WordPress Security Assessment, Multi-Site Remediation, and Clean Website Rebuild
📍 AlbanySecurityPosted Aug 28, 2026via html-list
I am requesting an estimate for a whole-account WordPress security assessment and the clean rebuilding of one compromised website.
My WebHostingHub/cPanel account contains five domains:
• arealwholelot.com — document root: /public_html
• kaneconsultingandcoaching.com — document root: /public_html/kaneconsultingandcoaching.com
• doctoralsuccess.com — document root: /doctoralsuccess.com
• finisheddissertation.com — document root: /finisheddissertation.com
• jakproductions.biz — document root: /jakproductions.biz
WebHostingHub confirmed that arealwholelot.com was compromised. A support representative found substantial malicious base64 code in its wp-config.php file. The host reinstalled the WordPress core files, but the problem persisted. The host did not perform a complete malware scan, identify all affected files, or determine how long the infection had been present.
Although the sites use separate WordPress installations, Kane Consulting and Coaching is nested beneath /public_html, and all five sites share the same hosting account. I therefore need the entire account examined—not only the known infected wp-config.php file.
I have a full cPanel account backup created on August 16, 2026. It is a 3.65 GB preservation snapshot stored locally and in Dropbox. Because it was created after the compromise was discovered, I am treating it as potentially infected and will not restore or share it except through an agreed secure process.
Please provide an itemized estimate addressing:
• A security assessment and malware scan of the entire hosting account, including all five sites, databases, wp-config.php and .htaccess files, administrator accounts, themes, plugins, uploads, cron jobs, and other persistence mechanisms.
• Safe containment of arealwholelot.com without disabling or damaging kaneconsultingandcoaching.com or the other sites.
• Identification and remediation of any compromise found in the other WordPress installations or elsewhere in the hosting account.
• A fresh rebuild of arealwholelot.com using a clean WordPress installation, freshly obtained themes and plugins, and only scanned and validated content recovered from the old site.
• Security hardening, including credential rotation guidance, new WordPress salts, multifactor authentication where available, removal of unused accounts and software, firewall or monitoring recommendations, and properly configured off-site backups.
• Post-remediation testing and written confirmation that the rebuilt site and the other installations have passed malware scans.
Please also include:
• Your proposed approach: cleaning the existing ARWL installation, rebuilding it, or both—and why.
• The estimated schedule.
• Itemized one-time charges.
• Any required subscriptions or continuing fees.
• What access or credentials you would require and how they would be transmitted securely.
• What reports or documentation I would receive.
• Whether you provide a remediation warranty or follow-up period if malware reappears.
• Your experience handling compromised WordPress accounts with multiple sites under one cPanel account.