WordPress Security and Malware Remediation Project
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted1 hour ago
## Project overview
I manage one Hostinger Cloud Startup hosting account for my event business containing my WordPress event websites.
All websites have shown signs of the same recurring malware infection. The infection has appeared in WordPress `mu-plugins` and other locations, including cache files and plugin/theme files. On at least one website, removing or renaming the malicious file resulted in it being recreated within minutes, including once with read-only permissions. This suggests possible account-level persistence or compromised credentials rather than unrelated infections.
The hosting malware scanner has reported hundreds of malicious detections, with some files recurring after quarantine. The previous cleanup attempts did not permanently resolve the issue.
## Required work
Please provide a complete account-wide investigation and remediation, not just a standard WordPress plugin scan:
1. Investigate the infection and identify the reinfection mechanism or persistence point.
2. Inspect all WordPress installations, including:
- `wp-content/mu-plugins/`
- standard plugins and themes
- `wp-content/uploads/`
- cache and drop-in files such as `advanced-cache.php` and `db.php`
- `.htaccess`, `wp-config.php`, and other core files
- WordPress cron jobs and scheduled tasks
- databases and suspicious administrator accounts
3. Review the hosting account for suspicious FTP/SFTP/SSH access, unauthorized files outside the public website directories, and other account-level persistence mechanisms.
4. Compare core, plugin, and theme files against clean originals and replace compromised files safely.
5. Remove malicious code and backdoors without deleting legitimate business content or media.
6. Check databases for injected users, options, scheduled actions, redirects, spam, and malicious scripts.
7. Harden all sites after cleanup, including least-privilege access, safe file permissions, updates, disabling risky functionality where appropriate, and security monitoring.
8. Confirm that hosting, FTP/SFTP, SSH, database, and WordPress credentials have been rotated and that no unknown users or access keys remain.
9. Run a fresh scan of the entire account and monitor for at least 24–72 hours to confirm that the infection does not return.
10. Provide a written report listing the root cause, files and accounts affected, actions performed, remaining risks, and prevention recommendations.
## Important constraints
- Do not perform destructive cleanup without first creating a backup or preserving a recoverable copy.
- Do not delete legitimate website content, databases, uploads, or business data.
- Keep the websites online wherever safely possible and notify me before any action that could cause downtime.
- Please explain any required SSH or SFTP changes before applying them.
## Quote request
Please provide:
- A fixed price quote
- A clear list of what is included and excluded
- Estimated timeline and expected downtime, if any
- Your follow-up monitoring or reinfection warranty period
- The backup and rollback plan
- Examples of similar multi site WordPress malware cases you have handled
The project will be considered complete only after the account-wide scan is clean and the infection has not returned during the agreed monitoring period.
I manage one Hostinger Cloud Startup hosting account for my event business containing my WordPress event websites.
All websites have shown signs of the same recurring malware infection. The infection has appeared in WordPress `mu-plugins` and other locations, including cache files and plugin/theme files. On at least one website, removing or renaming the malicious file resulted in it being recreated within minutes, including once with read-only permissions. This suggests possible account-level persistence or compromised credentials rather than unrelated infections.
The hosting malware scanner has reported hundreds of malicious detections, with some files recurring after quarantine. The previous cleanup attempts did not permanently resolve the issue.
## Required work
Please provide a complete account-wide investigation and remediation, not just a standard WordPress plugin scan:
1. Investigate the infection and identify the reinfection mechanism or persistence point.
2. Inspect all WordPress installations, including:
- `wp-content/mu-plugins/`
- standard plugins and themes
- `wp-content/uploads/`
- cache and drop-in files such as `advanced-cache.php` and `db.php`
- `.htaccess`, `wp-config.php`, and other core files
- WordPress cron jobs and scheduled tasks
- databases and suspicious administrator accounts
3. Review the hosting account for suspicious FTP/SFTP/SSH access, unauthorized files outside the public website directories, and other account-level persistence mechanisms.
4. Compare core, plugin, and theme files against clean originals and replace compromised files safely.
5. Remove malicious code and backdoors without deleting legitimate business content or media.
6. Check databases for injected users, options, scheduled actions, redirects, spam, and malicious scripts.
7. Harden all sites after cleanup, including least-privilege access, safe file permissions, updates, disabling risky functionality where appropriate, and security monitoring.
8. Confirm that hosting, FTP/SFTP, SSH, database, and WordPress credentials have been rotated and that no unknown users or access keys remain.
9. Run a fresh scan of the entire account and monitor for at least 24–72 hours to confirm that the infection does not return.
10. Provide a written report listing the root cause, files and accounts affected, actions performed, remaining risks, and prevention recommendations.
## Important constraints
- Do not perform destructive cleanup without first creating a backup or preserving a recoverable copy.
- Do not delete legitimate website content, databases, uploads, or business data.
- Keep the websites online wherever safely possible and notify me before any action that could cause downtime.
- Please explain any required SSH or SFTP changes before applying them.
## Quote request
Please provide:
- A fixed price quote
- A clear list of what is included and excluded
- Estimated timeline and expected downtime, if any
- Your follow-up monitoring or reinfection warranty period
- The backup and rollback plan
- Examples of similar multi site WordPress malware cases you have handled
The project will be considered complete only after the account-wide scan is clean and the infection has not returned during the agreed monitoring period.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.