Senior WordPress / WooCommerce Security Expert Needed – Root Cause Analysis of Bot Traffic & Server Load
Budget / Salary€30–250
TypeFreelance project
LocationRemote
Posted2 hours ago
We run a live WordPress / WooCommerce webshop behind Cloudflare on a Linode/cPanel server.
We are experiencing abnormal automated traffic that started only recently, after website redevelopment and changes to our advertising setup. For many years we monitored live visitors daily and never saw this pattern before.
The current issue includes:
* large waves of browser-like visitors from Singapore, Malaysia and other regions
* rotating IP addresses
* traffic reaching category/product pages and sometimes cart/checkout
* very short sessions with no referrer
* high server load and many 5xx errors during attack periods
* previous abnormal WooCommerce actions such as add-to-cart / wishlist traffic
* Cloudflare blocking rules sometimes causing false positives for real customers
We do not want someone who simply adds more blocking rules or installs another security plugin.
We need an experienced security engineer who can perform a proper root-cause investigation.
Required investigation:
* Apache/cPanel raw access log analysis
* Cloudflare Security Analytics / Traffic / WAF review
* Cloudflare audit/change history
* check whether the Linode origin can be accessed directly and bypass Cloudflare
* Linode firewall / CSF / server network configuration
* WordPress and WooCommerce plugin review
* REST API / AJAX / cron / generated action URLs
* Google Tag Manager / Google Ads / tracking / Pixel Manager changes
* DNS, robots.txt, sitemap and feeds
* malware / backdoor / file integrity review
* timeline comparison: what changed immediately before the abnormal traffic started
* identification of the actual source and mechanism of the traffic
Deliverables:
1. Clear written root-cause conclusion
2. Evidence supporting the conclusion
3. Exact example IPs, requests, timestamps and affected endpoints
4. Separation of confirmed facts vs hypotheses
5. Recommended remediation steps
6. Confirmation whether this is external bot traffic, crawler abuse, application behaviour, configuration error, origin bypass, compromise, or a combination
Important:
* Do not make production changes without approval.
* Do not block countries or checkout globally.
* Do not disable Google/AdsBot traffic.
* Preserve logs and evidence.
* We want diagnosis first, remediation second.
Please only apply if you have proven experience with:
* WordPress/WooCommerce security
* Cloudflare WAF / Security Analytics
* Linux/cPanel servers
* web server log analysis
* bot / crawler abuse
* incident response
In your proposal, explain how you would investigate this issue step-by-step before making changes.
We are experiencing abnormal automated traffic that started only recently, after website redevelopment and changes to our advertising setup. For many years we monitored live visitors daily and never saw this pattern before.
The current issue includes:
* large waves of browser-like visitors from Singapore, Malaysia and other regions
* rotating IP addresses
* traffic reaching category/product pages and sometimes cart/checkout
* very short sessions with no referrer
* high server load and many 5xx errors during attack periods
* previous abnormal WooCommerce actions such as add-to-cart / wishlist traffic
* Cloudflare blocking rules sometimes causing false positives for real customers
We do not want someone who simply adds more blocking rules or installs another security plugin.
We need an experienced security engineer who can perform a proper root-cause investigation.
Required investigation:
* Apache/cPanel raw access log analysis
* Cloudflare Security Analytics / Traffic / WAF review
* Cloudflare audit/change history
* check whether the Linode origin can be accessed directly and bypass Cloudflare
* Linode firewall / CSF / server network configuration
* WordPress and WooCommerce plugin review
* REST API / AJAX / cron / generated action URLs
* Google Tag Manager / Google Ads / tracking / Pixel Manager changes
* DNS, robots.txt, sitemap and feeds
* malware / backdoor / file integrity review
* timeline comparison: what changed immediately before the abnormal traffic started
* identification of the actual source and mechanism of the traffic
Deliverables:
1. Clear written root-cause conclusion
2. Evidence supporting the conclusion
3. Exact example IPs, requests, timestamps and affected endpoints
4. Separation of confirmed facts vs hypotheses
5. Recommended remediation steps
6. Confirmation whether this is external bot traffic, crawler abuse, application behaviour, configuration error, origin bypass, compromise, or a combination
Important:
* Do not make production changes without approval.
* Do not block countries or checkout globally.
* Do not disable Google/AdsBot traffic.
* Preserve logs and evidence.
* We want diagnosis first, remediation second.
Please only apply if you have proven experience with:
* WordPress/WooCommerce security
* Cloudflare WAF / Security Analytics
* Linux/cPanel servers
* web server log analysis
* bot / crawler abuse
* incident response
In your proposal, explain how you would investigate this issue step-by-step before making changes.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.