WordPress Security Investigation, Clean Rebuild and Hosting Migration
- Status
- Open
- Remote policy
- Not stated
- Employment type
- Not stated
- Salary
- Not stated
- Tech
- security
- Source
- wordpress-jobs
- First observed
- 2026-08-25 19:03 UTC
- Last seen
- 2026-08-25 19:03 UTC
- Source claims posted
- 2026-08-25 17:05 UTC
- Consecutive misses
- 0 of 3
What the posting says
I need an independent WordPress security specialist to investigate a recurring malware infection affecting my business website, Chatty Cats Care.
The website’s booking form has repeatedly stopped working. Most recently, the suspicious domain “mcafeesmcafee.com” appeared on the booking page. My current agency confirmed that the malware had returned, removed the visible malicious file and restored the website from an older backup. However, they have not identified or documented the underlying entry point, so I am concerned that the infection could return again.
The WordPress website is currently hosted within the agency’s Hostinger account. I control the domain through Squarespace, my WordPress administrator account, business email, Google Analytics and Search Console. I have also downloaded a current UpdraftPlus backup of the database and website files. This backup must be treated as potentially infected and should not be restored to a clean website without inspection.
For this initial project, I need:
An independent security assessment of the current WordPress website.
Investigation of the likely source and extent of the recurring infection.
Checks for malicious files, database injections, redirects, unauthorised users, scheduled tasks, vulnerable plugins, themes and code snippets.
A review of the booking form failure and whether it is connected to the compromise.
Assessment of whether customer information submitted through the booking form may have been accessed, altered, lost or exposed.
Urgent containment of any active threat that can safely be addressed within the agreed budget.
A written report explaining the findings, work completed and recommended next steps.
A separate fixed-price estimate for a later clean rebuild and migration to hosting held in my own account.
Please do not make destructive changes, restore backups, rebuild the website or alter DNS without my prior written approval. Please preserve relevant evidence and logs where available.
My budget is very limited, so please quote a fixed price for the essential initial investigation and containment only. Clearly separate essential work from optional work. This is a one-time project and I am not seeking an SEO service, redesign or ongoing retainer.
When responding, please confirm:
Your experience with recurring WordPress malware and compromised Elementor websites.
What access you require.
What work is included in your fixed-price quote.
Whether you will work on a staging copy where appropriate.
Your estimated timescale.
How you will handle backups and any customer data securely.
Quality
- x Salary range stated weight 35%
- x Remote policy stated weight 20%
- x Location stated weight 15%
- x Organisation stated weight 15%
- + Publication date stated weight 15%
Not enough history yet to judge honesty signals.
Timeline
-
*
#364302 2026-08-25 19:03 UTCPublished