Senior Web Security & SEO Audit for React Site After WordPress Malware Hack
Budget: $120.0
FIXED /
⭐ 0.00 (0)
India
malware-removal, assessments-and-testing, source-code-scanning, vulnerability-assessment, infromation-security-consultation, website-security, web-application-security, wordpress-malware-removal, technical-seo
Gewenste kwalificaties
- Ervaring: Expert
We need a senior web security / cPanel / technical SEO specialist to perform a final independent audit of thebrothing.com before we submit a Meta/Instagram appeal.
Current situation
Our current website is a React/Vite SPA hosted on Apache/cPanel.
The domain previously ran an older WordPress website which was historically compromised with casino/gambling SEO-spam URLs.
We have already:
moved to new hosting
uploaded a clean React build
scanned the uploaded files with VirusTotal
removed the old WordPress environment from production
configured known hacked/retired URLs to return 410
configured random/nonexistent URLs to return 404
kept legitimate current pages at 200
preserved legitimate historical redirects as 301
created and submitted a valid sitemap.xml
cleaned website copy and removed positive result-guarantee language
added disclaimers
added Open Graph metadata and og:image
verified the domain inside Meta Business
confirmed Meta Sharing Debugger can currently fetch the new homepage with HTTP 200 and the correct branding
confirmed Google Search Console currently shows no Security Issues and no Manual Actions
We are not looking for someone to rebuild or clean the website from scratch.
We need an experienced specialist to independently verify that the current production environment is clean, technically correct and safe to use for a Meta appeal.
Please audit the following:
New hosting / cPanel
inspect public_html
confirm no old WordPress files remain
confirm no malware, backdoors, webshells or suspicious PHP remain
inspect .htaccess, .user.ini, php.ini
inspect cron jobs
inspect FTP/SSH access
inspect recently modified PHP files
confirm legitimate /api/*.php files are safe
React/Vite production build
verify source/build is clean
inspect compiled JS/CSS for suspicious injected code
confirm no casino/loan/pharmacy/adult spam exists in current build
confirm no malicious external scripts or redirects
HTTP routing
Verify:
legitimate current pages → 200
legitimate old redirects → 301
known hacked/retired URLs → 410
random/nonexistent URLs → 404
assets/APIs continue to work normally
Historical spam verification
Search current hosting/build/config for:
casino
gambling
Pokerdom
Mostbet
BetFlag
Plinko
Glory Casino
Chicken Road
payday/loan spam
pharmacy spam
adult/escort spam
Confirm these are not live anywhere on the current hosting.
Google Search Console
Review:
Security Issues
Manual Actions
URL Inspection
Page Indexing
Removals
sitemap.xml
robots.txt
canonical tags
soft 404s
5xx errors
Confirm current legitimate pages are indexable and old hacked URLs are unavailable through 404/410.
Sitemap / robots / canonicals
verify sitemap.xml contains only legitimate current public URLs
verify no spam/retired URLs are included
verify robots.txt is valid
verify canonicals are correct
confirm no old malicious or incorrect canonical URLs remain
Crawler consistency
Compare:
normal browser
Googlebot
Facebook/Meta crawler
Confirm they all see the same legitimate website.
Rule out:
cloaking
bot-only spam
mobile-only redirects
geo/referrer-based spam
DNS / hosting consistency
confirm A/AAAA records point to the correct new hosting
confirm no old origin/server remains active
confirm www/non-www behave correctly
confirm Cloudflare, if used, points to the correct origin
Meta-facing technical check
Verify:
current homepage is reachable by Meta
correct canonical
correct og:title
correct og:description
correct og:image
no casino/spam metadata
retired spam URLs do not behave like active business pages
Important working rule
This is an audit-first job.
Do NOT delete or modify anything initially.
First send us:
findings
risks
suspicious files/configs
screenshots/evidence
recommended changes
We will approve any changes before you make them.
Required final report
Please provide a concise PASS/FAIL report for:
current hosting clean
malware/backdoor/webshell
old WordPress remnants
suspicious cron/FTP/SSH access
casino/SEO spam live
loan/pharmacy/adult spam live
legitimate pages 200
redirects 301
hacked/retired URLs 410
random URLs 404
sitemap clean
robots.txt clean
canonicals clean
Googlebot cloaking
Meta crawler sees clean site
Search Console Security Issues
Search Console Manual Actions
final malware scan
Also provide a list of every change made, if any.
Please answer these in your proposal:
Have you audited a site after a historical WordPress SEO-spam hack?
Have you handled casino/gambling spam specifically?
Can you audit cPanel beyond simply installing Wordfence?
Can you manually inspect PHP for backdoors/webshells?
Are you comfortable with React/Vite + Apache?
Can you audit Google Search Console after a hacked-site incident?
Can you compare Googlebot/Meta crawler responses against a normal browser?
How many hours will this final audit take?
What fixed price would you quote?
Most remediation has already been completed. This project is for final independent verification before appeal, not a full rebuild or malware cleanup from scratch.
Openen op Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Inloggen