) that I can see. I rolled back to the latest backup from one month prior, yet the infection persists, so the payload is likely sitting somewhere in the files or database.

Deliverables
• Identify and eliminate every malicious redirect script or database entry.
• Provide a brief report of the compromised files/URLs and what was done to patch them.
• Update core, theme, and plugins safely and patch any vulnerable components.
• Configure a reputable security plugin (Wordfence, Sucuri, iThemes Security—whichever you prefer) with sensible firewall rules and automated scans.
• Add basic hardening (stronger .htaccess rules, disable file editing, salted keys refresh, etc.).
• Final confirmation that the site loads normally, with no redirects detected in popular scanners (Google Safe Browsing, VirusTotal, Sucuri SiteCheck).

Please let me know your estimated turnaround and any server-side access you’ll need beyond WordPress admin so I can arrange it right away.