Efficient WordPress Malware Removal Tasks
Discover how Vollna optimizes your freelancing projects on Upwork with advanced filters for specialized tasks like WordPress Malware Removal. Get real-time updates and insights to maximize success and efficiency.
Signup for free
to get access to all filter attributes and instant notifications when new jobs are posted.
Setup filter
Get access to over 30+ filter attributes, setup instant notifications, integrate with your CRM and marketing tools, and more.
Start free trial
71 projects
published for past 72 hours.
| Job Title | Budget | Published | |||
|---|---|---|---|---|---|
|
Owner/CEO
Applied
|
not specified | 8 minutes ago |
1
|
||
|
Looking for great talent to complete the second phase which is the development of my MVP.
Budget:
not specified
8 minutes ago
|
|||||
|
Website compromised down -suspected sql injection - hosted via ventraip
Applied
|
not specified | 11 hours ago |
1
|
||
|
My websites hosted on ventraip are
https://globalconnectpathways.com.au/ Filotooz.com.au Schoolinozconsulting.com.au Need the sites cleaned.
Budget:
not specified
11 hours ago
|
|||||
|
Senior Web Security & SEO Audit for React Site After WordPress Malware Hack
Applied
|
$120
|
15 hours ago |
3
|
||
|
We need a senior web security / cPanel / technical SEO specialist to perform a final independent audit of thebrothing.com before we submit a Meta/Instagram appeal.
Current situation Our current website is a React/Vite SPA hosted on Apache/cPanel. The domain previously ran an older WordPress website which was historically compromised with casino/gambling SEO-spam URLs. We have already: moved to new hosting uploaded a clean React build scanned the uploaded files with VirusTotal removed the old WordPress environment from production configured known hacked/retired URLs to return 410 configured random/nonexistent URLs to return 404 kept legitimate current pages at 200 preserved legitimate historical redirects as 301 created and submitted a valid sitemap.xml cleaned website copy and removed positive result-guarantee language added disclaimers added Open Graph metadata and og:image verified the domain inside Meta Business confirmed Meta Sharing Debugger can currently fetch the new homepage with HTTP 200 and the correct branding confirmed Google Search Console currently shows no Security Issues and no Manual Actions We are not looking for someone to rebuild or clean the website from scratch. We need an experienced specialist to independently verify that the current production environment is clean, technically correct and safe to use for a Meta appeal. Please audit the following: New hosting / cPanel inspect public_html confirm no old WordPress files remain confirm no malware, backdoors, webshells or suspicious PHP remain inspect .htaccess, .user.ini, php.ini inspect cron jobs inspect FTP/SSH access inspect recently modified PHP files confirm legitimate /api/*.php files are safe React/Vite production build verify source/build is clean inspect compiled JS/CSS for suspicious injected code confirm no casino/loan/pharmacy/adult spam exists in current build confirm no malicious external scripts or redirects HTTP routing Verify: legitimate current pages → 200 legitimate old redirects → 301 known hacked/retired URLs → 410 random/nonexistent URLs → 404 assets/APIs continue to work normally Historical spam verification Search current hosting/build/config for: casino gambling Pokerdom Mostbet BetFlag Plinko Glory Casino Chicken Road payday/loan spam pharmacy spam adult/escort spam Confirm these are not live anywhere on the current hosting. Google Search Console Review: Security Issues Manual Actions URL Inspection Page Indexing Removals sitemap.xml robots.txt canonical tags soft 404s 5xx errors Confirm current legitimate pages are indexable and old hacked URLs are unavailable through 404/410. Sitemap / robots / canonicals verify sitemap.xml contains only legitimate current public URLs verify no spam/retired URLs are included verify robots.txt is valid verify canonicals are correct confirm no old malicious or incorrect canonical URLs remain Crawler consistency Compare: normal browser Googlebot Facebook/Meta crawler Confirm they all see the same legitimate website. Rule out: cloaking bot-only spam mobile-only redirects geo/referrer-based spam DNS / hosting consistency confirm A/AAAA records point to the correct new hosting confirm no old origin/server remains active confirm www/non-www behave correctly confirm Cloudflare, if used, points to the correct origin Meta-facing technical check Verify: current homepage is reachable by Meta correct canonical correct og:title correct og:description correct og:image no casino/spam metadata retired spam URLs do not behave like active business pages Important working rule This is an audit-first job. Do NOT delete or modify anything initially. First send us: findings risks suspicious files/configs screenshots/evidence recommended changes We will approve any changes before you make them. Required final report Please provide a concise PASS/FAIL report for: current hosting clean malware/backdoor/webshell old WordPress remnants suspicious cron/FTP/SSH access casino/SEO spam live loan/pharmacy/adult spam live legitimate pages 200 redirects 301 hacked/retired URLs 410 random URLs 404 sitemap clean robots.txt clean canonicals clean Googlebot cloaking Meta crawler sees clean site Search Console Security Issues Search Console Manual Actions final malware scan Also provide a list of every change made, if any. Please answer these in your proposal: Have you audited a site after a historical WordPress SEO-spam hack? Have you handled casino/gambling spam specifically? Can you audit cPanel beyond simply installing Wordfence? Can you manually inspect PHP for backdoors/webshells? Are you comfortable with React/Vite + Apache? Can you audit Google Search Console after a hacked-site incident? Can you compare Googlebot/Meta crawler responses against a normal browser? How many hours will this final audit take? What fixed price would you quote? Most remediation has already been completed. This project is for final independent verification before appeal, not a full rebuild or malware cleanup from scratch.
Fixed budget:
120 USD
15 hours ago
|
|||||
|
Urgent WordPress malware cleanup needed for persistent PHP/auto_prepend infection
Applied
|
not specified | 1 day ago |
4
|
||
|
I need an experienced WordPress malware/security specialist to clean a hacked WordPress site on Namecheap shared hosting.
This is not a simple plugin issue. Known symptoms/findings: - Browser DevTools shows an injected request to https://forecast-chaos.com/x9i32md/w1/la02 - Malware injects obfuscated inline JavaScript into the homepage - Malicious MU-plugin found at /wp-content/mu-plugins/vista-tracker-ops.php - .user.ini and .htaccess were repeatedly rewritten with auto_prepend_file - Payload files included /wp-content/ed34bae7.php, /wp-content/.ed34bae7.php, and /wp-content/81b7e91f.php - Fake/suspicious plugin wordpesso was found and removed - Imunify360 detected/cleaned backdoor-related files including /wp-content/.sc_15c1a847/core_d1ac14b9.php - The infection has recreated files after WordPress/PHP was triggered I need someone who can: - Find and remove the persistence/backdoor source, not just delete visible malware files - Inspect .user.ini, .htaccess, MU-plugins, wp-content, plugins/themes, uploads, and access logs - Repair or replace infected WordPress core/plugin/theme files safely - Keep the site working if possible - Provide a clear list of files changed/removed and recommended next steps - Advise on credential resets and hardening after cleanup Please reply with: 1. Your experience with WordPress auto_prepend_file malware/backdoors 2. How you would approach this case 3. Whether you can start immediately 4. Estimated time to contain and clean 5. What access you need
Budget:
not specified
1 day ago
|
|||||
|
Promote Youtube Channel
Applied
|
not specified | 1 day ago |
5
|
||
|
Freelancer will promote videos that we produce and post on our youtube platform The promo is intended for organic growth in subscription, views, comments and likes
Budget:
not specified
1 day ago
|
|||||
|
WordPress Security Expert Needed – Persistent Malware / Backdoor & Unauthorized Admin Accounts
Applied
|
$200
|
2 days ago |
5
|
||
|
URGENT!
I am looking for an experienced WordPress malware/security specialist to investigate and permanently clean a compromised WordPress website hosted on Hostinger. The website has already been restored and cleaned several times, but the compromise keeps returning. ________ The site has shown multiple signs of persistent compromise: Unauthorized WordPress Administrator accounts are recreated after being deleted. Random administrator usernames have appeared. Fake-looking administrator accounts using @wordpress.org addresses have appeared. WordPress core files have been modified without authorization. Malicious/suspicious require_once statements were injected into core files such as: wp-includes/functions.php wp-settings.php One injected line attempted to load: wp-content/uploads/cache/readme.css Another attempted to load: wp-includes/ID3/license.txt .htaccess was previously modified with suspicious Googlebot-specific redirects to amp.php. A suspicious amp.php file appeared in the WordPress root. We restored from backup, reinstalled/updated WordPress core, removed suspicious code and deleted unauthorized administrators, but the infection returned. Please start your proposal with the words “PERSISTENT WP” so I know you read the full description.
Fixed budget:
200 USD
2 days ago
|
|||||
|
WordPress Malware Removal & Hardening
Applied
|
~9 - 23 USD
|
2 days ago |
-
|
||
|
My WordPress site is showing signs of infection—odd text shifts have started appearing even though I’m not sure if other functionality has been affected yet. I ran a malware-scanning plugin which flagged multiple infected files, but I need a dev to remove the infected files and make sure there is no malware anymore.
Here’s what I need from you: • Perform a full scan via SSH, cPanel, or preferred tools to locate every malicious file, script, and database entry. • Safely remove or clean those items without breaking the theme, plugins, or core. • Patch whatever vulnerability allowed the intrusion: update WordPress core, themes, plugins, and tighten file permissions. • Add lightweight hardening measures—.htaccess tweaks, login-limit, firewall rules—so this doesn’t happen again. • Supply a concise cleanup report listing what you found, what you removed, and recommendations for future maintenance. The site should load normally, with no hidden redirects or suspicious code remnants, and must pass a fresh malware scan before the job is considered complete. Skills: PHP, Web Security, WordPress, MySQL, Web Hosting, Web Development, Database Management, cPanel
Fixed budget:
8 - 20 EUR
2 days ago
|
|||||
|
Urgent WordPress Malware Removal
Applied
|
$50
|
2 days ago |
5
|
||
|
Need urgent help to identify and remove malware from a WordPress site. The freelancer should be able to scan the site, locate malicious files or code, and clean the infection while ensuring the site remains secure afterward. Experience with WordPress security issues is important, and the work should be completed quickly to minimize downtime and risk. Please share relevant experience and your approach to malware removal.
## WordPress Malware Removal & Security Investigation I need an experienced WordPress security specialist to investigate and clean a suspected malware infection on a live WooCommerce website. Wordfence has detected malicious code inside: `/wp-content/themes/shoptimizer-child-theme/functions.php` Detection: **IOC:JS/fake.analytics.16210 – Fake Google Analytics script hiding malware** The suspicious code is an obfuscated JavaScript injection added to the child theme `functions.php`. ### Important The entire `functions.php` file must **not** be deleted or replaced. It contains important custom WooCommerce code, including our software licence activation system, checkout modifications, customer account creation and other custom functionality. ### Work Required * Back up the website and database before making changes * Safely remove the malicious code without damaging legitimate custom functionality * Perform a full malware scan of all WordPress files and database * Check for backdoors, additional injected files, suspicious PHP/JavaScript and modified core files * Check plugins, themes, MU plugins, uploads, `.htaccess` and `wp-config.php` * Check WordPress administrator accounts for anything suspicious * Check WP-Cron/scheduled tasks for malicious entries * Check hosting/access logs where possible * Investigate how the compromise occurred * Check whether a vulnerable plugin/theme or stolen credential was likely responsible * Update and secure the WordPress installation where appropriate * Run Wordfence again after cleanup * Test WooCommerce checkout, customer accounts and our custom software licence activation system after the work is completed The affected `functions.php` file was showing a modification date of approximately: **6 August 2026 at 11:50 AM** Please investigate activity around this time if logs are available. ### Deliverable I need a short report confirming: * What malware or suspicious code was found * What was removed or repaired * Whether any backdoors were discovered * Likely cause or entry point * Whether any passwords or API credentials should be changed * Recommended security improvements * Confirmation that the site is clean after rescanning This is a live e-commerce website, so experience with **WordPress malware removal, WooCommerce and security forensics** is important. Please only apply if you regularly handle compromised WordPress websites rather than general WordPress development.
Fixed budget:
50 USD
2 days ago
|
|||||
|
Wordpress Malware Cleanup and Optimization
Applied
|
$150
|
2 days ago |
5
|
||
|
So for the past few months I have been hounding my developers to look at my site because server resources kept intermittently maxing out. The site would produce error pages and not load for customers, and then return to normal albeit a bit slow 5 minutes later. Every time something like this happens it means we are under attack. For weeks they said it was fine and nothing is wrong.
3 days ago the site disappeared. Entirely gone. Going to the URL brought you to a wordpress signup page. I restored from a backup and it was working again. Broken and gone again within 24hrs. The database was getting overloaded with slow queries and shutting down. Last night I dove in and removed some stuff that may have been taxing the server and did some cleanup that got the site working again. After what appears to be a caching issue that displayed 404 pages everywhere I once again have the site working. That leads me to where we are today. After hours of cleanup, updating, optimizing, I know without a shadow of a doubt there are malicious files on the site. How do I know this? The server CPU usage is still intermittently maxing out, and there are still slow database queries. The security and other vital caching plugins, wp-admin change URL, were off when I was finally able to access the site. ALSO the biggest red flag- a fake credit card checkout form that only shows up every few refreshes. We use an entirely 3rd party system for entering credit card info. There is no form on our site for this, it is only entered on authorize.net for customer safety. This is to prevent anybody's info from being compromised in the case of the site being compromised. Our security involves hostinger scans, and a paid database cleanup, wordfence premium, and cleantalk. There is also custom code for detecting intruders, quarantining them, etc. Somehow all of these fortified measures were bypassed. But not a single system, wordfence, hostinger, cleantalk, etc says it can detect a single piece of malicious code. I need a real expert to wipe it out COMPLETELY and let me know how to fix it once and for all. I am sick of the constant attacks. We are ALWAYS under attack. I need this done NOW. We are supposed to be running a sale and these continued attacks, crashes, and problems are ruining my time and my customer's experience. apparently most developers can't or won't handle a problem before it becomes a larger issue. For the right person this should be relatively quick and easy. Don't waste my time.
Fixed budget:
150 USD
2 days ago
|
|||||
|
Web design
Applied
|
not specified | 2 days ago |
1
|
||
|
Hi Syed,
I came across your profile and I’m interested in discussing a WordPress/Elementor project with you before hiring. I already have an existing website design that I would like recreated in WordPress with just a little updating and polishing. Would you be willing to review the reference site and provide a free estimate and expected timeline?
Budget:
not specified
2 days ago
|
|||||
|
Social media and Advertisement expert for Shopify store
Applied
|
not specified | 4 days ago |
4
|
||
|
My store setup online location with organized displays, branding elements, and operational systems to ensure smooth functioning. For advertising, I plan to use digital marketing through social media and online ads, along with promotions. Additionally, I aim to implement special promotions and content marketing strategies to attract and retain customers.
Budget:
not specified
4 days ago
|
|||||
|
Shopify Developer
Applied
|
not specified | 4 days ago |
3
|
||
|
Shopify Developer Needed
To join our Dubai-based e-commerce trading company specialising in precious metals, lab-grown diamonds, gemstones and jewellery. You will be responsible for building, maintaining and optimising our Shopify e-commerce platform. Responsibilities Build and configure our Shopify store. Create and organise product pages and collections. Upload products, images, videos and certificates. Set up product specifications and pricing. Configure payments, shipping and checkout. Connect relevant third-party systems and apps. Assist with supplier and fulfilment integrations. Maintain accurate product and inventory information. Fix technical issues when required. Optimise website performance and mobile experience. Make ongoing improvements to the Shopify store. Provide technical support and maintenance as the business grows. If this sounds like you, please apply with your rate and we will look to move you to the next stages. Looking forward to speaking with you.
Budget:
not specified
4 days ago
|
|||||
|
WordPress Malware Removal Expert
Applied
|
$12 - $30
/ hr
|
4 days ago |
3
|
||
|
Need a freelancer to identify and remove malware from a WordPress site. The work includes scanning the site, locating malicious files or code, cleaning the infected files, and restoring the site to a secure state. Bluehost did a scan and identified 5 infected files in the scan report, which I can provide. You should also review the site for vulnerabilities and recommend steps to prevent future infections. Please share examples of similar WordPress malware removal work and your approach to handling infected sites securely. I would also like to review my bluehost c-panel and remove websites that are no longer necessary/being used. (Such as a staging site). Lastly, if you could help me put a contact form on my website and configure my email.
Client's questions:
Hourly rate:
12 - 30 USD
4 days ago
|
|||||
|
Bison Ice Hockey Club
Applied
|
not specified | 5 days ago |
1
|
||
|
I have attached a design brief an initial design map of the page layouts etc.
We have colour pallets and a full range of logos and photos for the project.
Budget:
not specified
5 days ago
|
|||||
|
Wordpress malware cleanup
Applied
|
not specified | 5 days ago |
5
|
||
|
I have 2 websites that clearly have malware on them, they automatically have blogs created to advertise for gambling websites even after I delete these they re appear again, i have tried using a few security plugins but still the malware exists (either replanting itself or someone has been hacking in using either my own account or my web developers. We've recently changed our logins and I've reinstalled Wordpress but the problem still exists.
This needs to be a quick and efficient job, if the issue still persists after your fix i will need you to come back again and fix it. I’d invision that you need you to download, host on your server, remove all malware, code injections and find the loophole from where it is hacked and fix it. Convince me why you’re best at doing this job more than the 100 others that will apply. Also please shoot me your realistic fees - I don’t have a huge budget but again the websites are very small anyway.
Budget:
not specified
5 days ago
|
|||||
|
WordPress Website Redesign with Custom Development and Automation
Applied
|
not specified | 6 days ago |
1
|
||
|
We are looking for an experienced WordPress developer to redesign and improve an existing business website. This is a complete redesign and development project that includes custom functionality, WooCommerce work, integrations, automation, security, and performance improvements.
Project requirements: • Redesign the existing website with a clean, modern, and professional appearance • Build a fully responsive layout for desktop, tablet, and mobile • Improve the website structure, navigation, and user experience • Develop custom WordPress functionality based on our business requirements • Customize WooCommerce products, checkout, customer accounts, and order processes • Connect third-party services through APIs and webhooks • Create automated workflows for customers, orders, emails, and administrative tasks • Develop or modify custom WordPress plugins when necessary • Fix existing WordPress, PHP, JavaScript, CSS, and database issues • Improve website speed and Core Web Vitals • Strengthen website security and remove unnecessary or vulnerable components • Configure backups, caching, staging, and safe deployment procedures • Preserve important content and SEO data during the redesign • Test all features across major browsers and screen sizes • Provide documentation and short post-launch support The developer should have strong experience with: • WordPress and WooCommerce • PHP, MySQL, HTML, CSS, and JavaScript • Custom themes and plugins • REST APIs, webhooks, and external integrations • Workflow automation • Website security and malware prevention • Performance optimization • Git, staging environments, and production deployment Expected deliverables: 1. Approved website design and page structure 2. Completed responsive WordPress website 3. Working custom features and integrations 4. Configured WooCommerce system 5. Tested forms, checkout, emails, and automated workflows 6. Performance and security improvements 7. Deployment to the live website 8. Technical documentation and post-launch support Please include the following in your proposal: • Two or three relevant WordPress or WooCommerce projects • Examples of custom plugins, APIs, or automation you developed • Your recommended development approach • Estimated project timeline • Estimated fixed price or hourly rate • Your availability for communication and progress updates We value clear communication, honest progress updates, clean code, careful testing, and a long-term working relationship. Full requirements and website access will be shared with the selected developer.
Budget:
not specified
6 days ago
|
|||||
|
AWS S3/IAM Security Expert Needed Today — Two Restricted Access Levels
Applied
|
$20 - $75
/ hr
|
6 days ago |
3
|
||
|
I need an experienced AWS security/IAM engineer to configure secure access to data currently stored in my AWS environment.
I need two distinct user/access levels: Level 1 — View Only: User needs to be able to view/read the information but ideally cannot download, copy, export, move, modify or delete the underlying files/data. I understand ordinary S3 GetObject/read-only permission may permit downloading, so I need you to recommend and implement the appropriate AWS architecture for controlled viewing. Level 2 — Read/Export but No Delete: User can access, download/copy/export information from the source, but cannot modify or delete the original files/data. Requirements: * Strong Amazon S3 experience * Expert-level AWS IAM policies/roles * Least-privilege security architecture * Explicit protection against deletion/modification * S3 Versioning / Object Lock or other safeguards if appropriate * CloudTrail/audit logging as appropriate * MFA/security best practices * Test both user roles before completion * Provide me with administrator/owner control and brief documentation I need this completed immediately, preferably today. Please respond with: 1. Your experience implementing S3/IAM access controls 2. How you would solve the “view but cannot download/copy” requirement 3. Whether you are available to start immediately 4. Estimated hours to complete
Hourly rate:
20 - 75 USD
6 days ago
|
|||||
|
WordPress Website Fix and Stripe Plugin Audit
Applied
|
$15 - $25
/ hr
|
7 days ago |
4
|
||
|
Need an expert to audit and resolve a website issue caused by a custom plugin connected to our Stripe gateway. The site is experiencing 500 errors, and we need someone who can investigate firsthand, identify the root cause, and provide actionable recommendations. The goal is to fix the issue permanently and restore stable site performance. Please apply only if you have strong experience troubleshooting complex WordPress and payment integration problems.
Hourly rate:
15 - 25 USD
7 days ago
|
|||||
|
WordPress Technical Web Developer, Security & Troubleshooting
Applied
|
$10 - $20
/ hr
|
7 days ago |
4
|
||
|
About the Role
We are a growing Local SEO agency working primarily with local service businesses. We are looking for a highly technical WordPress developer who can help manage, troubleshoot, repair and improve our clients' websites. We need someone who is comfortable getting into the technical side of WordPress and figuring out problems when something breaks. You should be able to diagnose issues involving PHP, plugins, themes, hosting, DNS, malware, redirects, databases and server configurations without needing step-by-step instructions. You will work alongside our SEO team to ensure our clients' websites remain fast, secure, functional and technically optimized. Responsibilities WordPress Development & Troubleshooting Diagnose and fix WordPress errors and broken websites Troubleshoot PHP errors, fatal errors and compatibility issues Identify plugin and theme conflicts Troubleshoot WordPress admin and frontend issues Fix broken functionality after WordPress/plugin/theme updates Work with Elementor and other common WordPress builders Make HTML, CSS, JavaScript and PHP changes when required Troubleshoot contact forms and email delivery issues Security & Malware Diagnose hacked or compromised WordPress websites Identify malicious PHP files, injected scripts and suspicious code Remove malware and malicious files Investigate unexpected administrator accounts or unauthorized changes Clean compromised WordPress installations Secure WordPress after malware removal Review plugins, themes, users and files for vulnerabilities Help prevent reinfection rather than simply deleting infected files Restore websites from clean backups when appropriate Hosting & Server Troubleshooting Work with hosting platforms such as Cloudways, GoDaddy, SiteGround, cPanel and similar environments Troubleshoot PHP versions and PHP configuration Diagnose server errors including 403, 404, 500, 502 and 503 errors Work with SSL certificates Troubleshoot DNS issues Configure redirects Diagnose redirect loops and redirect chains Work with .htaccess Troubleshoot caching and CDN issues Perform website migrations and domain changes Create and restore backups Technical SEO Support Implement and troubleshoot 301 redirects Fix 404 errors and broken URLs Diagnose indexing and crawling problems Review robots.txt Review and fix XML sitemap issues Implement canonical tags Fix internal linking and URL problems Implement schema markup Help maintain technical SEO during domain migrations Improve Core Web Vitals and website performance Ensure development changes do not negatively impact SEO What We're Looking For You should have strong experience with: WordPress PHP MySQL HTML CSS JavaScript Elementor WordPress database troubleshooting WordPress malware removal Website security DNS SSL cPanel/server environments Website migrations Domain migrations 301 redirects .htaccess Website speed optimization Backup and restoration Experience with Cloudways, Cloudflare, GoDaddy and Google Search Console is a major plus. Most Important Skill Problem solving. We don't expect you to know the answer to every issue immediately. We do expect you to be able to investigate an unfamiliar technical problem, identify the root cause, explain what happened and implement a safe solution. For example, if a WordPress website suddenly goes down after PHP code is added, we don't just want someone who can remove the code. We want someone who can determine: What broke → Why it broke → How to fix it → How to prevent it from happening again. Security Expectations Because you will have access to client websites and hosting environments, security is extremely important. You must: Follow least-privilege access practices Never share client credentials Never create unauthorized administrator accounts Never install nulled/cracked plugins or themes Take backups before significant changes Document major technical changes Test potentially risky changes in staging whenever possible Escalate potentially compromised websites immediately Please answer this technical question: A WordPress website suddenly starts returning a 500 error after custom PHP code is added. You don't have access to wp-admin. Walk me through exactly how you would diagnose and fix the problem.
Hourly rate:
10 - 20 USD
7 days ago
|
|||||
|
Freelance Linux System Administrator – CWP, Contabo & WordPress Security Specialist
Applied
|
$10 - $25
/ hr
|
7 days ago |
3
|
||
|
### *Job Overview:*
We are seeking an experienced *Linux Systems Administrator* with hands-on expertise in *Control-WebPanel (CWP / CWP7), **Contabo cloud infrastructure, and **WordPress malware remediation*. As a freelancer, you will handle server updates, performance tuning, malware auditing/cleanup, and server hardening on our Contabo-hosted CWP environment. ### *Key Responsibilities:* #### *1. Contabo Server & CWP Management* * Maintain, update, and optimize CWP on *Contabo VPS* instances (CentOS). * Monitor Contabo resource metrics (vCPU, RAM, disk I/O, bandwidth) to prevent overload and ensure maximum server uptime. * Manage Contabo firewall rules. * Configure, test, and maintain automated local and remote backups. #### *2. WordPress Malware Remediation & Security* * *Scan & Detect:* Perform deep server-level security audits across hosted WordPress accounts to identify webshells, backdoor scripts, and malicious code injections. * *Clean & Cleanse:* Manually inspect and clean infected WordPress core files, plugins, and themes—replacing compromised components with clean versions from official repositories. * *Database Cleanup:* Audit and clean WordPress database tables for injected malicious code, spam URLs, and unauthorized admin accounts. * *Vulnerability Patching:* Identify entry points (outdated plugins, nulled themes, weak file permissions) and secure them to prevent reinfection. * *WP Hardening:* Implement WordPress security best practices (securing wp-config.php, restricting XML-RPC, setting up 2FA, enforcing proper file permissions, and disabling file editing in wp-admin). #### *3. Server Hardening & Isolation* * Configure *CSF (ConfigServer Security & Firewall), **ModSecurity (OWASP rules), and **fail2ban* to block brute-force attacks and suspicious traffic. * Enforce SSH security (custom port, key-based authentication, disabling direct root login). * Enforce cross-account isolation in CWP (CageFS/symlink protection) to prevent malware cross-contamination. --- ### *Required Freelancer Qualifications:* * *Contabo Experience:* Demonstrated experience managing *Contabo VPS/Dedicated environments* (snapshots, rescue mode, IP routing, PTR/rDNS setup). * *CWP & Linux Expertise:* Advanced administration of Control-WebPanel (CWP7) via GUI and SSH command line on RHEL-based Linux distributions. * *WordPress Security Mastery:* Proven track record of manually cleaning infected WordPress environments without breaking site structure or functionality. * *CLI Malware Analysis:* Expert level with command-line diagnostic tools (grep, find, diff, awk, WP-CLI) to isolate payload patterns and malicious code signatures. * *Security Software:* Proficiency with CSF Firewall, ModSecurity, Maldet, ClamAV, and Imunify360 (if enabled). ### *Freelance Terms & Proposal Requirements:* * *Engagement Type:* Freelance (Project-Based Cleanup) * *Location:* Remote * *Rate Model:* [Hourly Rate / Fixed Price per Server/Project] * *To Apply:* Please submit your proposal including: 1. Brief summary of your experience with Contabo, CWP7, and Linux server hardening. 2. Examples of recent WordPress malware cleanups or server remediation projects you’ve completed. 3. Your hourly rate or fixed-project estimate and typical turnaround time.
Hourly rate:
10 - 25 USD
7 days ago
|
|||||
|
WordPress Malware Removal and Prevention
Applied
|
$14 - $100
/ hr
|
7 days ago |
3
|
||
|
Need help removing a persistent malware infection (and preventing re-infection) from 1–8 WordPress sites on the same server.
The infection matches the description in this blog post: monarx.com/press-news/the-wordpress-infection-that-rebuilds-itself-faster-than-you-can-delete-it. Clean backups are available, and I can provide any necessary access. Will need to show that the site(s) are fully cleaned and protected from reinfection.
Hourly rate:
14 - 100 USD
7 days ago
|
|||||
|
WordPress Malware Removal Specialist
Applied
|
$20 - $60
/ hr
|
8 days ago |
3
|
||
|
My WordPress site is showing visitors a fake Cloudflare ‘Verify you are human’ page that instructs them to open Windows Terminal and paste a command. I need the site quarantined, malware/backdoors identified and removed, WordPress core/plugins/themes checked for integrity, the database scanned for injected code, admin accounts audited, and the site secured after cleanup. I do not want the existing site rebuilt or restored from an old backup unless necessary
Hourly rate:
20 - 60 USD
8 days ago
|
|||||
|
Freelance Linux System Administrator – CWP, Contabo & WordPress Security Specialist
Applied
|
$10 - $25
/ hr
|
8 days ago |
1
|
||
|
## *Key Responsibilities:*
#### *1. Contabo Server & CWP Management* * Maintain, update, and optimize CWP on *Contabo VPS* instances (CentOS). * Monitor Contabo resource metrics (vCPU, RAM, disk I/O, bandwidth) to prevent overload and ensure maximum server uptime. * Manage Contabo firewall rules. * Configure, test, and maintain automated local and remote backups. #### *2. WordPress Malware Remediation & Security* * *Scan & Detect:* Perform deep server-level security audits across hosted WordPress accounts to identify webshells, backdoor scripts, and malicious code injections. * *Clean & Cleanse:* Manually inspect and clean infected WordPress core files, plugins, and themes—replacing compromised components with clean versions from official repositories. * *Database Cleanup:* Audit and clean WordPress database tables for injected malicious code, spam URLs, and unauthorized admin accounts. * *Vulnerability Patching:* Identify entry points (outdated plugins, nulled themes, weak file permissions) and secure them to prevent reinfection. * *WP Hardening:* Implement WordPress security best practices (securing wp-config.php, restricting XML-RPC, setting up 2FA, enforcing proper file permissions, and disabling file editing in wp-admin). #### *3. Server Hardening & Isolation* * Configure *CSF (ConfigServer Security & Firewall), **ModSecurity (OWASP rules), and **fail2ban* to block brute-force attacks and suspicious traffic. * Enforce SSH security (custom port, key-based authentication, disabling direct root login). * Enforce cross-account isolation in CWP (CageFS/symlink protection) to prevent malware cross-contamination. --- ### *Required Freelancer Qualifications:* * *Contabo Experience:* Demonstrated experience managing *Contabo VPS/Dedicated environments* (snapshots, rescue mode, IP routing, PTR/rDNS setup). * *CWP & Linux Expertise:* Advanced administration of Control-WebPanel (CWP7) via GUI and SSH command line on RHEL-based Linux distributions. * *WordPress Security Mastery:* Proven track record of manually cleaning infected WordPress environments without breaking site structure or functionality. * *CLI Malware Analysis:* Expert level with command-line diagnostic tools (grep, find, diff, awk, WP-CLI) to isolate payload patterns and malicious code signatures. * *Security Software:* Proficiency with CSF Firewall, ModSecurity, Maldet, ClamAV, and Imunify360 (if enabled). ### *Freelance Terms & Proposal Requirements:* * *Engagement Type:* Freelance (Project-Based Cleanup) * *Location:* Remote * *Rate Model:* [Hourly Rate / Fixed Price per Server/Project] * *To Apply:* Please submit your proposal including: 1. Brief summary of your experience with Contabo, CWP7, and Linux server hardening. 2. Examples of recent WordPress malware cleanups or server remediation projects you’ve completed. 3. Your hourly rate or fixed-project estimate and typical turnaround time.
Hourly rate:
10 - 25 USD
8 days ago
|
|||||
|
WordPress/WooCommerce Security Expert Needed – Recurring Malware & Backdoor Investigation
Applied
|
$600
|
8 days ago |
5
|
||
|
# WordPress / WooCommerce Malware Investigation and Removal
We are looking for an experienced WordPress security specialist to investigate and fully remediate a recurring malware infection on a WooCommerce website. Our internal development team has already carried out several malware cleanups. Malicious files are removed, but further malicious files are appearing again, typically within approximately 24 hours. We therefore need someone with strong WordPress security and malware investigation experience who can identify the **root cause and persistence mechanism**, rather than simply carrying out another file cleanup. ## Scope of Work The successful freelancer will be expected to: * Carry out a full security review of the WordPress/WooCommerce installation. * Identify all malicious files, injected code, backdoors and persistence mechanisms. * Determine how the website is being reinfected. * Review WordPress core files, plugins and themes for unauthorised modifications. * Check the database for malicious injections, rogue administrators, scheduled tasks or other suspicious entries. * Review WordPress cron jobs and server-level cron jobs where relevant. * Check for compromised administrator, FTP/SFTP, hosting or database credentials where evidence indicates this may be an issue. * Review relevant server and access logs to identify the likely attack vector where possible. * Remove all malicious code and compromised files. * Replace compromised WordPress core/plugin/theme files with clean versions where appropriate. * Identify vulnerable, abandoned or compromised plugins/themes. * Apply appropriate security hardening after the cleanup. * Confirm that no obvious persistence mechanisms remain. * Provide recommendations to reduce the risk of reinfection. ## Important This is **not simply a request to run a malware scanner and delete flagged files**. Our team has already performed repeated cleanups. We need someone who is experienced in investigating persistent WordPress infections and can establish why the malware keeps returning. The website is an active WooCommerce installation, so work must be carried out carefully to avoid unnecessary disruption to the live website or loss of legitimate website/order data. ## Deliverables At completion, we require: 1. Website cleaned of identified malware and backdoors. 2. Root cause or most likely source of reinfection identified. 3. Persistence mechanisms removed. 4. Security vulnerabilities found during the investigation addressed or clearly documented. 5. A short written report covering: * What was found. * How the infection was persisting. * What was removed or changed. * Any remaining risks. * Recommended preventative measures. ## Required Experience Please apply only if you have demonstrable experience with: * WordPress malware investigation and removal. * Persistent/reoccurring WordPress infections. * WooCommerce websites. * PHP malware and obfuscated code. * WordPress database compromise. * Backdoors, web shells and malicious cron jobs. * Server/access log analysis. * WordPress security hardening. Experience working with compromised production WooCommerce websites is particularly important. ## When Applying Please briefly explain: * Your experience with recurring WordPress malware infections. * How you would approach identifying the reinfection mechanism. * Examples of persistence methods you have encountered on compromised WordPress sites. * Whether you can provide a short remediation report after completing the work. We are looking for someone who can investigate this thoroughly and provide confidence that the underlying compromise has been addressed, rather than carrying out another temporary cleanup.
Fixed budget:
600 USD
8 days ago
|
|||||
|
Google account recovery
Applied
|
not specified | 8 days ago |
1
|
||
|
I am having a problem recovering access to my Google account.
I have access to the following: My account password My backup codes Two-step verification My recovery email address However, I no longer have access to the phone number linked to the account, and I am unable to complete the sign-in process. I am the rightful owner of this account and can provide any additional information or verification needed to prove ownership. Please help me recover access to my account using my recovery email or backup codes.
Budget:
not specified
8 days ago
|
|||||
|
Indian takeaway
Applied
|
not specified | 9 days ago |
1
|
||
|
Hello!
Hope you’re well. I have a new restaurant and need a website. Website will be connected to system called flip dish and structure should be like the website you created called mystic Thai. I have an ai website design that matches our logo and restaurant design that i could send that may give you an idea of how i would want it to look. Give me your cost to create this system. No rush on due date around a month I would say. The website doesn’t need payment system just the menu and connected to flipdish.
Budget:
not specified
9 days ago
|
|||||
|
Wordpress Malware Infection
Applied
|
$10 - $20
/ hr
|
9 days ago |
5
|
||
|
Since recently, multiple Wordpress websites I built and host are being infected with the same kind of Malware, known as "Fake captcha".
Almost each and everyone of my websites is being infected one by one. Mainly due to outdated plugins or forgotten updates. Because of this infection, I am not able to log on to the websites. And some are even quarantined by the hosting provider. Since I host multiple Wordpress websites, I require someone to quickly clean all websites and keep them clean in the future. Currently there are 3 to 4 websites actively needing attention. And I am willing to pay $15 per cleaned website. I am looking for someone who is an expert on the matter and does not require additional explanation. For example, I would hire you if you would be able to think of installing and activating the Wordfence or similar plugin by yourself, because you know it's an advantage etc. After this, I am willing to discuss long term maintenance of my small server, hosting about 30 domains. Client's questions:
Hourly rate:
10 - 20 USD
9 days ago
|
|||||
|
Remove Malicious content from Wordpress WooCommerce site
Applied
|
$5 - $15
/ hr
|
9 days ago |
5
|
||
|
I have a Wordpress WooCommerce site. Unfortunately, it got hacked and the webhost has disabled the site. The site has one custom plugin regarding shipping. Most likely, the PHP version needs to be updated as well on the Webhost.
The webhost has sent instructions on what files have been infected and steps to handle it. I need help following the webhost instruction and update WP plugins to get the sites up and running again. The Wordpress site hasn't been updated in a long time. When it's done I need to use LocalWP to download the site locally. Client's questions:
Hourly rate:
5 - 15 USD
9 days ago
|
|||||
|
Fix Hacked WordPress Site — Remove Legacy Spam Pages & Harden Security
Applied
|
not specified | 9 days ago |
5
|
||
|
A Semrush backlink audit surfaced a large legacy spam injection that needs professional cleanup and security hardening. This is urgent — please only apply if you can start within 24-48 hrs.
What we found: Semrush's Backlink Analytics shows ~908,000 indexed URLs tied to this domain. The real site has ~30-50 legitimate pages. The excess is doorway/spam pages with dictionary-word-plus-random-hash slugs (e.g. /abscessed-07zt5v/jdvmvs4noit8smi, /academese-0807a4, /cered-04ee5a/2vnsp6vv), titled "Page not found," each carrying 6-17 internal links and 42 external links. All dated Oct 2020–Jan 2021 — appears to be a single historical injection, not an active live attack, but it was never cleaned up and is very likely still burning crawl budget and dragging down site trust years later. Not visible via a normal site crawl (Screaming Frog etc.) — these are orphaned, only discoverable via GSC Index Coverage or backlink-tool data, since nothing on the live site currently links to them. SCOPE: Full malware/backdoor scan — files, database, and any injected code. Find and close the actual entry point, not just delete visible spam pages. A surviving backdoor will re-inject pages within weeks. Spam URL cleanup, done correctly — serve 410 Gone (not just a bare 404) for the spam URL pattern via server-level rule, so Google stops re-checking them instead of leaving them in permanent crawl-budget limbo. Google Search Console — check Security Issues for any manual action tied to this; submit removals for the indexed spam URLs. Reconsideration Request — file with Google if a manual action is found, only after cleanup is verified complete. Hardening — updated core/plugins/themes, a security plugin, admin access/credential review, so this doesn't recur. Written report — what was found, what was done, and confirmation the entry point is closed. REQUIREMENTS: Proven experience cleaning hacked/spam-injected WordPress sites — share 1-2 examples of similar cleanups, ideally with a comparable scale of injected pages. Comfortable with Search Console (Security Issues, manual actions, removals, reconsideration requests). Fixed-price quote after inspecting the site — not looking for a blind quote. A brief warranty/follow-up window in case anything resurfaces. NOT LOOKING FOR: Surface-level page deletion without addressing the underlying vulnerability Anyone quoting a price before seeing the site Agencies / project managers relaying to a dev — need someone hands-on A discovery call to explain what's above
Budget:
not specified
9 days ago
|
|||||
|
Website Malware Removal
Applied
|
not specified | 9 days ago |
5
|
||
|
I require an experienced website security specialist to investigate, clean, and restore a UK-based website hosted with SiteGround.
SiteGround has detected malicious code on the website and has disabled public access to the web service. Email services remain active. The website must be cleaned and secured so that SiteGround will reactivate public access. The job involves reviewing SiteGround's malware notification and security reports, identify the source of the malicious code, remove all malicious files, code injections, backdoors, malware, and unauthorised scripts. Applicants must have WordPress security and malware removal experience. The successful freelancer may be given temporary access to hosting and WordPress administration systems. All work must comply with UK data protection requirements and standard cybersecurity best practices.
Budget:
not specified
9 days ago
|
|||||
|
Website maintenance
Applied
|
not specified | 9 days ago |
3
|
||
|
My website: www.belindazollo.com
- The Kalium theme needs updating... but the website needs to be saved FIRST. Can you please assist with this? Let me know if you need any information from me to get into the backend. Thank you! Belinda
Budget:
not specified
9 days ago
|
|||||
Related freelance jobs queries: