If your WordPress site keeps getting hacked, cleaned, and then hacked again a fortnight later, the problem is not that you have been unlucky twice. It is that the first clean-up never closed the door, and everything since has been the same break-in playing out on repeat.
That cycle is exhausting and expensive, and it is the reason so many business owners end up walking away from WordPress altogether. What follows is what is actually happening underneath, what it does to your position in Google while it runs, and how to stop it permanently rather than buying yourself another three weeks.
Why Does My WordPress Site Keep Getting Hacked After I Clean It?
Because a clean-up and a lock change are two different jobs, and most people only pay for the first one.
When someone compromises a WordPress site, they rarely stop at putting content on it. They leave themselves a way back, normally a small file dropped somewhere unremarkable, a scheduled task, or an extra administrator account with a plausible name. That way back is the actual asset. The spam pages are just what it gets used for.
So when you restore last month’s backup, you replace the pages and nothing else. If the compromise predates that backup, and it usually does by weeks or months, the backup contains the way back as well. The site looks fine for a few days while nobody is paying attention, then the pages reappear and you are back where you started, having lost a day and paid for the privilege.
This is why the recurrence matters more than the hack. A site that was compromised once and properly repaired stays repaired. A site that keeps producing spam pages is telling you the repair never happened, no matter how many times the content has been rolled back.
What Do Hacked WordPress Pages Actually Look Like?
They are usually not subtle once you know the shape of them, which is why so many owners are shocked at how long it had been running.
On a site I rebuilt after a long-running compromise, the injected pages fell into two consistent patterns. The first was a bare number followed by .html sitting at the root of the site, along the lines of /34304203.html. The second was a folder of five random letters containing a similar numeric file, along the lines of /weoht/k737662.html. Between them, those two shapes accounted for 795 of the 816 dead URLs still showing in Search Console months after the site had been replaced.
The content on them is almost always the same commercial categories. Online casinos, sports betting, crypto trading, pharmacy products, replica goods. What surprises people is the languages, because a site serving customers in one town will suddenly be publishing in Russian, Turkish, Polish, Hindi, Korean and a dozen others. Your domain is being borrowed to rank someone else’s pages in markets you have never sold into.
The pages are also frequently hidden from you specifically. Many injections serve the spam only to search engine crawlers, or only to visitors arriving from a search result, so the owner logging in directly sees a perfectly normal website. That is why the two checks below matter more than simply looking at your own site.
How Do I Check Whether My Site Has Been Hacked?
Two checks, neither of them technical, and both take about ten seconds.
Search Google for site:yourdomain.com, typed exactly like that with no space after the colon. That returns what Google currently holds for your domain and nothing else. If your own pages are sitting alongside betting pages, or the results run to page after page when your site has fifteen pages on it, you have your answer.
Then open your own sitemap, normally at yourdomain.com/sitemap_index.xml. A sitemap is the list your site publishes for search engines, so it hides nothing. Follow the post sitemap links and count what is in them. A small business site with a handful of blog posts should not have a sitemap running to thousands of entries, and if it does, every one of those entries is a page your website is currently publishing under your name.
Worth doing both, because they answer different questions. The sitemap tells you what your site is publishing right now. The Google search tells you how much of it the outside world can already see.
Why Forwarding Your Domain to Social Media Makes It Worse
This is the part almost nobody warns about, and it does more lasting damage than the malware.
Faced with a site that keeps breaking, a lot of owners do something that feels responsible. They point the domain at their Facebook or Instagram page so that customers still land somewhere useful while it gets sorted. It keeps a presence up, it stops people seeing casino pages, and it buys time.
Google reads that as a permanent move. A domain-wide redirect to another destination is the standard signal that a website has relocated, so the correct response is to drop the original pages and hand whatever they had earned to the new destination. Which is exactly what happens.
On the site I rebuilt, the domain sat forwarded to a social profile while the mess was dealt with. The result was fourteen months in which the domain earned no search impressions at all. Not reduced, not down by half. Zero. Every page that had ranked was gone, and the rebuild afterwards started from nothing rather than from a damaged position, which is a materially harder place to come back from.
If a site has to come down, take it down. A holding page on your own domain, a maintenance notice, even a plain page with your phone number on it, all of these are safe. Sending the domain somewhere else is the one option that turns a recoverable problem into a much longer one.
Should I Clean a Hacked WordPress Site or Rebuild It?
Search this question and the answer comes back near-unanimous, which is that you should restore or clean first and treat rebuilding as a last resort. Before taking that at face value, look at who writes it. The top results are security plugin vendors, WordPress hosting companies and page builder products. All of them sell something that only has value while you stay on WordPress. None of them earns anything from telling you to leave.
That does not make the advice wrong, and there is a real case for cleaning. If the compromise is recent, the site is otherwise well maintained, the plugins and theme are current, you know which one let them in, and you have a backup from before it happened, then cleaning is the sensible, cheaper route. Fix the hole, remove the files, move on.
The case falls apart when those conditions do not hold, which is the situation most people are in by the time they go looking for help. A site running a theme and plugins that have not been updated in years, compromised for months before anyone noticed, with no backup that predates it, is not a cleaning job. You can pay for the malware removal and still not be certain it is all gone, and at the end of it you own the same ageing site, with the same weekly maintenance obligation that produced the problem, waiting to happen again.
That is paying twice. Once to rescue something, and again later to replace the thing you rescued.
How Long Does It Take to Recover in Google?
Longer than anyone tells you, and the shape of the recovery is misleading in a way that causes real anxiety.
On the rebuilt site, the count of dead spam URLs in Search Console peaked at roughly 27,000. Taking the compromised site offline removed about 81% of them within three days, which is the single biggest thing you can do and it costs nothing. The rebuild went live shortly after, and from there the remainder fell from around 2,700 to just over 800 across the following nine weeks. Two months on from a complete platform rebuild, several hundred injected URLs were still listed.
Here is the part that catches people out. That figure does not decline smoothly. It sits at exactly the same number for eight days, fourteen days, eighteen days, then drops in a single step. Search Console updates the report in batches, so a fortnight of no movement is completely normal and means nothing has gone wrong. Owners watching it daily conclude the fix failed and start changing things, which is the worst thing to do mid-recovery.
Two things speed it up. Make sure the dead URLs return a “410 Gone” response rather than a standard “404 Not Found”, because 410 tells Google the page is permanently finished and will not be back, and it drops out faster. Second, leave it alone. Google recrawls those URLs on a decaying schedule, dropping from hundreds a month to a handful, and the tail is measured in months no matter what you do.
Can a Website Be Built So This Cannot Happen Again?
Not perfectly, and anyone who says otherwise is selling something. Your hosting login, your domain registrar and your email account all still exist and still need protecting.
What can be removed entirely is this specific category of attack. Every injection described above needs the same three things to work, which are a database to write pages into, executable code running on the server, and a login page facing the internet. A site built as static files has none of them. There is no database to insert a casino page into, no plugin to exploit, and no admin screen to break into. The attack does not fail, it has nothing to attempt.
That is the difference between hardening WordPress and moving away from it. Hardening reduces the odds while leaving the mechanism intact, and it commits you to updating a dozen separate add-ons every week forever. Removing the mechanism ends the category. It also happens to make the site considerably faster, because most of what makes a WordPress site slow is the same machinery that makes it vulnerable.
The trade-off is honest and worth stating. A static site does not come with the familiar dashboard, so updating content works differently. Either you get a small purpose-built editor for the parts that genuinely change, or you send the changes to whoever built it. For most small business sites, where the opening hours and the phone number are the only things that move in a year, that is not much of a loss against never thinking about this again.
If you are weighing that up for an Irish business, the practical questions are covered in how to choose a web designer in Ireland, and the reasons a site fails to rank are worth reading alongside it in why your Irish website isn’t ranking.
The Short Version
A WordPress site keeps getting hacked because the clean-up addressed the symptom and left the cause in place. Restoring a backup replaces your pages while preserving the way back in, so the spam returns on a loop until someone finds and closes the entry point. Meanwhile the damage in Google compounds, and the instinct to forward the domain somewhere safer quietly makes it far worse than the hack ever did.
Cleaning is the right call on a recent compromise of a well-maintained site with a clean backup. On an ageing site that has been open for months, it is money spent rescuing something you will need to replace anyway. Rebuilding on a platform with no database, no plugins and no login page does not just fix the current break-in, it retires the whole category, which is the only outcome that actually ends the cycle.
Want a straight answer about your own ranking?
Get a straight answer