WordPress powers more than 40% of the web, which makes WordPress security one of the most searched topics for anyone who runs a business website. The good news: WordPress core itself is well maintained and rarely the weak point. Almost every hacked site we clean at MIVAQ was compromised through something preventable, such as an outdated plugin, a reused password, a nulled theme or a cheap shared server with no isolation.
This guide is for business owners, marketers and freelancers who manage a WordPress site and want one place that explains everything: how sites actually get hacked, how to tell if yours is infected, how to remove malware step by step, how to get back into Google after a hack, and how to harden your site so it does not happen again. It is written from real cleanup work, not theory, and it is up to date for 2026.
Key takeaways
- Over 90% of WordPress vulnerabilities are found in plugins and themes, not WordPress core. Updates and fewer plugins prevent most hacks.
- Many infections are invisible to logged-in admins. Check Google results, Search Console and your site from a phone and an incognito window.
- A proper cleanup removes the backdoor and closes the entry point. Deleting the visible spam alone means the hacker returns within days.
- After cleaning, you must change every password and secret key, then ask Google to review the site and remove spam URLs.
- Off-site backups, two-factor authentication, a firewall and monthly maintenance protect a typical business site for a small fraction of what a hack costs.
Table of contents
- Is WordPress secure? How WordPress sites really get hacked
- How to tell if your WordPress site has been hacked
- What to do in the first hour after a hack
- How to remove malware from WordPress: step by step
- Common WordPress malware types and how to fix them
- How to recover your Google rankings after a hack
- How to secure a WordPress site: hardening essentials
- Best WordPress security plugins compared
- WordPress backups: your last line of defence
- WooCommerce security: protecting an online store
- How much do WordPress security and malware removal cost?
- DIY vs hiring a WordPress malware removal professional
- WordPress security checklist: launch and monthly
- More complete guides
- Frequently asked questions
Is WordPress secure? How WordPress sites really get hacked
Yes, WordPress core is secure when it is kept up to date. It has a dedicated security team, a public disclosure process, and automatic background updates for minor security releases that have been switched on by default since version 3.7. Serious vulnerabilities in core are rare and are usually patched before most people hear about them.
The problem is everything around core. A typical business site runs 15 to 40 plugins, a theme, sometimes a page builder, all written by different developers with very different standards. Independent security researchers such as Patchstack and Wordfence publish thousands of new WordPress vulnerabilities every year, and consistently report that well over 90% of them are in plugins, a small share in themes and only a handful in core.
The real entry points
In our cleanup work, the cause of a hack nearly always falls into one of these groups:
- Outdated plugins and themes. Once a vulnerability is published, automated bots scan millions of sites for the affected version within hours. A site that waits weeks to update is an easy target.
- Abandoned or nulled software. Plugins that are no longer maintained never receive fixes, and pirated (nulled) premium themes and plugins often ship with a backdoor already installed.
- Weak or reused passwords. Credential-stuffing bots try leaked email and password combinations against wp-login.php all day, every day. Without two-factor authentication, one reused password is enough.
- Poor hosting. Cheap shared hosting without account isolation lets one infected site spread to neighbours, and outdated PHP versions lose security fixes.
- Too many admin accounts. Old developers, agencies and former staff who still have administrator access multiply the risk.
- Insecure file uploads and forms. Contact form, membership and file-upload plugins with flaws are a frequent route for uploading malicious PHP files.
Why would anyone hack a small business website?
Most attacks are not personal. They are automated, and your site is valuable for its server and its Google reputation. Hacked sites are used to host spam pages (the Japanese keyword hack and pharma spam), redirect visitors to scams, send spam email, mine cryptocurrency, host phishing pages and, on WooCommerce stores, steal card details at checkout. A small, trusted local business site with a clean history is exactly what spammers want to borrow.
For the official baseline, the WordPress project maintains a detailed hardening guide on developer.wordpress.org. The rest of this guide turns that baseline, and what we see in real infections, into a practical plan.
How to tell if your WordPress site has been hacked
Modern malware is designed to stay hidden. Many infections only show spam or redirects to visitors coming from Google, to mobile users, or to people who are not logged in. That is why site owners are often the last to know. These are the warning signs we see most often:
- Google results for your site show strange titles in Japanese, Chinese or about pills, replica goods, casinos or loans.
- A “This site may be hacked” or “Deceptive site ahead” warning appears in Google or Chrome.
- Search Console sends a Security issues or Manual actions alert, or the Pages report suddenly shows thousands of new URLs.
- Visitors (often on mobile) are redirected to other websites, but you cannot reproduce it while logged in.
- New administrator users you did not create, or your own admin account no longer works.
- Unknown files in the site root or wp-content/uploads, especially PHP files where only images should be.
- Your host suspends the account or warns about outgoing spam email or high CPU usage.
- The site becomes very slow, or customers report fake orders, card fraud or strange pop-ups.
- Your security plugin was deactivated without your knowledge.
Quick checks you can do in 10 minutes
- Search Google for site:yourdomain.com and scroll through several pages, looking for titles or URLs you never created.
- Open your site in a private window on your phone, both directly and by clicking your result in Google, to catch referrer-based redirects.
- In Google Search Console, open Security and manual actions, then the Pages report, and look for a sudden spike in indexed URLs.
- In WordPress, go to Users and filter by Administrator. Remove anyone you do not recognise only after taking a backup for evidence.
- Run a free external scan (for example Sucuri SiteCheck) and check your domain in Google Safe Browsing site status.
A clean external scan does not prove the site is clean, because scanners only see what the server shows them. If you see any of the signs above, treat the site as compromised. Read next: our detailed list of 12 signs your WordPress site has been hacked and what to do in the first hour.
What to do in the first hour after a hack
Panic leads to the two most common mistakes: deleting everything that looks odd (which destroys the evidence you need to find the entry point) and restoring an old backup without fixing anything (which brings the hacker straight back). Work through these steps calmly, in order.
- Do not delete the site or reinstall blindly. You need the infected files to work out how the attacker got in.
- Take a full backup of the infected site. Download all files and a database export, and label it clearly as infected. This is your evidence and your safety net.
- Change the most important passwords from a clean device. Start with your hosting control panel, SFTP/SSH, the database user and your WordPress administrator accounts. If your own computer may be infected, use another device.
- Contain the damage. If visitors are being redirected or card details are at risk, put the site into maintenance mode or ask your host to restrict access. For a WooCommerce store, temporarily disable checkout.
- Tell your host. Good hosts can share server logs, scan the account and confirm whether other sites on the same account are affected.
- Record what you see. Note dates, strange URLs, new users and screenshots of warnings. Timelines help match infected files to log entries.
- Check whether you must notify anyone. If personal or payment data may have been exposed, data-protection law (for example the GDPR in the UK and EU) can require you to report it within strict deadlines. Speak to your payment provider if you run a shop.
How to remove malware from WordPress: step by step
A real cleanup has three goals: remove every malicious file and database entry, close the hole that let the attacker in, and make sure no backdoor remains. Skipping any of the three is why so many sites get reinfected a week later. This is the process we follow on client sites.
- Work on a copy where possible. Clone the site to a staging area or a local environment so you can investigate without breaking the live site further.
- Replace WordPress core with a fresh copy. Download WordPress from wordpress.org and replace the wp-admin and wp-includes folders entirely, plus the root files except wp-config.php. With WP-CLI, wp core verify-checksums lists every core file that differs from the official release, as described in the WP-CLI documentation.
- Reinstall every plugin and theme from the official source. Delete each plugin folder and reinstall a fresh copy from wordpress.org or the vendor. wp plugin verify-checksums –all highlights modified files for plugins hosted on wordpress.org. Remove anything you no longer use, and remove any nulled software completely.
- Inspect wp-config.php and the root folder by hand. Look for code at the very top or bottom of wp-config.php, unknown PHP files in the root, and modified .htaccess rules that redirect search engine or mobile visitors.
- Clean wp-content/uploads. This folder should contain media, not code. Any .php file there is suspicious. Also check for unfamiliar folders inside wp-content and in mu-plugins (must-use plugins load automatically and are a favourite hiding place).
- Search for obfuscated code. Malware is usually disguised. Search remaining files for patterns commonly used to hide code, such as long base64 strings, eval combined with decoding functions, gzinflate, str_rot13, and files with recent modification dates that do not match your updates. Not every match is malicious, so compare against the original plugin source before deleting.
- Clean the database. Check the wp_users table for unknown accounts, wp_options for injected scripts in options such as siteurl, home and widget settings, and wp_posts for hidden links, script tags and spam pages. Japanese and pharma hacks often create thousands of posts or inject content into existing ones.
- Remove rogue users and reset all credentials. Delete unknown administrators, then reset passwords for every user with Editor role or higher, the database password (update it in wp-config.php), hosting, SFTP and email accounts.
- Replace the security keys and salts. Generate new keys and salts for wp-config.php. This logs everyone out and invalidates any stolen login cookies.
- Find and fix the entry point. Review access logs around the infection date for requests to vulnerable plugins, upload endpoints or wp-login.php. Update or remove the vulnerable component. Without this step, the cleanup is temporary.
- Harden and monitor. Add a firewall, two-factor authentication, file-change monitoring and uptime checks, then rescan after 24 hours and again after a week.
Restoring a backup is only a shortcut if you know the backup was made before the infection and you also fix the entry point. Many backups already contain the backdoor because the hacker got in weeks before anything visible happened.
Is a security plugin scan enough?
Plugin scanners are useful for finding known malware signatures, but they run inside the infected site, can be disabled by the malware, and often miss database injections and custom backdoors. Use them as one tool alongside manual review, checksum verification and log analysis. Read next: our real-world walk-through of how we cleaned a hacked WooCommerce store and stopped fake orders.
Common WordPress malware types and how to fix them
Knowing the type of infection tells you where to look and what damage to repair afterwards. These are the families we meet most often on business sites.
| Malware type | What you notice | Where it usually hides | Extra recovery work |
|---|---|---|---|
| Japanese keyword hack | Thousands of Japanese pages in Google under your domain | Generated PHP files, .htaccess rules, sometimes a fake sitemap and a hijacked Search Console owner | Remove spam URLs from Google, remove unknown Search Console owners |
| Pharma and SEO spam | Pill, casino or replica-goods titles in search results only | Database content, theme functions.php, cloaking code that only shows spam to Googlebot | Clean posts and options, request review in Search Console |
| Malicious redirects | Mobile or Google visitors sent to scam sites | .htaccess, injected JavaScript in options or posts, header.php, fake plugins | Clear caches and CDN, check Safe Browsing status |
| Backdoors and fake admin users | Reinfection after cleanup, unknown administrators | uploads, mu-plugins, files named to look like core, wp_users table | Reset all credentials and salts, find entry point |
| Card skimmers (WooCommerce) | Customers report card fraud, fake orders | Injected JavaScript on checkout, modified payment plugin files, database options | Inform payment provider, review legal reporting duties |
| Spam mailers and phishing | Host suspends account for spam, Google phishing warning | PHP mailer scripts and phishing kits in random folders | Check email blacklists, delist IP and domain |
| Cryptominers | Very high CPU, slow site | Injected scripts or server processes | Ask host to check server-level processes |
The Japanese keyword hack
This is one of the most damaging infections for SEO, because it creates thousands of auto-generated Japanese pages that Google indexes under your brand. Attackers frequently verify themselves as an owner in your Search Console so they can submit their own sitemaps. Read next: how to find, remove and recover from the Japanese keyword hack.
Redirect and cloaking hacks
Cloaking malware checks who is visiting. Logged-in admins and direct visitors see the normal site, while Googlebot sees spam and searchers get redirected. Always test as a logged-out mobile user arriving from Google, and use the URL Inspection tool in Search Console to see the page exactly as Google fetches it.
How to recover your Google rankings after a hack
Cleaning the server is only half the job. Google may still show your site with a warning, keep thousands of spam URLs in its index, or have lowered trust in your pages. Recovery is usually possible, and most sites return to previous rankings once the spam is gone and Google recrawls, but you have to guide Google through it.
- Secure Search Console. Open Settings, then Users and permissions, and remove any owner or user you do not recognise. Also delete any verification files or meta tags they added, otherwise they can re-verify.
- Make spam URLs return 404 or 410. Once the malicious files and database entries are removed, the spam URLs should return a 404 (not found) or 410 (gone) status. Do not redirect them to your homepage, as that can be treated as a soft 404 and slows clean-up.
- Submit a clean sitemap. Remove any sitemaps the attacker submitted and resubmit your genuine XML sitemap so Google recrawls real pages first.
- Use the Removals tool for urgent cases. The Removals tool hides URLs from search results for about six months while Google drops them permanently. Use prefix removals for spam folders where possible.
- Request a review. If the Security issues report in Search Console lists problems, click Request review and explain what you removed and how you closed the vulnerability. Reviews for hacked content typically take from a few days to a couple of weeks.
- Monitor the Pages report. Watch the number of indexed pages fall back towards normal over the following weeks, and inspect key pages with the URL Inspection tool.
Read next: our step-by-step guide on removing hacked spam URLs from Google after a website hack. If your genuine pages also dropped out of the index, our complete Google indexing guide explains how to get them back, and the Page indexing report explained helps you read the numbers while Google recrawls.
How to secure a WordPress site: hardening essentials
Hardening means removing the easy wins attackers rely on. You do not need dozens of tweaks. The measures below stop the overwhelming majority of real-world attacks on business sites, roughly in order of impact.
1. Keep everything updated
Update WordPress core, plugins and themes at least weekly, or enable auto-updates for trusted, well-maintained plugins (available from Plugins in the dashboard since WordPress 5.5). Take a backup before major updates and test on staging if the site is business-critical. Remove plugins that have not been updated in over a year or have been closed on wordpress.org.
2. Use fewer, better plugins and never nulled software
Every plugin is extra code that can contain a vulnerability. Replace three small plugins with one well-supported one where possible, and buy premium plugins and themes only from the original developer. “Free” copies of premium themes from download sites are one of the most common sources of backdoors we find. If you need a design, choose from reputable sources such as our guide to the best free WordPress themes that are maintained and listed on wordpress.org.
3. Protect logins
- Use a unique, long password for every account, stored in a password manager.
- Turn on two-factor authentication (2FA) for every administrator and shop manager. Passkeys are an even stronger option where your security plugin supports them.
- Limit login attempts or rate-limit wp-login.php, ideally at the firewall.
- Disable XML-RPC if you do not use the mobile app, Jetpack or remote publishing, as it is often abused for brute-force attacks.
- Review Application Passwords under each user profile and revoke any you did not create.
4. Apply least privilege to users
Give each person the lowest role they need. Content writers should be Authors or Editors, not Administrators. Remove accounts for former staff, agencies and developers as soon as the work ends, and avoid shared logins so every action can be traced.
5. Choose secure hosting and a supported PHP version
Good hosting is a security feature. Look for account isolation, server-level malware scanning, a web application firewall, automatic daily backups stored off the server, free SSL and support that responds to security incidents. Run a currently supported PHP version (PHP 8.3 or newer is the sensible choice in 2026), because older versions no longer receive security fixes.
6. Lock down wp-config.php and file permissions
- Add define(‘DISALLOW_FILE_EDIT’, true); to wp-config.php so the built-in theme and plugin editor cannot be used to inject code if an admin account is stolen.
- Use standard permissions: 755 for folders, 644 for files and 600 or 640 for wp-config.php where your host supports it. Never use 777.
- Block PHP execution inside wp-content/uploads with a server rule, because media folders should never run code.
- Keep unique security keys and salts, and keep debug mode off on the live site.
7. Use HTTPS and security headers
Force HTTPS across the whole site and redirect HTTP to HTTPS. Then add basic security headers such as Strict-Transport-Security, X-Content-Type-Options and a Referrer-Policy. A Content-Security-Policy is powerful against injected scripts on stores, but test it carefully because it can break plugins.
8. Add a firewall and monitoring
A web application firewall (WAF) blocks known attack patterns before they reach vulnerable code. Pair it with file-change monitoring, an activity log of who changed what, and uptime monitoring so you hear about problems before your customers do. For the full 30-point list, read our WordPress security checklist: 30 steps to protect your website.
Does security slow WordPress down?
Not if it is set up sensibly. A cloud or server-level firewall usually reduces load by blocking bots, and scheduled scans can run at quiet times. Caching and security work well together; see our guide to speeding up WordPress with LiteSpeed Cache for a setup that keeps the site fast without weakening protection.
Best WordPress security plugins compared
A security plugin is not a substitute for updates and good hosting, but the right one adds a firewall, login protection, scanning and alerts. These are the established options in 2026 and what each does best. Features and pricing change, so check the vendor’s site before buying.
| Plugin or service | Main strength | Firewall type | Free version | Best for |
|---|---|---|---|---|
| Wordfence | Endpoint firewall, malware scanner, login security and 2FA | Runs on your server (application level) | Yes; free firewall rules arrive 30 days after premium | Most small business sites on decent hosting |
| Sucuri | Cloud WAF and CDN that filters traffic before it reaches the server, plus cleanup service | Cloud (DNS level) | Free plugin offers auditing and remote scanning; WAF is paid | Sites under frequent attack or with weak hosting |
| Solid Security (formerly iThemes Security) | Hardening settings, 2FA and passkeys, user security | Basic rules; virtual patching in paid plans | Yes | Owners who want easy hardening in one place |
| Patchstack | Vulnerability alerts and virtual patches for vulnerable plugins | Targeted virtual patching | Free tier with vulnerability alerts | Agencies and sites with many plugins |
| MalCare | Off-site scanning that does not load your server, one-click cleanup in paid plans | Application level | Free scanner | Owners who want simple scan and cleanup |
Use one main security plugin, not several. Overlapping firewalls and scanners conflict, slow the site and create false alarms. If your host already provides a server firewall and malware scanning, a lighter plugin focused on 2FA and activity logging may be all you need.
WordPress backups: your last line of defence
Backups do not stop a hack, but they decide how bad it gets. With a clean, recent, off-site backup, a disaster becomes an inconvenience. Without one, every page, order and customer record may have to be rebuilt by hand.
- Back up files and the database, not just one of them.
- Store copies off the server, for example in cloud storage. Backups kept on the same hosting account can be deleted or infected along with the site.
- Keep history. Hold at least 30 days of daily backups, because many infections start weeks before anyone notices.
- Match frequency to change. A brochure site can be backed up daily; a busy WooCommerce store needs more frequent database backups.
- Test restores. A backup you have never restored is a hope, not a plan. Test a restore to staging at least every quarter.
Read next: our full WordPress backup strategy that makes sure you can always recover.
WooCommerce security: protecting an online store
An online store is a bigger target than a brochure site because it handles payments and personal data. The same hardening rules apply, plus a few specific to e-commerce.
- Use hosted payment gateways. Gateways such as Stripe and PayPal that collect card details in their own secure fields keep raw card numbers off your server and reduce your PCI DSS scope. Never store card numbers in WordPress.
- Protect the checkout from injected scripts. Card skimmers work by adding JavaScript to the checkout page. File-change monitoring, a Content-Security-Policy and regular checks of the checkout page source help you catch them quickly.
- Stop card testing and fake orders. Bots use checkout forms to test stolen cards, which leads to chargebacks and gateway penalties. Add rate limiting, bot protection such as a CAPTCHA or Cloudflare Turnstile on checkout, and fraud rules in your payment gateway.
- Secure shop manager accounts. Require 2FA for every Shop Manager and Administrator, since these accounts can export customer data.
- Keep WooCommerce extensions current. Payment, subscription and checkout add-ons are high-value targets and need prompt updates.
Read next: our case study on cleaning a hacked WooCommerce store and stopping fake orders, and for growth after you are secure, our WooCommerce SEO guide.
How much do WordPress security and malware removal cost?
Prevention is far cheaper than repair. These are typical market ranges for small business sites in 2026; exact prices depend on the site’s size, the hosting and how badly it is infected.
| Item | Typical cost | Notes |
|---|---|---|
| Free security plugin, 2FA and updates done yourself | Free (your time) | Roughly 30 to 60 minutes a month if done properly |
| Premium security plugin or cloud firewall | About 100 to 300 USD per site per year | Real-time firewall rules, priority support, sometimes cleanup included |
| Quality managed WordPress hosting | About 15 to 50 USD per month for a small site | Isolation, server firewall, daily off-site backups |
| Monthly maintenance and security plan | Commonly 30 to 150 USD per month | Updates, backups, monitoring, uptime checks, reports |
| One-off malware removal | Commonly 150 to 600 USD or more | More for large stores, heavy SEO spam or repeated reinfection |
| Cost of doing nothing | Lost sales, ads, rankings and trust | Blocklisting can stop almost all organic and paid traffic until resolved |
How long does malware removal take?
A typical infection on a business site takes a few hours to one working day to clean and harden. Removing Google warnings depends on Google’s review, usually a few days, and clearing thousands of spam URLs from the index can take several weeks, even though they stop appearing much sooner with the Removals tool.
DIY vs hiring a WordPress malware removal professional
You can secure a WordPress site yourself with the steps in this guide, and many owners should handle routine updates and backups. Cleaning an active infection is different: it requires reading code, database work and log analysis, and missing a single backdoor means starting again.
| Do it yourself | Hire a professional | |
|---|---|---|
| Best for | Prevention, updates, backups, simple sites | Active infections, Google warnings, online stores, repeat hacks |
| Cost | Your time | Fixed fee, usually less than a few days of lost sales |
| Risk | Missed backdoors, broken site, reinfection | Low with a guarantee and root-cause fix |
| Speed | Days of learning and trial and error | Usually same or next day |
| Google recovery | You manage Search Console and reviews | Handled as part of the job |
How MIVAQ handles hacked WordPress sites
At MIVAQ we clean hacked WordPress and WooCommerce sites by hand, find and close the entry point, remove spam from Google, request review of security warnings and harden the site so it stays clean. You get a fixed-price quote before we start and a clear report of what was found and fixed. See our WordPress malware removal service, ongoing care through our WordPress development and maintenance service, examples in our work and real results in our case studies. If Google is still not indexing your clean pages afterwards, our Google indexing fix service takes care of it.
Book a free consultation and get a fixed-price quote:
- WhatsApp: message us on WhatsApp
- Email: hello@mivaq.com
- Form: contact MIVAQ
WordPress security checklist: launch and monthly
Use this checklist when you launch a site, after a cleanup, and as a monthly routine.
| Task | When |
|---|---|
| Unique strong passwords and 2FA for all admins and shop managers | Launch, then review quarterly |
| Remove unused plugins, themes and user accounts | Launch and monthly |
| Update core, plugins and themes (backup first) | Weekly or automatic |
| Confirm off-site backups are running and test a restore | Monthly check, quarterly restore test |
| Firewall and malware scan active, alerts going to a monitored inbox | Launch, check monthly |
| DISALLOW_FILE_EDIT set, debug off, PHP blocked in uploads | Launch |
| HTTPS forced and security headers in place | Launch |
| Supported PHP version and up-to-date server software | Twice a year |
| Search Console verified; check Security issues and Pages report | Monthly |
| Run a site:yourdomain.com search for unfamiliar pages | Monthly |
| Review administrator list and Application Passwords | Monthly |
| Uptime monitoring and activity log enabled | Launch |
For the complete 30-step version with explanations, use our printable WordPress security checklist.
More complete guides
- How to build a WordPress website for your business
- How to start a Shopify store: the complete guide
- SEO for small business: the complete guide
- Why is my website not on Google? The complete indexing guide
- Wix and Squarespace SEO: the complete guide
Frequently asked questions
Is WordPress secure enough for a business website?
Yes. WordPress core is actively maintained and secure when updated. Most hacks come from outdated plugins, nulled themes, weak passwords and poor hosting, all of which you control.
How do I know if my WordPress site has malware?
Look for strange pages in a site: search on Google, redirects on mobile, unknown admin users, PHP files in uploads, Search Console security alerts or warnings from your host. Some malware only shows to visitors from Google, so test logged out on a phone.
Can I remove malware from WordPress myself?
For simple infections, yes, by replacing core, plugins and themes with clean copies, cleaning the database, resetting all credentials and fixing the entry point. If the site keeps getting reinfected or you are not comfortable with code and databases, hire a professional.
Will restoring a backup remove the hack?
Only if the backup predates the infection, and only temporarily unless you also close the vulnerability. Many backups already contain the backdoor.
Why does my site keep getting hacked again?
Usually because a backdoor was left behind, the vulnerable plugin is still installed, or a stolen password was never changed. Reinfection almost always means the root cause was not fixed.
How do I remove the “This site may be hacked” warning from Google?
Clean the site fully, check the Security issues report in Search Console, then request a review explaining what you fixed. The label is removed once Google confirms the site is clean, which often takes a few days to a couple of weeks.
Do I really need a security plugin?
Most sites benefit from one, mainly for a firewall, 2FA and alerts. If your host provides a strong server firewall and scanning, a lighter plugin may be enough. Use one main security plugin, never several.
Will a hack hurt my SEO permanently?
Rarely, if you act quickly. Once spam URLs return 404 or 410, warnings are reviewed and real pages are recrawled, rankings usually recover. Long-running infections take longer to recover from.
How often should I update WordPress plugins?
At least weekly, and immediately for security releases. Enable automatic updates for well-maintained plugins and keep a recent backup in case an update causes problems.
WordPress security is not one big job; it is a handful of good habits done consistently: updates, strong logins with 2FA, fewer plugins, good hosting and tested off-site backups. If your site is already showing signs of a hack, act now, because the longer malware stays, the more damage it does to your rankings and your customers’ trust. If you would rather have it handled properly the first time, contact MIVAQ for a free consultation and a fixed-price cleanup quote.