Back to all jobs
WordPress Malware Removal·3 days ago

Fix Hacked WordPress Site

WordPress Malware RemovalWordPress CustomizationWordPress SecurityWordPress DevelopmentWordPress Bug FixWordPress Optimization

Project description

We're a plumbing, heating, and drain cleaning company in Manchester, CT (servicereliefnow.com, WordPress, hosted on GoDaddy, domain registered at Namecheap). Our homepage has been hacked and is currently serving spam/gambling content (Turkish "deneme bonusu" betting spam) to visitors, while interior pages still show our real content — classic malicious code injection, not a full site takedown.

Immediate scope (fixed price, urgent — need someone who can start today/tomorrow):

Identify and fully remove the malware/injected code from WordPress core files, theme files, plugins, and the database (not just the visible symptom — find and close the actual backdoor, since visible cleanup alone usually gets re-infected within days) Restore the homepage to clean, correct content — from a GoDaddy backup if a clean one exists, or rebuilt to match our current live pages if not Identify and patch the vulnerability that let this happen (outdated plugin/theme, weak login, compromised credentials, etc.) Update WordPress core, theme, and all plugins to current secure versions Verify Namecheap DNS records and GoDaddy account access haven't been tampered with Install and configure a security plugin/firewall (Wordfence, Sucuri, or MalCare) plus login hardening (limit login attempts, disable in-dashboard file editing, 2FA on admin accounts) Set up or verify automated off-site backups going forward Once clean, check Google Search Console for security warnings and request a review if needed

Ongoing scope (hourly or small monthly retainer, after the fix):

General WordPress edits as needed: updating service pages, adding new service-area pages, swapping photos/content, minor design tweaks Keeping plugins/theme/WordPress core updated and monitoring for security issues Available for occasional support requests, reasonably responsive turnaround (not a 24/7 SLA, just someone reliable we can come back to)

Requirements:

Demonstrated experience specifically removing WordPress malware/hack cleanup — not just general WordPress dev (please share an example of a past hack-recovery job) Comfortable working directly in GoDaddy hosting (cPanel/File Manager, phpMyAdmin) and with Namecheap DNS Clear communicator who explains what they found and what they did in plain English Available to start immediately given the site is actively compromised

$20–$40
per hour
Apply on Upwork