wp2shell: more than a month later. Confirm 6.8.6, 6.9.5, 7.0.2. Patched is not clean.

Read the advisory

Recover WordPress SEO After a Hack

Recover WordPress SEO after a hack: Japanese keyword spam, Search Console Security Issues and Manual Actions, sitemap cleanup, and reconsideration requests.

Topics Backups & recovery

Lars Koudal

Lars Koudal

Updated Published

A hack hurts SEO because Google and visitors see spam, redirects, or malware warnings. Ranking recovery starts with a clean site. SEO tools cannot outrank an infection that is still live.

Recover WordPress SEO after a hack

Order of operations (do not skip cleanup)

  1. Contain and clean (malware removal, what to do if hacked)
  2. Confirm the site is clean logged out and logged in; rescan files and the database
  3. Rotate credentials (WordPress, host, FTP, DNS if needed)
  4. Then work Search Console, spam URLs, sitemaps, and content fixes

If you only remove spam posts and leave a backdoor, rankings bounce and then collapse again.

Japanese keyword hacks (and similar SEO spam)

One common campaign injects thousands of spam URLs filled with Japanese (or other) keyword text for fake shops, pharma, or gambling. Owners often miss it at first because of cloaking: Googlebot is shown the spam pages while a logged-in human still sees a normal homepage.

Typical injection points:

  • Extra posts, pages, or options rows in the database
  • Modified theme or plugin PHP files
  • Malicious redirects in .htaccess or rogue plugins
  • Spam sitemaps or injected links meant only for crawlers

How to spot it

  • Search Google for site:yourdomain.com and look for foreign-language or junk titles you did not publish
  • Sudden ranking drops, or odd traffic spikes to nonsense URLs
  • Browser or Safe Browsing warnings
  • Security Issues or Manual Actions in Search Console

Treat this as malware cleanup first. Deleting a few visible posts is not enough if the database or a backdoor still regenerates spam.

SEO symptoms that often mean malware

  • Sudden foreign-language or pharma spam in search results
  • Redirects for Googlebot or mobile users only
  • Search Console security issues or Safe Browsing warnings
  • Unknown pages indexed with your domain
  • Analytics traffic spikes from nonsense URLs

Google Search Console checks

After (or while) cleaning, open Google Search Console for the property:

  1. Security Issues under Security & Manual Actions. Note malware, hacked content, or social engineering flags.
  2. Manual Actions. A spam or hacked-content action needs a clean site before reconsideration.
  3. URL Inspection on a few spam URLs and a few important real URLs.
  4. Pages / indexing reports for a surge of unknown URLs.
  5. Sitemaps for any sitemap you did not submit (or that lists junk URLs).
  6. Messages for emails you may have missed while the site was on fire.

If you lost Search Console access, re-verify ownership (HTML file, DNS, or another supported method) before you can request review.

Spam URL cleanup checklist

  1. Remove malware and database spam (malware removal)
  2. Delete or trash spam posts/pages; empty trash
  3. Remove malicious redirects (.htaccess, plugins, SEO plugin redirect modules)
  4. Regenerate a clean XML sitemap from your SEO plugin or WordPress core sitemaps
  5. In Search Console, remove or leave outdated spam URLs to drop naturally; use removals only for urgent sensitive URLs when appropriate
  6. Submit the clean sitemap
  7. Request indexing for key real pages after the site is clean

Do not disavow backlinks as your first move. Most Japanese-keyword damage is on-site spam and cloaking, not a mystery backlink profile. Disavow only when you have a clear third-party spam-link problem after cleanup.

Requesting a review (reconsideration)

When Security Issues or a Manual Action remains after cleanup:

  1. Confirm the site is clean (rescans, logged-out checks, site: search improving)
  2. Document what you fixed (malware removed, spam URLs deleted, credentials rotated, firewall/login hardening enabled)
  3. In Search Console, use Request review on the relevant Security Issue or Manual Action
  4. Be specific and honest. “We hope it is fine” fails reviews. “Removed injected posts and backdoor plugin X, rotated all credentials, submitted clean sitemap” is the right shape
  5. Wait. Reviews are not instant. Keep monitoring; do not reopen holes while you wait

If Google still sees spam URLs, the infection is probably not gone. Fix the site again before another request.

After the site is clean

StepAction
Search ConsoleClear Security Issues / Manual Actions via review when needed
IndexDrop spam URLs; submit a corrected sitemap
RedirectsDelete malicious rules; keep only intentional 301s
ContentRestore damaged pages from a clean backup
LinksDisavow only with a clear post-cleanup spam-backlink case
MonitorWatch coverage and performance for several weeks

Hardening so it does not repeat: security checklist, hardening guide.

Tools that help the security half

Stuck on cleanup? Hire help.

Bottom line

SEO recovery after a hack is cleanup, then Search Console, then patience. Japanese keyword spam and cloaking are malware problems with SEO symptoms. Do not buy SEO theater while the backdoor is still on disk. Start Free on WordPress.org or see pricing for Pro scanning and firewall.

Found this useful? Share it.

Larger screenshot