Urgent WordPress Malware Removal
Бюджет: $50.0
FIXED /
⭐ 5.00 (31)
United Kingdom
wordpress, virus-removal, php, cpanel
Предпочтительная квалификация
- Опыт: Средний
Need urgent help to identify and remove malware from a WordPress site. The freelancer should be able to scan the site, locate malicious files or code, and clean the infection while ensuring the site remains secure afterward. Experience with WordPress security issues is important, and the work should be completed quickly to minimize downtime and risk. Please share relevant experience and your approach to malware removal.
## WordPress Malware Removal & Security Investigation
I need an experienced WordPress security specialist to investigate and clean a suspected malware infection on a live WooCommerce website.
Wordfence has detected malicious code inside:
`/wp-content/themes/shoptimizer-child-theme/functions.php`
Detection:
**IOC:JS/fake.analytics.16210 – Fake Google Analytics script hiding malware**
The suspicious code is an obfuscated JavaScript injection added to the child theme `functions.php`.
### Important
The entire `functions.php` file must **not** be deleted or replaced. It contains important custom WooCommerce code, including our software licence activation system, checkout modifications, customer account creation and other custom functionality.
### Work Required
* Back up the website and database before making changes
* Safely remove the malicious code without damaging legitimate custom functionality
* Perform a full malware scan of all WordPress files and database
* Check for backdoors, additional injected files, suspicious PHP/JavaScript and modified core files
* Check plugins, themes, MU plugins, uploads, `.htaccess` and `wp-config.php`
* Check WordPress administrator accounts for anything suspicious
* Check WP-Cron/scheduled tasks for malicious entries
* Check hosting/access logs where possible
* Investigate how the compromise occurred
* Check whether a vulnerable plugin/theme or stolen credential was likely responsible
* Update and secure the WordPress installation where appropriate
* Run Wordfence again after cleanup
* Test WooCommerce checkout, customer accounts and our custom software licence activation system after the work is completed
The affected `functions.php` file was showing a modification date of approximately:
**6 August 2026 at 11:50 AM**
Please investigate activity around this time if logs are available.
### Deliverable
I need a short report confirming:
* What malware or suspicious code was found
* What was removed or repaired
* Whether any backdoors were discovered
* Likely cause or entry point
* Whether any passwords or API credentials should be changed
* Recommended security improvements
* Confirmation that the site is clean after rescanning
This is a live e-commerce website, so experience with **WordPress malware removal, WooCommerce and security forensics** is important.
Please only apply if you regularly handle compromised WordPress websites rather than general WordPress development.
Открыть заказ
AI-черновик отклика
Короткий текст отклика для копирования в оффер: интерес + готовность работать.
Войдите, чтобы сгенерировать AI-черновик.
Войти