Recovering your SEO after a hack follows an honest arc: cleanup is fast, but trust recovery is not. You can remove the malware in hours and get Google warnings lifted in days, yet full ranking recovery often takes weeks to months as Google rebuilds confidence. This step by step guide walks through containing the hack, cleaning it, closing the entry point, handling the Google side, and the recovery reality, plus how to avoid the reinfection that kills recoveries.
Step 1: Contain
Before cleaning, contain the situation so the damage stops spreading and you keep evidence. First, take a full backup of the hacked state for forensics, since this frozen copy helps you understand what was changed and can be vital if you need professional help later.
Then isolate the site: change all passwords, including hosting, admin, database, and FTP, and force all users to log out by invalidating sessions. Freeze plugin and theme changes so nothing new runs, and if possible put the site into maintenance mode while you work. Containment stops the attacker from continuing to act and gives you a stable, documented starting point for the cleanup, rather than fighting a moving target.
Step 2: Clean
With the site contained, remove the malicious code and content. There are a few routes. Manual file comparison means comparing your site’s core, theme, and plugin files against clean original copies and removing anything added or altered, which is precise but requires care and technical comfort.
Scanner tools, such as reputable malware scanner plugins or remote scanners, can find and often remove known infections, which is faster but may miss cleverly hidden code. For serious or persistent infections, professional cleanup is the sensible route, and there is a clear decision point: if the infection keeps returning, is deeply obfuscated, or reaches the server level, bring in an expert rather than fighting it alone. Whichever route, aim to remove every trace, since a single leftover backdoor lets the attacker return and undoes all your work.
Step 3: Find and close the entry
Cleaning without closing the entry point is the most common recovery failure, because reinfection kills recoveries. Attackers usually get in through a known weakness, so you must find and fix it.
The usual culprits are outdated plugins, themes, or core software with known vulnerabilities, weak or reused credentials that were guessed or stolen, and loose file permissions that let files be written. Update everything to the latest secure versions, replace all credentials with strong unique ones and add two factor authentication, and correct file permissions to safe values. Remove any unknown admin users or scheduled tasks the attacker left behind.
Only once the hole is genuinely closed is your cleanup durable, so treat this step as the most important of all, since skipping it means you will be cleaning the same hack again next week.
Step 4: The Google side
Once the site is clean and secured, handle Google so your warnings and any manual action are removed. In Google Search Console, if there is a security issue or manual action, you request a review, and the wording matters more than most guides admit.
Document what happened clearly: state that the site was hacked, describe the type of compromise you found, list the specific actions you took to clean it, name the entry point you identified and how you closed it, and confirm the site is now secure. A clear, specific, honest review request that shows you understand and fixed the problem is far more likely to succeed than a vague one. Also remove the hacked URLs, using the removals tool for urgent cases and letting cleaned pages return proper responses, and resubmit your sitemap so Google recrawls your genuine content.
This is how you formally tell Google the site is clean again.
Step 5: Ranking recovery reality
Be realistic about what returns and when. Some things come back fast: once warnings are lifted and spam URLs are gone, your clean pages stop being suppressed and can start regaining visibility within days to a couple of weeks.
Other things take longer, since Google rebuilds trust in your whole site gradually, so full ranking recovery for competitive terms often takes several weeks to a few months of the site staying clean and stable. If, after a few months of a clean, secure, well maintained site, some rankings have not returned, the damage may be partly lasting, and the path forward is simply strong ongoing SEO rather than waiting. In most cases, though, a promptly cleaned and secured site recovers well, so patience after the fix is warranted, and for the broader picture see our pillar on how hacked websites lose rankings.
The reinfection trap: monitoring for 90 days
The biggest threat to a recovery is reinfection, so monitor closely for at least 90 days after cleanup. Set up regular malware scans so any return is caught immediately, and watch your Search Console Security Issues report and search results for reappearing spam.
Keep an eye on file changes, new users, and unusual traffic, since these are early signs a hack has come back. Maintain the security fixes strictly, keeping everything updated and credentials strong, and take regular backups so you can restore quickly if needed. The first three months are when a poorly closed entry point tends to bite, so treating this period as active monitoring rather than assuming the job is done is what turns a temporary scare into a permanent fix. A recovery only counts once the site stays clean over time.
Common recovery mistakes to avoid
Several mistakes turn a recoverable hack into a drawn out disaster, so avoid them. The biggest is cleaning the site but never finding and closing the entry point, which leads straight to reinfection and a failed Google review, undoing all the work.
Another is requesting a Google review before the site is actually clean, which wastes a review cycle and extends the warning, so always confirm the site is fully clean first. Deleting your genuine pages in a panic, rather than cleaning them, throws away rankings and links you did not need to lose. Skipping the forensic backup means losing the evidence of what happened, which makes both cleanup and any professional help harder.
Restoring from an old backup without closing the vulnerability simply reintroduces the same weakness, so the hack returns. And stopping monitoring too soon, assuming the job is done after cleanup, misses the reinfection that often comes in the first weeks. Steering clear of these mistakes keeps your recovery on track, since most failed recoveries come down to a missed entry point or an impatient review request rather than the cleanup itself.
When to bring in a professional
Doing recovery yourself is realistic for many hacks, but some situations genuinely call for expert help, and recognizing them saves time and further damage. If the infection keeps returning despite your cleanup, that signals a hidden backdoor or a server level compromise you have not found, which an expert is better equipped to trace.
If the malicious code is heavily obfuscated and you cannot tell clean files from infected ones, or if you are not comfortable working with server files and databases, professional help reduces the risk of missing something or breaking your site. If your business depends heavily on the site and every hour of downtime or suppression costs real money, the speed and certainty of an expert may be worth the fee. There is no shame in this handoff; the goal is a genuinely clean, secure site, and knowing when the problem exceeds your comfort is good judgment, not failure.
Do the parts you can, and bring in expertise exactly where the stakes or complexity are highest.
Verdict
SEO recovery after a hack works in five steps: contain, clean, close the entry point, handle the Google side with a clear review request, and then wait through a realistic recovery while monitoring for reinfection. Cleanup and warning removal are fast, but trust and ranking recovery take patience.
The two make or break steps are genuinely closing the entry point, since reinfection undoes everything, and writing a specific, honest Google review request. Do those well, keep the site clean for 90 days, and most sites recover fully. To prevent the next hack, harden your site using our guide to WordPress security settings, and back up properly with our website backup strategy guide.
Frequently asked questions
How long does Google take to remove the hacked warning?
Once your site is genuinely clean and you submit a review request in Search Console, Google typically removes the hacked warning within a few days to a couple of weeks, depending on the review queue and warning type. The key is that the site must actually be clean when reviewed, since a failed review over leftover infection restarts the wait. A clear, specific review request describing your cleanup helps it go smoothly.
Do I need to disavow after a hack?
Usually you do not need to disavow links after a hack, since a typical hack involves injected content and malware rather than a bad backlink profile. Disavow is for link based problems, not hacks. Focus instead on cleaning the site, closing the entry point, and requesting a security review. Only consider disavow if the hack also generated large numbers of spammy links to your site and you have clear evidence of harm.
Will my rankings come back fully?
In most cases, rankings come back fully after a hack if you clean up promptly, close the entry point, and keep the site secure, though it can take weeks to months as Google rebuilds trust. Fast action leads to fuller recovery. If some rankings have not returned after several months of a clean, stable site, the damage may be partly lasting, and continued strong SEO is then the way forward rather than waiting.
Should I delete hacked pages or fix them?
It depends on the page. Spam pages the attacker created should be removed entirely, and their URLs cleaned from Google, since they are not real content. Your genuine pages that were altered should be cleaned and restored rather than deleted, so you keep their rankings and links. In short, delete the attacker’s injected spam pages, but fix and keep your own legitimate pages that were compromised.
How do I write a review request to Google?
Write a clear, specific review request in Search Console that documents what happened and what you did. State that the site was hacked, describe the type of compromise, list the exact cleanup actions you took, identify the entry point and how you closed it, and confirm the site is now secure. Honesty and specificity work far better than vague requests, since they show Google you understand and have genuinely fixed the problem.
