Budget: 5000 UAH Deadline: 2 days
Hello. I have extensive experience with WordPress. I am ready to remove the virus and find the cause.
Hello everyone. A shop website is currently being developed on WordPress. The files are on the dev server. This is the development of a new site.
On Monday, it was hacked, and doorway pages (massively generated pages) were uploaded. Most likely, it was an automated bot, as the site is not indexed and the generated pages did not make it there either.
What is needed:
Stack / environment:
What we expect from you:
Please write: your experience with similar incidents, estimated time and cost, and what access you will need to work.
Additional information (not sure how important this is, decided to write): besides the site in development, there is an old site, also WordPress, from which all the products were taken, etc. (this is our old site), it is currently operational, but we have not had any similar problems with it, there is also the Albatross program, separate, which is the product and reporting database.
We want to identify the problem before the release and transfer of files to the main server.
Budget: 5000 UAH Deadline: 2 days
Hello. I have extensive experience with WordPress. I am ready to remove the virus and find the cause.
Budget: 1500 UAH Deadline: 3 days
Good day! I have already cleaned such stories — WP, where a doorway was uploaded and generated pages were piled up. The main thing here is not to sweep the pages but to find out how they got in; otherwise, it will be the same in a week.
If I were doing it for you:
1. I take a copy of the files and a database dump, looking in read-only mode to avoid erasing traces.
2. I search for recently modified files, web shells, eval/base64 injections, rogue mu-plugins, tasks in wp-cron, foreign admins in wp_users, foreign strings in options, .htaccess, and nginx configs.
3. I compare plugins and the theme with clean sources — the vulnerable component is usually the entry point.
4. I clean or help rebuild from clean files, then rotate all keys and passwords and list what to close to prevent recurrence.
Access: SSH (preferably a separate key for this task), site files, and a database dump on the dev server. I will also quickly check the old working site for indicators — both could have been affected.
Estimated time is 2-3 days. I set the price lower than usual because I am gathering my first reviews here, so it is important for me to do it cleanly.
Question: Are there nginx and PHP-FPM logs left from Monday when it was hacked? With them, the entry point is visible much faster than from the files themselves.
I can start with a safe audit without touching anything yet.
Budget: 4000 UAH Deadline: 3 days
Good day. I have experience in healing WordPress sites, identifying and closing vulnerabilities, including in plugins and themes. Write to me, and we will discuss everything in detail.
Budget: 4200 UAH Deadline: 3 days
👋 Hello! I'm ready to start working right now.
I clearly understand the task and have successful experience in implementing exactly such projects (examples are in the reviews). I will complete the task quickly and without unnecessary questions.
SSH access ✅
I will check everything thoroughly and point out any issues✅
For an additional fee, I will fix the problems✅
Let's discuss the details and get started! 🚀
Budget: 3000 UAH Deadline: 2 days
Hello.
I have significant experience in incident response and hardening Linux servers (Nginx + PHP-FPM). I am ready to help you completely clean up the project and prepare it for a secure release.
Budget: 7500 UAH Deadline: 3 days
Good day! I have experience with WordPress security and understand that removing a doorway without eliminating the entry point is freezing, not healing.
Here’s how I approach such incidents: first, I take a snapshot of the files and database (I don’t delete anything), then I correlate nginx logs with the date the doorway appeared, check the mtime of files, search for web shells, mu-plugins, eval/base64 injections, foreign admins in wp_users, and external entries in wp_options. At the same time, I compare plugins and themes with clean versions - the vulnerable component is usually the entry point.
After identifying the root - I either clean or rebuild from clean sources, rotate all passwords and keys, and provide a specific hardening list for your stack (nginx + PHP-FPM + WireGuard). I am ready to describe what access will be needed and work with it safely.
Budget: 3500 UAH Deadline: 1 day
Good day!
The brief is clear. I work in the logic of "first the entry point, then the cleanup" — because removing a doorway without addressing the root cause = repeated hacking. I have experience in incident response on WordPress (nginx + PHP-FPM): doorway/spam injections, web shells, mu-plugins, backdoors in the database.
What I will do:
1. Snapshot of the state (files + database + logs) for evidence, without deleting anything.
2. Entry point: correlation of nginx logs with the appearance of the doorway, checking vulnerable plugins/themes, compromised accounts, find by mtime.
3. Cleanup of backdoors: file shells, mu-plugins/dropins, injections in the database (wp_options autoload, hidden admins, wp_posts), cron jobs.
4. Clean site: rebuilding core/plugins from official sources, custom — after verification, rotating passwords and keys.
5. Hardening: DISALLOW_FILE_EDIT, banning PHP in uploads (nginx), 2FA, limiting wp-login/xmlrpc, fail2ban, minimal DB user rights.
I recommend simultaneously checking the old site — if the new one pulled products from it, there may be shared credentials or a common source.
Access: SSH (your keys + WireGuard, initially read-only), nginx/PHP-FPM logs, access to the database (first read-only). Credentials — via a secure channel, we rotate them after work. Keep the files "frozen" until the state is fixed.
Deadline: 1 day. Cost: 3500 UAH for the described scope (with a brief report on the root cause and recommendations).
I am ready to start. Please provide the date/time of the incident as accurately as possible — this will speed up the search in the logs.
Budget: 6000 UAH Deadline: 3 days
Hello.
I can take on the diagnostics and cleaning. In such cases, you should start not with deleting generated pages, but with finding the entry point: files, mu-plugins, cron, database, users, nginx/PHP-FPM logs, access rights, plugins/theme.
After the check, I will either clean the current build or suggest what is better to transfer from clean sources. I will provide a brief report on what was found, what was deleted, how they likely gained access, and what needs to be closed before the release.
Budget: 1500 UAH Deadline: 3 days
I would look for an entry point (I think I know where and how to search). The measures you have taken are correct. Let's see, I will try to handle your task. I am working on the "weekend."
Budget: 8000 UAH Deadline: 3 days
Good day.
I have extensive experience working with WordPress, including legacy projects and security audits.
In your case, the main task is not just to remove the doorways, but to find the root cause of the compromise. I will check the installed plugins and theme, server logs, access rights, accounts, cron jobs, mu-plugins, possible backdoors in files and the database, as well as mechanisms for re-entry.
I would also like to highlight the transfer of data from the old site and all custom integrations through which vulnerable or compromised files could have entered.
For the work, SSH access, database access, and preferably nginx/PHP-FPM logs for the period before the incident will be needed.
After the review, I will provide conclusions regarding the entry point, a list of identified issues, and recommendations for hardening before the release.
I am ready to discuss the details and assess the scope of work after familiarizing myself with the project.
Budget: 15000 UAH Deadline: 7 days
Hello, tok24ua!
To fully understand the situation, please clarify:
1. Do you have backups of the site before the attack?
2. What plugins and themes are used on the site?
3. Were there any changes or updates made before the hack?
My approach:
1. First, I analyze all logs and files for suspicious activity to identify the entry point.
2. I remove all backdoors and malicious files, check the database for injections and unnecessary accounts.
3. I check all plugins and themes for vulnerabilities and update them to the latest versions.
4. I provide detailed recommendations for hardening: firewall configuration, access restrictions, checking permissions.
5. I test the site after cleaning to ensure there are no threats.
For the work, I will need:
- Access to the server via SSH (with your restrictions as you described).
- Administrative access to the WordPress admin panel.
Estimated time for completion: 1-2 days, cost depends on the amount of work we find during the analysis.
Please write in private messages to discuss the details and start the work.
Budget: 3000 UAH Deadline: 5 days
Good day, to start, access to the WordPress admin panel, if it is still opening, and access to the server to check the logs and settings. Then we will see. Either a vulnerability in some plugin or on the server itself.
Budget: 2000 UAH Deadline: 1 day
Hello, Yuri.
I work with WordPress constantly — every project is confirmed by client reviews.
I will do exactly what is described, plus I will show how to manage everything through the admin panel.
Final price/time after all clarifications.
Profile: Freelancehunt
Reviews: Freelancehunt
Budget: 4000 UAH Deadline: 3 days
Hello! I am ready to help. I have experience fixing issues on websites. I offer quality and fast work. Feel free to write.
Budget: 5000 UAH Deadline: 3 days
Hello! I will complete your task quickly and efficiently. It is necessary to review the code of the entire project.
My recent works
https://indexfast.pp.ua - fast website indexing
https://mono-bank.pp.ua - everything about Monobank
https://mamamia.pp.ua - online store
https://programist.pp.ua/ua/portfolio/ - portfolio of works
https://monitortest.pp.ua - monitor testing
https://keytest.pp.ua - keyboard testing
https://pctest.pp.ua - computer testing
My portfolio: https://freelancehunt.com/ua/freelancer/romas6ka.html#portfolio
Message me, I will start working today. I will be glad to collaborate with you!
Budget: 2200 UAH Deadline: 1 day
Hello. Ready to get started now!
Treatment and protection of websites!
Experience in treating and protecting websites for 10 years.
More than 2000 websites treated!!!
What I will do:
1. Remove viruses, completely clean the site.
2. Close vulnerabilities.
3. Update your CMS. Set up security.
4. Install hacking protection systems.
5. Free security consultation.
Timeline: 1 day.
Price for the complete service for 1 site: $50
Discounts for ordering 3 or more sites.
Guarantee:
First option: 1-year guarantee. (if you stay on your hosting)
Second option: LIFETIME GUARANTEE!!! (if transferred to a hosting with enhanced protection)
Contact me with respect, Dmitry!
8 proposals 31 July
Online Stores & E-commerce 53 proposals 31 July
Data Parsing 24 proposals 30 July
AI & Machine Learning 51 proposals 30 July
Content Management Systems 53 proposals 30 July