Discover how Vollna optimizes your freelancing projects on Upwork with advanced filters for specialized tasks like WordPress Malware Removal. Get real-time updates and insights to maximize success and efficiency.
Signup for free
to get access to all filter attributes and instant notifications when new jobs are posted.
Setup filter
Get access to over 30+ filter attributes, setup instant notifications, integrate with your CRM and marketing tools, and more.
Fix hacked server and WordPress site ASAP!
Applied
$14 - $28
/ hr
23 hours ago
Client Rank
- Excellent
Payment method verified
$30 414 total spent
187 hires, 1 active
177 jobs posted
100% hire rate,
1 open job
10.98 /hr avg hourly rate paid
424 hours paid
4.97
of 153 reviews
Registered: Mar 11, 2016
United States
Sacramento
14:18
5
Please tell me your FIXED price to fix it.
I did a WordPress No, No, and didn't keep my plugins updated m my site https://LEADSPROUTS.co got screwed up, started using tons of cpu on the server. Hosting company locked it until it was fixed.
I did a backup restore, seemingly fixing the problem.. but a week later it's back to being screwed up. My subdomain site is also going REALLY slow, so my other server items may be affected.
Need someone who can login NOW and restore everything.
My firm website needs to be updated/modernized with blogging and AI chat Also had some issues with prospects scheduling appointments. I think I have landing pages but if not, I want to have three. After that, to do some SEO/marketing, but first things first. Our website is ...haddadlawoffices.com.
Customize color system and branding for Dokan Dashboard in WP admin.
**If you think this will take longer than 8 hours, please let me know and we can adjust.**
Remove dokan logo from top,
change icon colors to: #d04e2f
change button colors to: #d04e2f
change main background color to: #1c1410
If possible, could we completely remove top taskbar ONLY for user gordon, that way he doesnt see version info, create a ticket, etc.
If you need an icon pack to replace the icons instead of change color, let me know and I can send one over.
Here is a loom video for everything: https://www.loom.com/share/ff1278aa84574ad89efdd02779a81626
My domain and subdomains are flagged as dangerous by Google's Safe Browsing. I need someone to check and fix the issues. The ideal candidate will have experience in website security and be able to identify and resolve problems that are causing these flags. This is a part-time project with a short duration, requiring an intermediate level of proficiency.
Client's questions:
How many projects have you done related to the Google Safe Browsing warning?
Have you worked with WordPress malware detection tools?
How many years of experience do you have with similar projects?
Hourly rate:
15 - 25 USD
1 day ago
IT & Networking, Information Security & Compliance
WordPress Malware Removal | Web Security | Site Migration | SSL expert
Applied
not specified
1 day ago
Client Rank
- Risky
Payment method not verified
4 jobs posted
1 open job
no reviews
Company size: 100
Registered: Jun 4, 2019
Philippines
Muntinlupa
05:18
1
Our website is down for quite a long time now and has a problem at its back end. We are using WordPress for our website.
The job I'm offering will be as an IT support professional for troubleshooting, recovery and maintenance of our website.
Budget:
not specified
1 day ago
IT & Networking, Information Security & Compliance
SilverBrook Engineering Webpage Development
Applied
not specified
1 day ago
Client Rank
- Risky
Payment method not verified
Phone number verified
1 open job
United States
16:18
1
Please review the attached images from Chat that capture the essence of the webpage I'm trying to create for my new company. Please provide a quote to develop this layout in WordPress ($XX/hr times ?? hours). I've purchased the URL for this new company from GoDaddy.com and now need the layout developed within WordPress.
I can see this project growing, with additional support needed from whomever I select to perform this work as I add case studies and additional information to the website.
Malware detection and resolve on Wordpress
Applied
$50
3 days ago
Client Rank
- Excellent
Payment method verified
$12 806 total spent
34 hires, 7 active
28 jobs posted
100% hire rate,
3 open job
9.59 /hr avg hourly rate paid
409 hours paid
4.91
of 21 reviews
Industry: Sales & Marketing
Company size: 2
Registered: Jun 1, 2022
Canada
Bedford
17:18
5
We have 2 websites that have been found to have malware and I am looking for someone to help detect it and remove it. One seems to be fake captcha. Please apply if you are serious and can help right away.
Fixed budget:
50 USD
3 days ago
IT & Networking, Information Security & Compliance
m the owner of Sagerlabs, a marketing agency. Our Instagram business account was recently disabled by Meta, which we believe was a wrongful ban — our account was used solely for legitimate professional marketing for global and regional brand clients.
We are looking for someone with proven experience recovering disabled Meta/Instagram business accounts to help us appeal this decision and restore access.
Please only reach out if you have verifiable past success with similar cases. We are happy to discuss your process and fee.
Important: Automated malware scanners alone are not sufficient. We are looking for a manual forensic investigation to identify the original attack vector and all persistence mechanisms, ensuring the compromise cannot return. This is the highest priority.
We are looking for an experienced **Linux server security and WordPress malware removal expert** to investigate and completely clean a compromised VPS hosting multiple WordPress websites.
The server has already had passwords changed and basic cleanup performed, however the compromise persists. Malicious code continues to be injected into website files (including `.htaccess`), indicating that the attacker still has a method of regaining access.
We are looking for someone who can identify the root cause, completely eliminate the compromise, and secure the server to prevent future reinfections.
## Environment
* VPS hosted with Namecheap
* Linux server
* Multiple WordPress websites
* SSH access available
* Root access available
## Scope of Work
### 1. Full Security Investigation
* Determine how the server was compromised
* Identify every persistence mechanism used by the attacker
* Review system logs
* Review SSH access
* Review cron jobs
* Check startup scripts and scheduled tasks
* Inspect all websites for backdoors
* Identify vulnerable plugins, themes or outdated software
* Verify there are no malicious Linux users, SSH keys or hidden services
### 2. Website Cleanup
* Remove all malware and malicious code
* Remove web shells and hidden PHP files
* Clean infected `.htaccess` files
* Verify WordPress core integrity
* Verify plugins and themes
* Remove injected JavaScript or redirects
* Ensure every hosted website is clean
### 3. Server Hardening
* Close the security hole that allowed the compromise
* Harden the VPS against future attacks
* Secure SSH
* Review file permissions
* Configure firewall if necessary
* Disable unnecessary services
* Apply security best practices
### 4. Password & Credential Review
Review and advise on any credentials that should be rotated, including:
* Create a verified clean backup of the entire hosting environment
* Ensure the backup can be restored if needed
### 6. Documentation
Provide a short report including:
* How the compromise occurred
* Files that were infected
* What was removed
* What security improvements were made
* Recommendations to prevent future compromises
## Required Experience
Please apply only if you have experience with:
* Linux server administration
* VPS security
* WordPress malware removal
* WordPress forensics
* Apache/Nginx
* SSH
* Malware persistence
* Root cause analysis
## When Applying
Please include:
* Similar compromised VPS recoveries you have completed
* Your approach to identifying persistent infections
* Your estimated timeline
* Your fixed price or hourly rate
This project requires finding the **root cause** of the compromise—not simply deleting infected files. The work will be considered complete only when the server is fully cleaned, hardened, verified, and a clean backup has been created.
Funds will be released after 7 days of job completion to make sure that the issue does not reoccur
Fixed budget:
100 USD
3 days ago
IT & Networking, Information Security & Compliance
URGENT: WordPress Malware and Server Security Expert Needed for Persistent Reinfection
Applied
not specified
3 days ago
Client Rank
- Excellent
Payment method verified
$291 992 total spent
363 hires, 21 active
598 jobs posted
61% hire rate,
1 open job
5.39 /hr avg hourly rate paid
48 565 hours paid
4.95
of 298 reviews
Registered: Nov 13, 2009
United States
Irvine
18:18
5
We are looking for an experienced WordPress malware removal and server security specialist to investigate and permanently resolve a recurring malware issue affecting a WordPress environment.
This is not a basic malware cleanup. We need someone who can identify the root entry point, persistence mechanism, and source of reinfection, then secure the environment to prevent the issue from returning.
Issue Summary
A WordPress website was compromised with casino/iGaming spam and unauthorized administrative activity.
A fake cloudflare/recaptcha/ Clickfix showing on windows users
- 1. ClickFix JavaScript injection Source found: wp-content/mu-plugins/index.php
- 2. Casino/iGaming spam posts Source found: published WordPress posts
During the incident:
- Legitimate pages, including the homepage, were moved to the trash.
- Installing unwanted plugins.
- Adding zip file in media library
- Media files deleted
- Created hidden a admin account
- The WordPress front-page setting was changed to display the blog roll.
- Casino and iGaming spam posts were created and published.
- Some spam posts appeared to have been scheduled in advance.
- Activity was recorded under legitimate WordPress usernames, but the associated IP addresses were unfamiliar and changed between actions.
- Suspicious administrator accounts have previously been created through injected code.
- Malicious code has appeared in different locations during separate incidents.
- The activity returned within hours of an initial cleanup, password change, and WordPress salt reset.
Work Already Completed
Our internal team has already:
- Inspected and cleaned suspicious WordPress files.
- Removed identified injected code.
- Replaced the wp-admin and wp-includes directories with clean WordPress copies.
- Updated WordPress core, PHP, plugins, and available components.
- Reset WordPress salts to invalidate active sessions.
- Changed passwords for available WordPress accounts.
- Changed database username and password.
- Reviewed themes, plugins, cache folders, core files, and functions.php.
- Reviewed WordPress activity logs, usernames, and IP addresses.
- Ran Wordfence using high-sensitivity scan settings.
- Requested a server-level scan from the hosting provider.
- Wordfence and hosting support reported that no malware was detected after the cleanup. However, the unauthorized activity returned afterward, indicating that the persistence mechanism may not be detectable through standard malware scans.
What We Need Investigated
We need the selected specialist to investigate possible sources including:
- Hidden or obfuscated PHP backdoors.
- Rogue cron jobs or scheduled server processes.
- WordPress cron events and scheduled posts.
- Must-use plugins or hidden plugins.
- Malicious theme or plugin code.
- Modified WordPress core files.
- Database-level injections or unauthorized options.
- Hidden or automatically recreated administrator accounts.
- Compromised WordPress credentials.
- Stolen cookies or hijacked WordPress sessions.
- Compromised API keys, application passwords, or authentication tokens.
- Vulnerable, outdated, nulled, or abandoned plugins and themes.
- Compromised hosting, server, SFTP, SSH, control panel, or database credentials.
- Infected local devices or browser sessions used to access WordPress.
- Cross-site or cross-account contamination within the hosting environment.
- The specialist should not rely only on Wordfence or automated malware scans.
Required Deliverables
The project must include:
- A full WordPress and server-level security audit.
- Identification of the original entry point, where technically possible.
- Identification and removal of all persistence mechanisms.
- Review of server cron jobs, WordPress cron events, database records, users, plugins, themes, and core files.
- Review of authentication logs, access logs, IP activity, sessions, and account usage.
- Removal of malicious files, accounts, scripts, database entries, and scheduled processes.
- Credential and session security recommendations.
- Hardening of WordPress and the server environment.
- Verification that clean files come from trusted and official sources.
- A monitoring plan to confirm that the malware does not return.
A written report explaining:
What was found
- How the attacker likely gained access
- How persistence was maintained
- What was removed or changed
- What was done to close the entry point
- What preventive controls should be implemented
- We do not want a final report that only says the files were cleaned. We need a clear explanation of the root cause and how it was addressed.
Required Experience
Please apply only if you have proven experience with:
- Persistent or recurring WordPress malware.
- PHP malware analysis and deobfuscation.
- WordPress and Linux server security.
- Cron jobs and scheduled-task investigation.
- WordPress database security.
- Session hijacking and compromised account investigations.
- Hosting and web-server log analysis.
- WordPress hardening after a breach.
- Incidents where automated scanners reported a site as clean despite continued unauthorized activity.
- Experience with managed WordPress hosting, VPS environments, Cloudflare, Nginx, Apache, SSH, SFTP, WP-CLI, and MySQL is highly preferred.
Access and Confidentiality
- No credentials or confidential client information will be included in the public job post.
- The selected freelancer may be provided with restricted and temporary access to the relevant systems after appropriate confidentiality and access-control measures are agreed upon.
- All findings, client information, credentials, files, and security details must remain confidential.
Application Questions
Please answer the following when applying:
- Have you handled a WordPress infection that returned after a full cleanup?
- How do you investigate malware when Wordfence and hosting scans report the site as clean?
- How would you check for rogue cron jobs, hidden plugins, database persistence, and session hijacking?
- What logs and access would you require?
- How would you determine whether the issue originated from WordPress, the hosting environment, credentials, or a compromised device?
- Can you provide a written root-cause and remediation report?
Please share examples of similar investigations, without exposing confidential client information.
We are looking for someone who can begin with the investigation promptly and provide clear updates throughout the process.
Budget:
not specified
3 days ago
IT & Networking, Information Security & Compliance
We are looking for an experienced WordPress Security Expert to investigate and permanently resolve a recurring malware issue on our SiteGround server.
Our SiteGround hosting account contains multiple WordPress websites, and SiteGround's Security Scanner continues to detect malware and quarantine files, even after cleanup attempts. We need someone who can identify the root cause and ensure the issue does not reoccur.
Scope of Work:
Investigate the source of recurring malware infections.
Clean all infected WordPress websites on the server.
Identify compromised files, plugins, themes, or backdoors.
Remove malicious code and hidden malware.
Check file permissions, cron jobs, database injections, and user accounts.
Scan the entire hosting account, not just a single website.
Determine whether the issue is caused by a vulnerable plugin/theme, server configuration, or cross-site infection.
Secure all WordPress installations to prevent future infections.
Provide a summary of findings and recommendations.
Required Experience:
Strong experience with WordPress malware removal.
Experience securing SiteGround-hosted WordPress websites.
Knowledge of malware detection, backdoors, shell scripts, and WordPress security best practices.
Familiarity with server-level security and cross-site contamination in shared hosting environments.
have an older mobile phone, and with the appropriate consent, I’d like a forensic examination of it. The goal is to identify any calls, text messages, WhatsApp messages, or recoverable deleted communications from the last three years involving two specific phone numbers, and to flag any other unusually frequent contacts.
I’m looking for someone experienced in mobile phone forensics who can handle the device securely, explain what can realistically be recovered, and provide a clear summary of the findings. Please confirm your method, confidentiality arrangements, turnaround time, and fixed price.
Budget:
not specified
3 days ago
IT & Networking, Information Security & Compliance
WordPress Malware Removal and Security Recovery
Applied
$15 - $25
/ hr
4 days ago
Client Rank
- Excellent
Payment method verified
$58 110 total spent
219 hires, 67 active
211 jobs posted
100% hire rate,
1 open job
7.33 /hr avg hourly rate paid
6 307 hours paid
4.80
of 300 reviews
Registered: Dec 3, 2013
United Arab Emirates
Ajman
01:18
5
I require an experienced WordPress malware-removal specialist to:
- Preserve a full backup of the current website and database before making changes.
- Inspect WordPress files, the database, users, plugins, themes, WP-Cron and server cron jobs.
- Identify and remove malware, backdoors, injected code, unauthorized users and spam content.
- Determine how the unauthorized posts are being created and stop the automated process.
- Replace WordPress core files and reinstall plugins and themes from clean, trusted sources where necessary.
- Review wp-config.php, .htaccess, advanced-cache.php, cache folders, upload folders and must-use plugins.
- Check whether other websites or directories within the same hosting account are affected.
- Coordinate with the hosting provider where access to server logs or account-wide scanning is required.
- Preserve all legitimate historical posts, pages, images and website functionality.
- Harden the website after cleanup, including password reset guidance, security salts, two-factor authentication, backups and monitoring.
- Provide a written report listing:
the malware and suspicious files found;
unauthorized database entries or accounts found;
files changed or replaced;
cron tasks removed;
probable entry point, if identifiable;
steps taken to prevent recurrence.
Client's questions:
Describe your recent experience with similar projects
Hourly rate:
15 - 25 USD
4 days ago
IT & Networking, Information Security & Compliance
My WordPress site has been hit by malware and I can no longer log in to wp-admin. I need the infection completely cleaned, the original functionality restored, and the root cause addressed so it doesn’t happen again.
You’ll have SSH, cPanel or FTP access (whichever you prefer) as soon as we start. I expect you to run a deep scan across core files, themes, and the database, eliminate every malicious script or backdoor, then harden the installation—updating WordPress, themes, and plugins where safe to do so, tightening permissions, and adding a firewall rule set.
Deliverables
• Clean, fully functioning WordPress site with wp-admin access restored
• Brief security report summarising what was found, what you removed, and any preventive steps you implemented or recommend
If you can get everything back online quickly and prove the site is clean, that will wrap the job.
I own a WordPress website hosted on Bluehost for my HVAC company, Turbo Home Services LLC.
I suspect that a former marketing contractor may still have access to the website. I have been unable to regain administrator access through WordPress, and some Bluehost website management functions are not working correctly. Before making any website changes or redesigns, I need an experienced WordPress security specialist to audit, secure, and restore full ownership of my website.
This is **not** a website redesign project. My priority is to secure the existing website and ensure I have complete control.
Scope of Work
Please complete the following:
Access & Ownership
* Verify I have full ownership of the website, hosting account, and WordPress installation.
* Create a new WordPress Administrator account under my email.
* Verify that I can successfully log in.
Security Audit
* Review all administrator accounts.
* Remove any unauthorized users or accounts.
* Audit user roles and permissions.
* Check for hidden administrator accounts.
Malware & Backdoor Scan
* Scan the website for malware.
* Check for backdoors.
* Inspect:
* Review Bluehost account access.
* Verify no unauthorized FTP/SFTP users exist.
* Verify database users.
* Check DNS settings if necessary.
Backup
Before making changes:
* Create a complete backup of the website.
* Create a complete database backup.
Recommendations
Provide a brief report including:
* Any vulnerabilities discovered.
* What was fixed.
* Remaining security concerns.
* Recommendations to prevent future unauthorized access.
Deliverables
At project completion I expect to have:
* Full WordPress administrator access.
* Confirmation that unauthorized access has been removed.
* A clean malware/security scan.
* A full website backup.
* Documentation of all work completed.
1. A brief description of similar WordPress security projects you've completed.
2. Your experience recovering hacked or compromised websites.
3. Approximately how many hours you expect this project to take.
4. Your availability to begin this week.
**Important:** I am looking for a security specialist, not a web designer or SEO agency. There may be additional work available after this project if everything goes well.
Fixed budget:
500 USD
6 days ago
IT & Networking, Information Security & Compliance
Your WordPress debugging and WooCommerce experience looks relevant.
Our website repeatedly reaches its PHP-FPM limit of 20 workers:
server reached max_children setting (20)
the server has sufficient resources. We need to identify which long-running PHP requests, database queries, cron jobs, plugins or bot traffic are exhausting the workers.
i have malware on a server linux and need it removed via SSH. is that something you can help me with. The malware was highlighted my imunify but required removal of crontabs etc
Technical SEO Audit + On-Page Optimization for Ecommerce Site
Applied
not specified
7 days ago
Client Rank
- Excellent
Payment method verified
Phone number verified
$102 399 total spent
8 hires, 6 active
2 jobs posted
100% hire rate,
1 open job
23.84 /hr avg hourly rate paid
4 089 hours paid
5.00
of 3 reviews
Registered: May 3, 2023
United States
Boerne
16:18
5
Scope of Work:
Technical SEO Audit
Site speed & Core Web Vitals check
Crawl errors, broken links, 404s
XML sitemap check/fix
Robots.txt review
Mobile responsiveness check
Duplicate content / thin content check
Indexing issues (Google Search Console)
On-Page SEO
Keyword research (main + long-tail keywords for my niche)
Title tags, meta descriptions, header tags (H1, H2) optimization
Internal linking structure
Image alt text optimization
URL structure review
Schema Markup
Basic structured data setup (product/organization schema, depending on site type)
Deliverables
Full audit report (issues found + fixes done)
Before/after summary
Keyword list used
Recommendations for next phase (content/link building)
Requirements:
Must know Google Search Console, Google Analytics, and one SEO tool (Ahrefs/SEMrush/Screaming Frog)
Experience with ecommerce sites (Shopify/WordPress) preferred
Must explain fixes in simple terms, not just jargon
White-hat SEO only
We are seeking a skilled freelancer to remove unwanted pages from a WordPress site. The site appears to have been compromised and installed as a spurious website. The ideal candidate will have experience in WordPress and security to identify and eliminate these issues effectively. Attention to detail and a thorough understanding of WordPress functionality are essential.
Acess to hostinger ,wordpress and google search console available .
would prefer them to do this online mode.
the website is www.orcan.com
My WordPress website has been hacked or infected with malware, and I need an experienced WordPress security expert to clean it up.
Scope of Work:
Remove all malware, malicious code, and backdoors.
Identify how the website was compromised.
Restore the website to a clean and secure state.
Update WordPress, plugins, and themes if needed.
Scan the entire website to ensure it is malware-free.
Implement basic security hardening to help prevent future attacks.
Verify the website is fully functional after cleanup.
Requirements:
Proven experience with WordPress malware removal and security.
Strong knowledge of PHP, WordPress, hosting environments, and website security.
Ability to start immediately.
When applying, please include:
Your experience with hacked WordPress websites.
The tools or methods you use for malware detection and cleanup.
Your estimated completion time.
I'm looking for someone who can resolve this quickly and professionally.
Hi, I’m looking for help recovering my own Instagram account. I lost access to it and I’d like assistance with the legitimate recovery process. Have you helped clients recover Instagram accounts before? If so, what information would you need, how long does it usually take, and what would the cost be?
Budget:
not specified
9 days ago
IT & Networking, Information Security & Compliance
WordPress Malware Removal and Security Hardening for Business Site
Applied
not specified
10 days ago
Client Rank
- Excellent
Payment method verified
$48 335 total spent
15 hires, 20 active
15 jobs posted
100% hire rate,
1 open job
17.12 /hr avg hourly rate paid
1 213 hours paid
no reviews
Industry: Sales & Marketing
Company size: 2
Registered: May 5, 2025
United States
Orland Park
16:18
5
Job Description:
I am looking for an experienced WordPress Security Expert to clean and secure my website hosting platform immediately. My hosting provider has identified multiple malicious files and web shells on my server, and the site is currently disabled to prevent further issues.
What I need:
Full Cleanup: Remove all identified malware, backdoors, and malicious scripts from my server and database.
Root Cause Analysis: Identify and close the entry point (vulnerable plugin/theme/config) that allowed this breach.
Hardening: Implement security best practices to prevent future re-infection (e.g., WAF configuration, file permission audits, hardening the wp-config.php).
Verification: Confirm that the site is clean and safe to return to production.
Required Experience:
Proven experience in manual malware removal (not just running a scanner).
Expertise in investigating server logs and identifying hidden backdoors.
Strong knowledge of WordPress security, PHP, and cPanel/server-side environments.
When applying, please include:
A brief overview of your experience with similar WordPress malware incidents.
What tools or methodology you use for deep cleaning.
Your estimated timeline for a full cleanup.
Budget:
not specified
10 days ago
IT & Networking, Information Security & Compliance
I had malware on my website's blog that was publishing spam posts. I hired someone to fix the issue but now the entire website appears to be affected. Many pages are broken or displaying incorrectly and I can no longer access the WordPress admin dashboard.
I'm looking for someone who's expert to fix this. I need a permanent solution and not a quick fix.
Fixed budget:
40 USD
10 days ago
IT & Networking, Information Security & Compliance