Successful website recovery after hacking requires a systematic approach: urgent isolation of the resource with HTTP 503 status, verification of file structure integrity using checksums, deep database cleaning from backdoors, and correct configuration of server responses (HTTP 410/404) to remove junk URLs from the index. Attempting to blindly restore an outdated backup without auditing often returns the site to the same vulnerable state due to preserved malicious code.
Symptoms of Compromise: Express Diagnosis of WordPress Infection

A significant portion of WordPress and WooCommerce-based web resource hacks remain unnoticed by owners until traffic drops or search engine sanctions appear. Early identification of symptoms allows you to determine the attack vector and localize the damage.
| External manifestation | Type of attack / Attack vector | Implications for SEO and business |
|---|---|---|
| Red screen or blank screen «"Deceptive site ahead"» in the browser | Phishing pages, malicious redirects, blocking by Google Safe Browsing | Instant blocking of all organic and direct traffic, loss of customer trust |
| Japanese characters or pharmaceutical drug names in Google search results | SEO spam on the website (Japanese Keyword Hack / Pharma Hack) | Clogging the index with thousands of generated pages, blurring relevance and pessimizing the site |
| Redirects mobile users to third-party casino or lottery sites | File injections .htaccess, index.php or active theme scripts |
Behavioral sanctions from search engines, sharp increase in bounce rate |
| Appearance of unknown administrator accounts or suspicious cron jobs | Implementation of web shells, backdoors, compromise of authorization keys | Permanent hidden access of hackers to files and databases even after removal of visible viruses |
Diagnostic matrix: restore from backup or manual cleaning

It is important to choose the right strategy before starting work. Restoring from a backup is not always a quick solution to the problem if the copy has already been infected.
| Scenario / Conditions | Recommended action | Critical risks |
|---|---|---|
| The exact time of the intrusion is known, there is a verified "clean" backup created before the date of the incident | Restoring files and databases from backup followed by mandatory update of all components | Loss of online store orders or new articles created between the time the copy was created and the time of the breach |
| The date of the initial breach is unknown or the backups already contain malicious code | Complete replacement of the kernel and plugins with the original distributions + manual audit of the database and uploads folder | Requires more technical time, but guarantees complete removal of hidden web shells |
| Over 30% of file structure modified, system database tables corrupted | Threat isolation, system directory deletion (wp-admin, wp-includes), deep database disinfection |
High probability of re-infection without changing authorization keys and closing the vulnerability |
Emergency Protocol: 5 Steps to Site Isolation and Cleanup
Incompetent actions during the elimination of the consequences of the attack can lead to the complete loss of the database or prolonged unavailability of the resource. If you plan to perform the process yourself, follow a strict sequence of actions. We also recommend that you read the guide on steps to safely remove viruses from a website before starting to modify system files.
Step 1. Temporary isolation (Maintenance Mode)
If a resource generates malicious redirects or phishing content, it must be immediately closed to external visitors by configuring the server to return a status code. HTTP 503 (Service Unavailable). This lets Google crawlers know that the site is temporarily under maintenance, preventing the original pages from falling out of the index during the cleanup.
Step 2. Change secret keys (SALT) and reset authorization
To block sessions of attackers who could intercept the administrator cookie, generate a new set of secret keys in the configuration file wp-config.php. According to the documentation WordPress Hardening Documentation, update constants AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY and NONCE_KEY forcibly terminates all active user sessions in the system.
Step 3. Verifying the integrity of core and plugins via WP-CLI
Instead of manually searching for modified sections of PHP code, use the WP-CLI console utility to compare the checksums of local files with the reference data in the official WordPress.org repository:
# Verify the integrity of the WordPress core wp core verify-checksums # Verify the integrity of all installed plugins wp plugin verify-checksums --all
According to the documentation WP-CLI Command Reference, the utility points to the exact files where code was added or changed. Directories wp-admin and wp-includes The safest thing to do is to completely remove and replace with fresh files of the corresponding kernel version.
Step 4. Cleaning the database, backdoors, and WP-Cron
Malicious scripts often become embedded within the database or through system task schedulers, causing recurrent infections:
- Administrators' audit: perform a user list check
wp user list --role=administratorand delete all third-party profiles. - Table audit
wp_options: check the startup options (autoload = 'yes'') for the presence of obfuscated functionseval(),base64_decode(),gzinflate(). - Checking WP-Cron jobs: start
wp cron event list, to detect and remove suspicious events that periodically upload spam files from remote servers.
Step 5. Protecting the media library (uploads)
Folder wp-content/uploads is intended solely for media files and should not contain executable PHP scripts. Create the file .htaccess at the root of the directory uploads with the following content to completely prevent code execution:
deny from all
Restoring SEO positions and eliminating search spam
After the technical cleaning is completed, the key stage comes - SEO position recovery after hacking. If hackers have managed to generate thousands of pages of Japanese or pharma spam, Google's robot spends crawling budget on them, ignoring the target content of the site.
Correct server response codes: HTTP 410 vs. HTTP 404
Do not set up a 301 redirect from spam pages to the home page: this dilutes the semantics of the domain and transmits spam signals to the entire site. The optimal solution is to return a header for hacker-generated URLs HTTP 410 (Gone) or HTTP 404 (Not Found). The 410 status directly informs the search bot that the resource has been permanently removed, which significantly speeds up the cleaning of Google's index compared to standard errors.
XML Sitemap Cleanup and Spam URL Removal
Check files sitemap.xml your site. Remove any generated spam maps (hackers often create dozens of maps of the type sitemap_spam.xml) and submit a clean sitemap file through Google Search Console for accelerated reindexing of your core content.
Unblocking in Google Search Console and Google Safe Browsing
The removal of the red security alert is carried out according to official protocol Google Search Central Guide for Hacked Sites. To regain trust in the algorithms, follow these steps:
- Go to Google Search Console in the section Security & Manual Actions.
- Learn about the types of violations detected (malware, social engineering, spam). For a detailed description of the blocking rules, see Google Safe Browsing help.
- Click the button Request Review.
- In the request form, describe in detail and concisely the actions taken: removing vulnerable plugins, cleaning the database, updating SALT keys, and setting 410 codes for spam pages.
After submitting a request, Google's automated systems typically re-check within a few days, after which the Safe Browsing warning is removed and the site's search results are restored.
Protection against re-hacking: a security checklist
Eliminating the consequences without eliminating the root cause opens the way for re-infiltration. For long-term resource security, implement a basic defense complex:
- Regular update: Update your WordPress core, plugins, and themes regularly. Don't use outdated extensions that have been discontinued.
- Automatic backup: create an isolated data storage system on external cloud storage. For more information on building fault-tolerant systems, read the article about automatic site backup.
- Two-factor authentication (2FA): Set up 2FA for all accounts with administrative rights and limit the number of login attempts.
- Correct access rights: set rights
755for directories and644for files. For a filewp-config.phprestrict rights to600or640.
Frequently Asked Questions (FAQ)
How long does it take for Google to remove the "Deceptive site ahead" warning?
After submitting a verification request through Google Search Console, the site scan takes from 24 to 72 hours, provided that all malicious scripts, spam pages, and redirects are completely removed from the server.
Can I remove SEO spam using robots.txt?
No. Closing spam URLs through Disallow in the robots.txt file prohibits the bot from crawling the page, but does not remove it from the index if there are external links to it. The only correct way is to return HTTP 410 or HTTP 404 codes directly from the server.
Why does the site get infected again a few days after cleaning?
Recurrence usually indicates the presence of a leaked web shell (backdoor) in the directory uploads or database, storing compromised cron jobs, or an unpatched vulnerability in an outdated plugin/theme.
If your web resource has been hacked, has been filtered by search engines, or needs a regular security audit, contact VORONOV Solutions: we offer services emergency cleaning of websites from viruses, as well as package regular Website Care maintenance for reliable protection of your online business.

