Real-World Web Security &
Malware Remediation
We don’t just run scanners. We reverse-engineer complex malware, secure compromised servers, and architect resilient AI pipelines based on years of hands-on, frontline experience.
Our Service Pillars
Deep manual remediation, secure AI architecture, and server hardening — for businesses that cannot afford avoidable risk.
Deep Malware Remediation
Beyond automated tools. Manual extraction of XOR-obfuscated backdoors, SEO spam, and persistent database payloads (WordPress & Magento).
Secure AI Architecture
Building production-ready, latency-optimized AI pipelines (Twilio Voice + OpenAI) with security and state management built-in from day one.
Post-Hack Hardening & Recovery
Server-level lockdown, vulnerability patching, and infrastructure recovery to ensure you never get hacked the same way twice.
Custom Secure Development
Developing bespoke, secure PHP/Laravel and Node.js solutions when off-the-shelf plugins introduce too much risk.
About Us
Juan Pablo González Camera
Security Specialist & Systems Architect
At SolidScripts.io, we do not just deliver code; we deliver the peace of mind that comes from working with someone who has been in the trenches. Our agency is founded and led by Juan Pablo González Camera, whose track record of remediating hundreds of compromised servers is the foundation of our quality promise.
Frontline Expertise, Not Certification Theater
While many rely on theoretical certifications, my expertise was forged on the frontlines. Having manually remediated hundreds of complex server compromises for high-volume agencies, I bring practical, battle-tested security practices to every project—whether it is cleaning a hacked site or architecting a new AI platform.
- Top Rated Plus on Upwork: We belong to the select top 3% of Upwork professionals, with proven track records in complex remediation and secure AI architecture.
- 100% Job Success Score: Every project we have touched has resulted in a satisfied client. This perfect metric reflects our obsession with detail.
- Real-World Track Record: In-memory execution backdoors, XOR-obfuscated database payloads, 5-vector combined infections — we have seen them all and cleaned them all.
My goal with SolidScripts.io is to democratize access to enterprise-level security and architecture, allowing businesses of all sizes to compete with solid, secure and scalable systems.
— Juan Pablo González Camera, Founder
Real-World Case Studies
Anonymized but real. Concrete examples of complex infections that commercial scanners missed — and how we eliminated them.
Case 1: Memory-Only Backdoor (DECKPHP Variant)
Client: E-commerce WordPress site (United States, 2026)
What we found: Three PHP files with a DEFLATE-compressed hexadecimal payload executed entirely in memory. Invisible to 5 commercial antivirus engines (ClamAV, BitDefender, AVG, ESET, Maldet).
What we did: Manual reverse-engineering of the compressed payload. Complete removal, audit of all modified files, and hardening of the upload vector used for initial access.
✅ Result: Site fully clean. Zero recurrence in 90-day follow-up.
Case 2: DB-Resident XOR Backdoor via Legitimate Plugin
Client: Service business WordPress site (United States, 2026)
What we found: A 17,000-character PHP injection directly into wp_options using WPCode. Hex XOR obfuscation bypassed every filesystem-based scanner. Detected only because 800+ DNS error log entries filled the database.
What we did: Identified the “Untitled Snippet” in WPCode as the infection vector. Removed the malicious payload, purged 800+ error logs, uninstalled the plugin. Full database audit.
✅ Result: Site clean. Database size reduced by 40%.
Case 3: Multi-Layer Persistent Infection with Fake Plugin
Client: Media and content WordPress site (United Kingdom, 2026)
What we found: Combined 5-vector attack: cookie-triggered PHP backdoors in themes, DECKPHP in root, fake SEO spam plugin, eval($_REQUEST) in single.php, and a Perl script for server-side command execution. Site blacklisted by Google.
What we did: Systematic removal in order of persistence risk. Surgically removed eval line, deleted fake plugin folder, removed DECKPHP files, wiped Perl scripts, cleaned all 6 theme backdoors.
✅ Result: Fully remediated. Google Safe Browsing flag cleared within 48 hours.
Case 4: AI Outbound Intelligence Platform (Secure Architecture)
Client: SaaS startup (United States, 2026) — Role: Founding Engineer
Challenge: Build a production-grade 3-layer AI outbound calling platform (Calling Engine → Speech Processing → Reasoning Engine) with security and scalability built in from day one — in 30 days.
What we built: Fully containerized backend with Twilio AMD, low-latency Deepgram transcription, and OpenAI reasoning layer returning consistent JSON. Redis for real-time call state management. Zero hardcoded credentials.
✅ Result: Functional MVP on day 28. First paying customers onboarded in week 5.
Security Tooling & Standards
Technology stack and security practices we apply on every remediation and architecture engagement.
Remediation Toolbox
- Manual Payload Analysis: Hex decoding, DEFLATE, XOR, nested base64 disassembly.
- Filesystem Audit: Checksum comparisons, detection of new and modified files.
- Deep Database Inspection: Scanning wp_options, wp_postmeta, and plugin tables.
- Log Forensics: Apache/Nginx access logs, PHP error logs, command history review.
- Multi-Scanner Verification: Cross-validation post-remediation with multiple engines.
- Server-Side Hardening: PHP.ini, .htaccess, file permissions, WAF configuration.
Secure Architecture Standards
- Zero Trust by Default: Least-privilege principle on every external connection.
- Secrets Management: Environment injection, zero hardcoded credentials anywhere.
- Immutable Containers: Docker with verified, regularly-updated base images.
- Strict Input Validation: Sanitization, prepared statements, output escaping.
- Monitoring & Alerts: Structured logging, real-time anomaly alerting.
- Secure CI/CD: Static analysis (SAST), dependency scanning, and container scans.
What Our Clients Say
Verified reviews from real projects on Upwork.
Security FAQ
Short answers to the most common questions about malware remediation and security.
My site looks normal. Do I still need an audit?
Absolutely yes. Many modern backdoors (like the DECKPHP variants we have analyzed) are silent by design. A site can be compromised for months with zero visible symptoms. We recommend quarterly reviews for high-traffic sites.
Why not just use a security plugin like Wordfence?
Wordfence and similar tools are excellent as a first layer, but they are signature-based. Custom-obfuscated payloads (hex XOR, in-memory DEFLATE, database payloads) do not exist in any signature database. Only manual human inspection detects and removes them.
What if the infection comes back after cleanup?
Our remediation explicitly includes identifying and closing the initial access vector. Without closing that hole, any cleanup is temporary. We include 30 days of post-remediation support to guarantee everything stays clean.
How long does a full remediation take?
For a standard 1–2 vector infection, typically 24–48 hours. Severe multi-vector cases with Google blacklisting can take 3–5 business days, including Google Safe Browsing review time. Urgent cases are prioritized.
Do you handle confidentiality and NDAs?
Completely. We routinely work under NDAs. Server access is granted under a minimum-necessity basis, and sensitive data is handled according to enterprise-grade security practices. We never share client details.
Can you work with my internal team or hosting?
Yes. We integrate with internal teams as senior support for remediation, coordinating through SSH/SFTP access, hosting panels, or ticketing systems. If we engage with your existing provider, we request temporary access and document every change.
Request a Security Audit or Remediation
Tell us briefly about your compromised site, your secure AI project, or your hardening needs. We respond in less than 24 hours with a concrete action plan.
Tell us about your case
Briefly describe the situation: hacked site, preventive audit needed, or secure AI architecture project.
If you prefer to email directly: support@solidscripts.io. For remediation emergencies, mention “URGENT” in the subject line.
Book a Strategic Consultation
30-45 minutes to review the current state of your systems, identifiable security risks, and secure architecture opportunities for your business.
Backed by a 100% Success Rate on Upwork
Top Rated Plus
Top 3% of professionals on Upwork
100% Job Success
Every project delivered successfully
5.0 Rating
Perfect client satisfaction score