[MORSALIN]
Service 10.3Updated September 2026New service

Hacked Laravel or custom app cleanup and hardening

If your Laravel or custom web app has been compromised, I contain it, rebuild it on a clean server from known-good code, rotate every secret and harden the setup. This is a new service: recovery, not forensics or legal work. From $520 ($400 founding), usually 3–8 working days. Email me what you’ve seen.

See a sample report, proposal and weekly update
Price
from $520
Founding
from $400
Timeline
3–4 working days
Format
Fixed scope, fixed price
Hours
US Eastern Time, async
01Fit

Who this is for.

A good fit if

  • Laravel and custom PHP, Go or Python apps showing signs of compromise
  • Teams with a leaked .env, APP_KEY or cloud key
  • Founders who need a clean, hardened rebuild quickly

Common triggers

  • Unknown files, admin users or redirects appear
  • Your host suspends the server for sending spam or attacking others
  • A secret was committed to a public repo

Not a fit if

  • It’s a WordPress site (not offered here)
  • You need forensic investigation, legal advice or breach notification (your counsel handles that)
  • You need a guarantee that it can never happen again
02Scope

What I do, and what you get.

What I do

  • Contain: put the app in maintenance mode or cut traffic, and revoke obvious attacker access
  • Keep a disk snapshot for your records before I change anything (I don’t analyze it)
  • Rebuild on a fresh server from known-good code, not by cleaning the infected one
  • Restore data from a backup you choose, and check it for obvious injected content
  • Rotate secrets: APP_KEY, database passwords, API keys, SSH keys and cloud keys the app uses
  • Sign out all users and force admin password resets
  • Harden: updates, firewall, file permissions, debug off, 2FA on admin access
  • Patch the likely entry point when I can see it, and tell you when I can’t

What you get

  • The app running on a clean, hardened server
  • A list of every secret rotated and any you still need to rotate
  • A plain summary of what I saw, what I did and what I couldn’t confirm
  • Handover notes and a hardening checklist

Your part

  • Decisions on notifying users or authorities, with your own counsel
  • Access to hosting, DNS, repo and third-party dashboards (payments, mail, storage)
  • Rotating secrets only you can (registrar, bank, personal accounts)
  • Choosing the backup date to restore from

Included

  • Containment and a preserved snapshot
  • Clean rebuild and data restore
  • Secret rotation and hardening
  • Summary and checklist

Not included

  • Forensic investigation or evidence analysis
  • Legal advice, breach notification or regulator contact
  • Guarantee against reinfection
  • WordPress malware cleanup
03Plans & price

Fixed prices, agreed before work starts.

Starter
$520
Founding price $400
3–4 working days

Contain, clean, patch, rotate credentials

Standard
$910
Founding price $700
5–6 working days

Rebuild on a fresh server, rotate, harden

Plus
$1,430
Founding price $1,100
7–8 working days

Rebuild of an app/database split setup

Build your scope

1 · Plan
2 · After handover (optional)
Your scope
$520
Timeline
3–4 working days
Payment
Paid in full before work starts
Earliest start
Oct 5
Not a commitment. I confirm the exact price in a written proposal.

Founding price: 3 of 7 spots left, until Mar 31, 2027 — one-off work, in return for a testimonial. How it works

Prices are in USD, paid by bank transfer against an invoice. Work under $1,000 is paid upfront; larger work is 50% to start and 50% before handover, or monthly milestones. How working together works

Variations

Single server, patch in place (Starter)
For small, well-understood incidents where a rebuild isn’t needed.
Fresh server rebuild (Standard)
The default.
App and database on separate servers (Plus)
Both nodes rebuilt and credentials rotated between them.
04Process

How it runs.

  1. 01

    Tell me what you saw

    Email what you’ve seen and when; if it’s live and urgent, book an Urgent Fix to contain it today.

  2. 02

    Plan and price

    I reply within one US business day with a plan, a fixed price and a start date.

  3. 03

    Invoice and access

    You pay the prepaid invoice (50% upfront above $1,000), then grant access.

  4. 04

    Contain and rebuild

    I contain, snapshot, rebuild, rotate secrets and harden.

  5. 05

    Summary and handover

    You get the summary, the rotation list and the handover notes.

05Proof

A new service, done openly.

I have not delivered this exact service for a client before, so there is no case study to point to yet. The approach above is built from parts I have shipped in production — see the case studies — and the fixed price and written scope protect you while it is new.

06FAQ

Questions buyers ask.

Can you tell us how they got in?

Sometimes the entry point is obvious and I’ll say so. Finding it for sure is forensics, which I don’t do.

Do we have to tell our users?

Ask your lawyer. I’ll give them my summary.

Will it happen again?

I close what I find and harden the server, but I can’t guarantee it.

Why rebuild instead of cleaning?

On a compromised server you can’t be sure you found everything.

Can you start today?

Containment can happen today through an Urgent Fix; the rebuild follows.

07Start

Ask about Hacked App Cleanup.

Tell me what you have and where it hurts. I reply within one US business day with either a fixed quote or the entry step that makes a fixed quote possible.

Helpful to include

  • Stack and versions
  • What you noticed and when
  • Hosting and number of servers
  • Last known-good backup
  • Who has access
  • Whether counsel is involved
Reply within one US business day. No calls needed.

Prefer your own email app? Write to [email protected]. Your details stay with me, never on a list. An AI model drafts a private summary of your message for me.

More in Troubleshooting & Bug Fixing