Part of the Website Security Checklist for SEO series. If you're here mid-crisis, skip straight to the recovery process.
Signs Your Site Has Been Hacked
Some infections announce themselves. Most don't — they sit quietly siphoning crawl budget and link equity into spam pages while you're none the wiser. Watch for:
- A "Security Issues" notice in Google Search Console
- Sudden, unexplained traffic drops with no corresponding algorithm update
- Unfamiliar pages appearing in Search Console's indexed-pages report (often pharmaceutical, gambling, or counterfeit-goods content)
- Search results showing your domain with title/description text you never wrote
- A red "Dangerous site" interstitial when you visit your own site in Chrome
- Antivirus or hosting provider warnings about outbound traffic from your server
The Recovery Process
Confirm the Infection
Check Search Console's Security Issues tab and run your domain through the Google Safe Browsing Transparency Report. Cross-check with an external scanner like Sucuri SiteCheck — don't rely on a single source.
Isolate the Site
Take the site offline or put it in maintenance mode if the infection is actively serving malware to visitors. This limits damage while you work and protects your users.
Clean the Malware
Restore from a known-clean backup if you have one — it's faster and more reliable than manual removal. If you don't, use a malware removal tool (Wordfence, Sucuri) or a specialist, and check every admin account for unauthorized additions.
Patch the Vulnerability
Cleaning without patching just invites reinfection. Update the CMS core, every theme, and every plugin. Change all passwords and API keys. If you can identify the specific entry point, close it explicitly.
Request a Google Review
In Search Console's Security Issues tab, submit a review request once you're confident the site is fully clean. Be specific in your notes about what was found and fixed — vague submissions take longer to process.
Monitor Recovery
Once the warning lifts, watch Search Console's coverage and performance reports weekly. Re-indexing and ranking recovery happen gradually, not instantly.
Don't request a review before you're sure it's clean. A failed review delays the next attempt and signals to Google that the issue wasn't properly resolved. Verify thoroughly first.
How Long Recovery Takes
| Stage | Typical Timeframe |
|---|---|
| Google detects the infection | 1–7 days after compromise |
| Cleanup & vulnerability patch | Hours to a few days, depending on severity |
| Google review response | Several days to a few weeks |
| Full ranking recovery | 60–180 days post-review |
The variable that matters most isn't the hack itself — it's how quickly and thoroughly you respond. Sites that clean up fast and patch properly recover faster than sites that linger in a half-fixed state.
Preventing the Next One
Recovery is the expensive way to learn this lesson. The cheap way is the routine covered in the Website Security Checklist for SEO — keeping software updated, backing up regularly, and checking Search Console weekly. If your stack is WordPress specifically, the hardening steps in WordPress Security Basics close most of the doors attackers actually use.
Need Help with SEO, AEO or GEO?
Let's build a visibility strategy that works across Google, AI answers and generative search.
Start a Free Consultation
