Hacked Laravel or custom app cleanup and hardening
If your Laravel or custom web app has been compromised, I contain it, rebuild it on a clean server from known-good code, rotate every secret and harden the setup. This is a new service: recovery, not forensics or legal work. From $520 ($400 founding), usually 3–8 working days. Email me what you’ve seen.
See a sample report, proposal and weekly update- Price
- from $520
- Founding
- from $400
- Timeline
- 3–4 working days
- Format
- Fixed scope, fixed price
- Hours
- US Eastern Time, async
Who this is for.
A good fit if
- Laravel and custom PHP, Go or Python apps showing signs of compromise
- Teams with a leaked .env, APP_KEY or cloud key
- Founders who need a clean, hardened rebuild quickly
Common triggers
- Unknown files, admin users or redirects appear
- Your host suspends the server for sending spam or attacking others
- A secret was committed to a public repo
Not a fit if
- It’s a WordPress site (not offered here)
- You need forensic investigation, legal advice or breach notification (your counsel handles that)
- You need a guarantee that it can never happen again
What I do, and what you get.
What I do
- Contain: put the app in maintenance mode or cut traffic, and revoke obvious attacker access
- Keep a disk snapshot for your records before I change anything (I don’t analyze it)
- Rebuild on a fresh server from known-good code, not by cleaning the infected one
- Restore data from a backup you choose, and check it for obvious injected content
- Rotate secrets: APP_KEY, database passwords, API keys, SSH keys and cloud keys the app uses
- Sign out all users and force admin password resets
- Harden: updates, firewall, file permissions, debug off, 2FA on admin access
- Patch the likely entry point when I can see it, and tell you when I can’t
What you get
- The app running on a clean, hardened server
- A list of every secret rotated and any you still need to rotate
- A plain summary of what I saw, what I did and what I couldn’t confirm
- Handover notes and a hardening checklist
Your part
- Decisions on notifying users or authorities, with your own counsel
- Access to hosting, DNS, repo and third-party dashboards (payments, mail, storage)
- Rotating secrets only you can (registrar, bank, personal accounts)
- Choosing the backup date to restore from
Included
- Containment and a preserved snapshot
- Clean rebuild and data restore
- Secret rotation and hardening
- Summary and checklist
Not included
- Forensic investigation or evidence analysis
- Legal advice, breach notification or regulator contact
- Guarantee against reinfection
- WordPress malware cleanup
Fixed prices, agreed before work starts.
Contain, clean, patch, rotate credentials
Rebuild on a fresh server, rotate, harden
Rebuild of an app/database split setup
Build your scope
- Timeline
- 3–4 working days
- Payment
- Paid in full before work starts
- Earliest start
- Oct 5
Founding price: 3 of 7 spots left, until Mar 31, 2027 — one-off work, in return for a testimonial. How it works
Prices are in USD, paid by bank transfer against an invoice. Work under $1,000 is paid upfront; larger work is 50% to start and 50% before handover, or monthly milestones. How working together works
Variations
- Single server, patch in place (Starter)
- For small, well-understood incidents where a rebuild isn’t needed.
- Fresh server rebuild (Standard)
- The default.
- App and database on separate servers (Plus)
- Both nodes rebuilt and credentials rotated between them.
How it runs.
- 01
Tell me what you saw
Email what you’ve seen and when; if it’s live and urgent, book an Urgent Fix to contain it today.
- 02
Plan and price
I reply within one US business day with a plan, a fixed price and a start date.
- 03
Invoice and access
You pay the prepaid invoice (50% upfront above $1,000), then grant access.
- 04
Contain and rebuild
I contain, snapshot, rebuild, rotate secrets and harden.
- 05
Summary and handover
You get the summary, the rotation list and the handover notes.
A new service, done openly.
I have not delivered this exact service for a client before, so there is no case study to point to yet. The approach above is built from parts I have shipped in production — see the case studies — and the fixed price and written scope protect you while it is new.
Questions buyers ask.
Can you tell us how they got in?
Sometimes the entry point is obvious and I’ll say so. Finding it for sure is forensics, which I don’t do.
Do we have to tell our users?
Ask your lawyer. I’ll give them my summary.
Will it happen again?
I close what I find and harden the server, but I can’t guarantee it.
Why rebuild instead of cleaning?
On a compromised server you can’t be sure you found everything.
Can you start today?
Containment can happen today through an Urgent Fix; the rebuild follows.
Ask about Hacked App Cleanup.
Tell me what you have and where it hurts. I reply within one US business day with either a fixed quote or the entry step that makes a fixed quote possible.
Helpful to include
- Stack and versions
- What you noticed and when
- Hosting and number of servers
- Last known-good backup
- Who has access
- Whether counsel is involved
More in Troubleshooting & Bug Fixing
Urgent Fix
When production is broken, book an Urgent Fix by 12:00 ET on a working day and I start that day. It’s for Laravel, Go and Python apps. From $190 for the 2-hour minimum, then $95 an hour, at most 3 hours a day. It’s working-hours help, not 24/7 on-call. Email with URGENT in the subject.
Bug Fixing
I find and fix a specific bug in a Laravel, Go or Python app, with diagnosis first and a hard cap on hours. If it runs over the cap you get a written finding and a quote, never a surprise bill. From $195 ($150 founding) for up to 3 hours. Email me the bug and how to reproduce it.