More than 150 WordPress sites cleaned personally in the past 12 months — a verifiable record, shared during scoping. 

Independent WordPress & server security

WordPress security. From server to site.

Independent audits, malware removal, and hardening for WordPress and Linux servers — with clear findings, practical fixes, and verified results.

I need ongoing protection → View a sample report →

Coverage

Every layer an attacker can reach.

A hardened WordPress install can still sit on an exposed server, a weak account model, or a backup nobody has restored. All five layers are assessed together.

  1. 01

    Edge

    DNS, TLS, CDN and WAF — what the public internet reaches, and what it reveals.

  2. 02

    Server

    Linux, Nginx or Apache, PHP, database, file permissions and tenant isolation.

  3. 03

    WordPress

    Core, themes, plugins, and the configuration and update posture around them.

  4. 04

    Accounts

    Roles, administrative access, session handling and business logic.

  5. 05

    Recovery

    Logging, detection, backups — whether a compromise is noticed and reversible.

How an engagement runs →

Services

Start from what you need right now.

Full pricing and scope factors →

Not sure which fits? Describe the system and the concern — scoping decides whether the work is preventive, incident-related, or compliance-driven. Compare all eight services →

Start an enquiry

What’s going on?

Active incidents get a reply the same business day; everything else within 24 hours, with the recommended scope and next steps. Scoping and the written proposal are free.

How urgent is it?

Never send credentials through this website. NDA available · written authorization required before any testing.

Portrait of G. Schad

The specialist

G. Schad

Independent WordPress and Linux security specialist

I audit, clean up and harden WordPress sites and the Linux servers they run on — every finding validated by hand, never a scanner export.

Public work evidence and credentials →

“Guido has been handling our website security and server audits for over five years… He currently helps us keep more than eight servers secure, identifying vulnerabilities, hardening our websites, and addressing potential security issues before they can become serious problems.”

Dan Wilson Verified client · August 2026 Read the full endorsement →

“Guido provided valuable technical support and security expertise throughout a complex server security project… We appreciated the depth of his technical knowledge and the quality of the audit work he delivered.”

Server security audit, hosting environment · September 2026 Verified contract

“Guido is very reliable, detail-oriented, and really knows what he’s doing when it comes to malware removal. I will definitely hire him again.”

ClickFix malware removal, WooCommerce store · March 2026 Verified contract

“Great communication. Clear, thorough and fast work. Perfect!”

Penetration assessment, SaaS web app · March 2026 Verified contract

“Got rid of the malware quickly and professionally. We felt confident having Guido work on our site.”

WordPress malware removal and security · July 2026 Verified contract

“Guido is a true professional and an expert in server security. He quickly understood the urgency of our situation, identified the vulnerabilities, and took action with precision and care…”

Server audit, cleanup and hardening · August 2025 Verified contract

“Outstanding work — clear communication, careful assessment, helpful suggestions. Already set up another contract with Guido.”

Security assessment, web app · December 2025 Verified contract

“Very happy with the work here. Very knowledgeable and provided excellent information.”

Security audit, new website · June 2026 Verified contract

“10/10 recommendation”

Japanese keyword hack recovery · July 2025 Verified contract

“Project completed successfully, already working on another project.”

WordPress and WooCommerce malware investigation · September 2026 Verified contract

“Guido was exceptional from start to finish. He quickly identified the security vulnerability on our WordPress site, cleaned up all compromised files, and implemented the necessary hardening measures…”

WordPress security audit and hardening · July 2025 Verified contract

“After a fairly sophisticated, multi-pronged attack on our wordpress site, Guido was fantastic at identifying issues, solving them, and helping me build confidence in our web assets again…”

Security audit, WordPress web server · November 2025 Verified contract

“Second project I’ve done with Guido — again was fast, clear, clean, did great work.”

Security assessment, web app · January 2026 Verified contract

“5/5. Responds to all inquiries quickly, pricing is very fair and competitive, especially considering the quality of work delivered. Efficient, completing tasks accurately and faster than expected.”

VPS Linux setup for WordPress staging · November 2025 Verified contract

“Je suis entièrement satisfait. Interlocuteur réactif, professionnel et à l’écoute. Je recommande sans hésiter.”

Debian and WordPress server hardening · April 2025 Verified contract

“Die Zusammenarbeit mit Guido war von Anfang bis Ende hervorragend. Er hat sehr schnell gearbeitet, war jederzeit freundlich und professionell und ist auf alle meine Änderungswünsche eingegangen…”

Technical SEO and website review · July 2026 Verified contract

“Guido quickly fixed a malware issue on our website and got our site clean. Very fast and professional. Thanks again.”

Website security and malware cleanup · June 2025 Verified contract

“As always, Guido delivers outstanding work. He is proactive, highly experienced, and communicates clearly. We strongly recommend him.”

WordPress troubleshooting and support · August 2025 Verified contract

Every endorsement above is quoted verbatim from a completed contract on the public Upwork profile. An ellipsis marks where a longer review has been shortened; only whole sentences are quoted.

Featured case study · E-commerce

Three cleanups had not held. The fourth ended the cycle.

Three parties had cleaned the store, and the malicious behavior returned every time. The fourth engagement treated the recurrence itself as the finding.

Read the repeat-reinfection case study →
Environment
Production WordPress e-commerce site
History
Three prior cleanups by other parties; infection returned each time
Objective
Remove every persistence layer and identify the likely access path
Outcome
Persistence removed, access reset, entry condition addressed, recovery verified

Browse all case studies →

The deliverable

Findings your team can act on.

Each finding carries severity, the affected component, evidence, business impact, a remediation summary, an acceptance test, and a retest status. Scanner output is never reported as a confirmed vulnerability.

View sample report
FINDING HOST-01 · WORKED EXAMPLE 3 of 12
HIGH COMPONENT: SHARED HOSTING ACCOUNT

Four production sites share one filesystem identity

EVIDENCE

Controlled cross-site read and write between sites sharing one account.

BUSINESS IMPACT

One compromised site can reach the files and configuration secrets of three others.

REMEDIATION

Move each site into its own hosting account and PHP-FPM identity, with separate deployment and database credentials.

RETEST

Open — staging migration passed; production separation still outstanding.

Engagement process

Controlled from scoping to retest.

  1. STEP 01

    Scope and authorize

    Define systems, objectives, exclusions, timing, contacts, and testing permission.

  2. STEP 02

    Assess and verify

    Combine tools with manual validation while respecting the agreed rules of engagement.

  3. STEP 03

    Report and explain

    Deliver prioritized findings, evidence, business impact, and practical remediation steps.

  4. STEP 04

    Remediate and retest

    Fix agreed issues directly or support the client’s team, then verify the result.

Selected research

Published work you can read before hiring anyone.

INCIDENT REPORT · WHM SERVER

The backdoor three clean scan results missed

Wordfence flagged 283 files, ImunifyAV agreed, and the database export was clean. The backdoor was a hidden ELF binary outside the web root on a 261-account WHM server — with the detection method and triage checks for your own server.

Read the WHM server backdoor report →
INCIDENT REPORT · 30+ SITES

ClickFix malware across a WordPress fleet

A coordinated infection mapped layer by layer: redacted evidence, IOC triage, MITRE ATT&CK mapping, and the cleanup that held. Free PDF included.

Read the ClickFix incident report →
Is the first conversation free?

Yes. The inquiry, the scoping conversation, and the written proposal are free and carry no obligation. Fees apply only to the engagement you agree to, at the fixed price the proposal states.

Will testing affect production availability?

Testing windows and production constraints are agreed first. Nothing destructive runs unless it is separately authorized, and an escalation contact is in place throughout.

What access will you need?

It depends. Assessments often begin from the outside with no access at all; audits and hardening need a named, least-privilege account with a documented expiry — arranged after scoping through an agreed secure method, never through this website.

Can you fix the findings as well as report them?

Yes — directly, or as guidance for your own developers and administrators. Agreed fixes are retested and the finding’s status is updated in the report.

Request a confidential assessment.

Describe your site and concern. I’ll reply within 24 hours with the recommended scope and next steps — the same business day for an active incident. Scoping and the proposal are free; the engagement is quoted as a fixed fee before any access is exchanged.

Get a scope and fixed quote
NOTE

Never send credentials through this website. No passwords, keys, backups, or source code in a first message — if a secret is sent by accident, rotate it immediately. Access, NDA, and authorization terms →