WordPress/WooCommerce Security Audit + Code Review + Front End Fixes — B2B Trade Platform

Posted 4 days ago

Worldwide

Summary

I am building a B2B trade ordering platform (WordPress + WooCommerce + custom PHP plugin layer) that connects wholesale suppliers with their business customers across Australia. I am pre-launch and looking for an experienced developer or small team to do three things: 1. Security audit — a full review of the custom plugin layer, the checkout and order flow, file upload handling, and data access controls. This needs to be thorough. Flag everything from critical vulnerabilities through to hardening recommendations. 2. Code audit — a general code quality review. Structure, error handling, edge cases, and anything that looks fragile or likely to break under real usage. I want a prioritised list — critical, important, minor — rather than a pass or fail. 3. Front end fixes — approximately four to six specific items including card layout, product name truncation, button styling, and promotional text display. This is not a redesign. The platform has already been through internal development and testing, so you are auditing a functional product rather than starting from scratch. I want a second, independent set of eyes on it before it goes live with real customers and real orders. To be clear about the scope: this is not a stock WordPress install. The order handling, catalogue logic and fee calculations sit in a custom plugin layer, and that is where I most want attention. I am looking for someone willing to read the code properly rather than run a scanner over it — two significant issues have already been found and fixed internally, and both were only caught by reading carefully. Stack: WordPress, WooCommerce, and a custom PHP plugin layer. Target hosting is SiteGround. Happy to share more detail on scale and complexity under NDA. Not in scope: new feature development, performance optimisation, hosting migration, or any redesign work. What I will provide: access to the codebase via private repository, and availability to answer questions throughout. I want this to be straightforward for whoever takes it on. Access and confidentiality: A mutual NDA is required before any code access is granted. Deliverable: a written report with findings prioritised as critical, important, or minor. Each finding should include its location in the codebase, the severity, and a recommended fix. For any remediation work that follows, I want verification evidence — before and after test results, not just a description of the fix — and each fix retested against the original finding. Timeline: I am looking for someone who can start promptly and turn the initial audit around within a couple of weeks. Launch is planned for the coming months. Ongoing maintenance work: Once the platform is live I intend to put a developer or small team on a monthly retainer — routine WordPress and plugin updates, patching, backups, bug fixes, and support with an agreed response time. I would rather build that relationship with whoever does this audit than start again with someone new. Please mention in your application if ongoing retainer work is of interest, and roughly what you would charge for it. What I am looking for: • Strong WordPress, WooCommerce, and PHP experience, ideally with custom plugin development • Security review experience, OWASP familiar • Clear written reporting. I need to be able to act on your findings, not just read them • Some overlap with Australian business hours is preferred but not essential • Comfortable working async with clear written updates • If you are applying as a team, please tell me who will be doing the work and who my main point of contact will be Structure and payment (all figures AUD): I have budgeted $1,000–2,000 for the security audit, code audit, and written report, held in Upwork escrow and released on delivery. I will consider higher for the right person given the custom plugin layer involved. Remediation work and the front end fixes will be billed hourly at $45–65/hour, with an agreed cap once we both know what the audit has found.

  • Less than 30 hrs/week
    Hourly
  • 1-3 months
    Duration
  • Intermediate
    Experience Level
  • $15.00

    -

    $35.00

    Hourly
  • Remote Job
  • Ongoing project
    Project Type
Skills and Expertise
Mandatory skills
WordPress
WordPress Plugin
Activity on this job
  • Proposals:20 to 50
  • Interviewing:
    0
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Jul 13, 2026
  • Australia
    10:59 AM

Explore similar jobs on Upwork

JavaScript
Node.js
PHP
Web Application
AI App Development
DevOps
API
Git
MySQL
Cs2 Gambling SiteFixed-price‐ Posted 4 weeks ago
Gambling
Unity
Counter Strike
AR & VR
Online Gambling Website
Card Game
Board Game
Unreal Engine
MetaMask
Mystery Box
iGaming
WebGL
Game Development
Gaming
Multiplayer
Game UI/UX Design
UI/UX Prototyping
Steam API
AI Development
PixiJS

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo