Hire Me
Back to Portfolio
Security Hardening 2026

Complete WordPress Malware Removal

Wordpress Security and malware removal

A root-level server compromise via Yanz Webshell (Symlink Bypass) that infected core directories (.ssh, .cagefs) and injected 140 spam posts, rendering standard cleanup useless.

Forensics: Used Linux CLI on access-logs to trace the breach to an xmlrpc.php brute-force attack.

Wipe & Restore: Extracted clean databases and media, wiped the infected cPanel account, and deployed a fresh server architecture.

Hardening: Permanently blocked XML-RPC and updated the Defentry security engine to prevent recurrence.

Total Server Recovery
Database Clean
Live Again
WordPress PHP MySQL

Project Details

Client Confidential (NDA)
Year 2026
Duration 1 Days
Category Security Hardening
View Live Site ↗

Need Similar Work?

I can build this for you. Let's discuss your project.

Get a Quote →