WordPress services
WordPress Maintenance and Malware Removal
I look after WordPress sites for businesses and agencies: tested updates, restore-tested backups, malware cleanup, migrations, WooCommerce fixes, speed work and custom plugins. Hacked sites get a fixed eight-step method, and I say plainly when a full recovery is not possible.
By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated
What does WordPress maintenance include?
It covers the routine work that stops a site from breaking or being hacked: tested updates, backups you know can be restored, uptime checks and a regular review of what is installed.
- Updates tested before release. Core, plugin and theme updates go to a staging copy first. I click through forms, login, search and checkout, and only then update production.
- Backups with restore tests. Files and database are copied off the server on a schedule. A backup that has never been restored is only a hope, so I restore one into a test environment and confirm the site loads.
- Uptime checks. An outside monitor requests your homepage and one key page and alerts me when the response or the expected text is wrong. A hosting panel that says the server is up does not prove the site works.
- Housekeeping. Unused plugins and themes come off, administrator accounts are reviewed, and old revisions and spam comments are cleared from the database.
I agree maintenance as an ongoing arrangement after seeing the site, because a small brochure site and a busy shop need different attention. Alerts reach me and I respond during my working day in India Standard Time.
How do you remove malware from a hacked WordPress site?
I follow the same eight steps every time, because cleaning visible symptoms without finding the entry point is how sites get reinfected within days.
- Isolate and snapshot. I limit public access, usually by IP allow-list or maintenance mode, and copy all files and the database before changing anything. That gives me evidence and a way back.
- Scan. I run server-side and WordPress-aware scanners, then search by hand for typical code such as
eval(base64_decode(,gzinflateand recently modified PHP files. - Check the usual hiding places.
wp-content/uploadsshould hold no PHP files.wp-content/mu-pluginsloads automatically and is easy to miss.wp-config.php,.htaccessand.user.inican carry injected code or anauto_prepend_fileline. I list every administrator account, since attackers add their own, and search the database for injected scripts in posts and inwp_options. - Replace core and plugin files from fresh copies. I compare against official checksums and reinstall instead of hand-editing infected files.
- Rotate secrets. New keys and salts in
wp-config.phplog everyone out. Then new passwords for WordPress admins, the database, the hosting panel, SFTP and any API keys. - Close the entry point. From logs and file dates I find the likely way in: an outdated plugin, a nulled theme, a stolen password, or another infected site on the same account. Until that is fixed, the site will be hit again.
- Harden. I disable the built-in file editor, block PHP execution in uploads, correct file permissions, add login protection and remove unused code.
- Monitor. I watch for file changes, rescan after a day and after a week, and check Google Search Console for security warnings.
The checksum comparison in step 4 uses WP-CLI. The plugin check covers plugins hosted on wordpress.org only:
wp core verify-checksums
wp plugin verify-checksums --all
What causes common WordPress problems, and what do you do?
Most problems have a short list of usual causes. I start with those and confirm them from logs before changing anything.
| Problem | Typical cause | What I do |
|---|---|---|
| White screen or critical error after an update | A plugin or theme that conflicts with the new version, or an unsupported PHP version | Turn on WP_DEBUG_LOG, read wp-content/debug.log, disable the culprit by renaming its folder, then fix or replace it. |
| Spam pages in Google, or visitors sent to other sites | Injected code in files or the database, often through an outdated plugin | Run the cleanup method above, then request a review in Google Search Console. |
| Checkout loops, empty cart or failed payments | Cart and checkout pages served from cache, an outdated gateway plugin, or a firewall blocking the gateway callback | Exclude cart, checkout and account pages from caching, read the gateway log in WooCommerce and test in the gateway's test mode on staging. |
| Orders paid but still pending | The gateway webhook never reaches the site | Check the webhook URL, security plugin rules and SSL, then replay a failed event. |
| Slow pages | Heavy plugins, no page cache, oversized images or a bloated autoload in wp_options | Measure first, then add caching, resize images, replace slow plugins and trim the autoload. |
| Form emails not arriving | Server mail blocked, or sent without SPF and DKIM | Send through authenticated SMTP and set the DNS records. |
| Redirect loop after moving to HTTPS | Mismatched home and siteurl values, or a proxy not passing the HTTPS header | Correct the URLs and the server or CDN setting. |
Can you migrate my WordPress site to a new host?
Yes. I copy files and database to the new host, test the site there before DNS changes, and switch at a quiet time. URL changes go through a tool that understands serialized data, such as wp search-replace, because a plain find-and-replace in SQL corrupts theme and plugin settings. Afterwards I check permalinks, SSL, email delivery, scheduled tasks and forms. For larger server projects, see server migration and backup.
Do you build custom WordPress plugins?
Yes. I have built more than 50 WordPress plugins, from small admin utilities to WooCommerce extensions and connections to outside systems, including WHMCS. A plugin is the right home for custom logic because it survives a theme change, which code pasted into functions.php does not. I use nonces and capability checks on every action, sanitize input, escape output, run queries through $wpdb->prepare() and clean up on uninstall. For a WordPress site that talks to a billing system, see WHMCS API integration.
How do you approach speed work?
I measure real page timings first and change one thing at a time. Typical wins are page caching, correctly sized images, fewer or lighter plugins and a smaller database autoload. I do not promise a particular score, because results depend on your host, theme and plugins.
What can I not do for a WordPress site?
There are cases where I decline the work or limit what I promise.
- I do not install, clean around or keep nulled themes and plugins. They are a common entry point for infections. I replace them with licensed versions or alternatives.
- If the site was heavily altered and no clean backup exists, I cannot promise full recovery. I rebuild from what can be verified as clean and tell you what could not be saved as soon as I know.
- I cannot control how fast Google lifts a warning. I submit the review and Google decides.
- I cannot protect a site on a hosting account shared with other infected sites. The account has to be cleaned or the site moved.
What does it cost?
I quote a fixed price within one business day of the scoping call and a first look at the site, or work hourly at $55 to $65 per hour. Maintenance is quoted as a recurring arrangement once I know what the site needs. If the site sits on your own VPS, server security hardening closes the gaps at server level. The terms are on how I work.
Who this is for
- Owners whose site shows spam, strange redirects or a Google security warning
- Agencies that need a dependable person to look after client sites after launch
- Shop owners whose WooCommerce checkout or payments fail some of the time
- Teams that need one custom plugin instead of another stack of off-the-shelf ones
What is included
- A staging copy of the site for testing updates and fixes
- A backup with a documented restore test
- An outside uptime check on the homepage and one key page
- A written list of what changed and why
- For hacked sites, a cleanup report with infected files, entry point and fixes
- Hardening changes: permissions, login protection, disabled file editor
- An audit of plugins and themes, including abandoned and unused ones
- Two weeks of support after delivery
How the work runs
-
1
Review
I look at the site, hosting, plugin list and logs, and tell you what is wrong, what is risky and what I would leave alone.
-
2
Stage
I take a full backup and build a staging copy, so changes are tried away from your live visitors and customers.
-
3
Fix
I carry out the maintenance, cleanup, migration or plugin work, with a daily progress update while it runs.
-
4
Verify
I test the pages that matter to you: forms, login, search and checkout. For a hacked site I rescan after a day and again after a week.
-
5
Hand over
You receive a written summary of every change. I stay available for two weeks in case anything surfaces.
Frequently asked questions
How long does WordPress malware removal take?
Typically one to three days, depending on the size of the site and how deep the infection goes. A single site with a few infected files is faster. A site with a modified database, several backdoors and a shared hosting account that also needs cleaning takes longer. I give a more exact estimate after a first look at the files and logs.
Will my site be offline while you clean it?
Not necessarily. I often work on a copy and keep the live site running, but if it is spreading malware to visitors or sending spam I may restrict access for a short time. I tell you before I do. The final switch from the cleaned copy to the live site usually takes minutes.
Why do hacked WordPress sites get infected again?
Usually because only the visible damage was removed. The entry point stayed open: an outdated plugin, a nulled theme, a weak or stolen password, or another infected site on the same hosting account. Cleanup therefore includes finding the way in, closing it, and rotating every password and key. Until that is done, reinfection is likely.
Can you remove the Google warning about my site?
After the site is clean I submit a review request through Google Search Console and check that the warning conditions are gone. Google makes the decision and sets the timing, so I cannot control how quickly the warning disappears. Fixing the real infection first matters, because a review of a still-infected site is rejected.
How do you test updates before applying them?
I update a staging copy first, then click through the pages that earn you money or inquiries: forms, login, search and the full checkout in the gateway's test mode. If something breaks, I find the plugin or theme responsible before touching the live site. Only a tested set of updates goes to production, after a fresh backup.
What access do you need for a WordPress job?
Usually an administrator login, or SFTP and database access if the dashboard is unreachable, plus the hosting panel for backups and logs. Temporary accounts are best, and I remove my access when the work ends.
Related services
-
Server Hardening Service for Linux and cPanel Servers
I harden Linux and cPanel servers with SSH keys, firewall review, patching, PHP isolation and protected backup...
-
cPanel Server Migration and Backup Setup
I move cPanel accounts, mail and DNS to a new server with a tested cutover, then set up local and off-site bac...
-
WHMCS API Integration and Automation
I connect WHMCS to your CRM, Slack or Telegram, SMS, accounting and control panels with the API, localAPI() an...
-
How I Work: Process, Rates and Payment
How a project with me runs: free 30-minute scoping call, written quote within one business day, $55-$65 per ho...
Ready to talk about your project?
Send the details and I reply within one business day with questions, an estimate and a plan.