WooCommerce Security Hardening Specialist — Store Audit + Ongoing Protection

Posted 4 weeks ago

Worldwide

Summary

Scope of work • Full security audit of the WordPress/WooCommerce install (core, theme, plugins, file permissions, user roles, exposed endpoints) • Malware/backdoor scan and cleanup if anything is found • Harden wp-admin, XML-RPC, REST API, and login (rate limiting, 2FA, brute-force protection) • Cloudflare WAF configuration: custom rules, bot management, rate limiting on checkout/cart/login, and blocking non-human traffic hitting expensive endpoints • Server-level hardening: firewall, fail2ban, SSH, PHP config, file integrity monitoring • Checkout and payment flow security review (card testing / carding attack prevention, fake order and spam order filtering) • Automated offsite backups with a tested restore procedure • Monitoring and alerting so we know when something’s wrong before customers do • Short written handoff doc covering what was changed and how to maintain it Required experience • 3+ years securing WordPress/WooCommerce stores in production • Strong Linux VPS admin skills (Nginx/Apache, PHP-FPM, MySQL) • Deep Cloudflare experience — WAF custom rules, not just turning on the toggle • Proven history cleaning up hacked or bot-flooded WooCommerce sites • Understands e-commerce-specific threats: card testing, checkout abuse, credential stuffing, scraping Nice to have • Experience with high-volume transactional email deliverability • Familiarity with FluentCRM or similar • Security certifications or documented CVE/bug bounty work Engagement Starts as a fixed-scope audit + hardening project. If it goes well, we’ll move to a monthly retainer for monitoring, patching, and incident response. To apply, answer these: 1. Describe a WooCommerce site you secured — what was the threat, and what did you actually do? 2. What’s your approach to blocking bots without hurting real customers or SEO? 3. What tools do you use for monitoring and file integrity? 4. Your availability and estimated timeline for the initial audit. Please skip generic proposals. Applications that don’t answer the questions won’t be reviewed.

  • Less than 30 hrs/week
    Hourly
  • 1-3 months
    Duration
  • Expert
    Experience Level
  • Remote Job
  • Ongoing project
    Project Type

Contract-to-hire opportunity

This lets talent know that this job could become full time.
Learn more
Skills and Expertise
Mandatory skills
WordPress
Network Security
Activity on this job
  • Proposals:20 to 50
  • Last viewed by client:3 weeks ago
  • Hires:
    1
  • Interviewing:
    4
  • Invites sent:
    5
  • Unanswered invites:
    0
About the client
Member since May 27, 2025
  • USA
    Sugar Land5:25 AM
  • $2.7K total spent
    6 hires, 0 active
  • 24 hours

Explore similar jobs on Upwork

Vulnerability Assessment
Penetration Testing
Information Security
Whitehat Hacker for Billing SoftwareHourly‐ Posted 1 month ago
Software Testing
Penetration Testing
Software QA
Manual Testing

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo