WordPress Security Assessment, Multi-Site Remediation, and Clean Website Rebuild
- Status
- Open
- Remote policy
- Not stated
- Employment type
- Not stated
- Salary
- Not stated
- Tech
- security
- Source
- wordpress-jobs
- First observed
- 2026-08-28 19:19 UTC
- Last seen
- 2026-08-28 19:19 UTC
- Source claims posted
- 2026-08-28 18:29 UTC
- Consecutive misses
- 0 of 3
What the posting says
I am requesting an estimate for a whole-account WordPress security assessment and the clean rebuilding of one compromised website.
My WebHostingHub/cPanel account contains five domains:
arealwholelot.com — document root: /public_html
kaneconsultingandcoaching.com — document root: /public_html/kaneconsultingandcoaching.com
doctoralsuccess.com — document root: /doctoralsuccess.com
finisheddissertation.com — document root: /finisheddissertation.com
jakproductions.biz — document root: /jakproductions.biz
WebHostingHub confirmed that arealwholelot.com was compromised. A support representative found substantial malicious base64 code in its wp-config.php file. The host reinstalled the WordPress core files, but the problem persisted. The host did not perform a complete malware scan, identify all affected files, or determine how long the infection had been present.
Although the sites use separate WordPress installations, Kane Consulting and Coaching is nested beneath /public_html, and all five sites share the same hosting account. I therefore need the entire account examined—not only the known infected wp-config.php file.
I have a full cPanel account backup created on August 16, 2026. It is a 3.65 GB preservation snapshot stored locally and in Dropbox. Because it was created after the compromise was discovered, I am treating it as potentially infected and will not restore or share it except through an agreed secure process.
Please provide an itemized estimate addressing:
A security assessment and malware scan of the entire hosting account, including all five sites, databases, wp-config.php and .htaccess files, administrator accounts, themes, plugins, uploads, cron jobs, and other persistence mechanisms.
Safe containment of arealwholelot.com without disabling or damaging kaneconsultingandcoaching.com or the other sites.
Identification and remediation of any compromise found in the other WordPress installations or elsewhere in the hosting account.
A fresh rebuild of arealwholelot.com using a clean WordPress installation, freshly obtained themes and plugins, and only scanned and validated content recovered from the old site.
Security hardening, including credential rotation guidance, new WordPress salts, multifactor authentication where available, removal of unused accounts and software, firewall or monitoring recommendations, and properly configured off-site backups.
Post-remediation testing and written confirmation that the rebuilt site and the other installations have passed malware scans.
Please also include:
Your proposed approach: cleaning the existing ARWL installation, rebuilding it, or both—and why.
The estimated schedule.
Itemized one-time charges.
Any required subscriptions or continuing fees.
What access or credentials you would require and how they would be transmitted securely.
What reports or documentation I would receive.
Whether you provide a remediation warranty or follow-up period if malware reappears.
Your experience handling compromised WordPress accounts with multiple sites under one cPanel account.
Quality
- x Salary range stated weight 35%
- x Remote policy stated weight 20%
- x Location stated weight 15%
- x Organisation stated weight 15%
- + Publication date stated weight 15%
Not enough history yet to judge honesty signals.
Timeline
-
*
#426406 2026-08-28 19:19 UTCPublished