Deleting hacked WordPress pages does not immediately remove their indexed URLs, snippets or security signals. Search Console helps Google observe the cleaned state, but temporary removal tools cannot substitute for correct public HTTP responses.
Secure ownership and make the live site consistently crawlable.
Inventory hacked URL patterns
Export or record example spam/phishing URLs, parameters, titles and source reports. Group them by real compromised page, invented path, language/subdomain and redirect pattern.
Do not click unknown destinations while signed into owner accounts. Keep lists secure if URLs contain customer identifiers.
Record first/last observed dates.
Verify live status and content
Test representative URLs publicly: legitimate restored pages should return clean 200; moved content a relevant 301; nonexistent hacked URLs true 404/410.
Avoid soft 404 (200 with error text) and redirecting every spam URL to homepage. Check canonical, robots and headers.
Reproduce mobile/referrer/first-visit conditions to rule out conditional malware.
Secure property ownership
Review owners/users and verification tokens for domain and URL-prefix properties. Preserve unknown identifiers before revocation and secure the Google account with MFA.
Remove unapproved HTML verification files, DNS records and analytics/tag-manager ownership only after control is established.
Use an organisational owner and independent recovery contact.
Clean sitemaps and internal signals
Regenerate XML sitemaps from clean content, remove spam URLs from links/navigation/feeds/hreflang and submit current sitemap locations.
Check SEO-plugin metadata, page-builder templates, structured data and alternate-language sitemaps for injected titles/URLs.
Sitemap removal alone does not deindex a still-live page.
Handle parameter and path floods
Hacks may generate thousands of query/path variants. Fix the server/database generator and return consistent status/canonical signals by pattern.
Do not create one redirect rule per spam URL or block crawling through robots.txt; both scale poorly and can hide final status. Validate encoded, case and trailing-slash variants without creating internal links.
Monitor logs/index reports for new patterns.
Use URL inspection selectively
Inspect important restored pages and representative removed URLs to see Google’s canonical/crawl result. Request indexing for critical clean pages after verification.
Do not submit thousands of spam URLs individually when one correct server/database rule handles the pattern. Monitor coverage over normal recrawl.
Record requested date and outcome.
Understand temporary removals
Use Search Console removals only when urgent visibility reduction is needed while permanent cleanup/status is already implemented. The effect is temporary and does not erase content.
Do not use it to hide a still-compromised page. Confirm robots do not prevent Google from seeing the final 404/410 or clean page.
Keep owner approval for broad prefix removals.
Resolve security and manual actions
Review Security Issues and Manual Actions separately. Follow the relevant review request after the site is clean and explain remediation/entry-vector closure.
Do not request reconsideration with generic "fixed" text while examples still reproduce. Avoid including secrets, customer data or payloads.
Retain submission/response IDs.
Protect legitimate SEO recovery
Compare important clean pages’ titles, canonical/hreflang/schema, robots and HTTP status with the pre-incident inventory. Emergency rules can accidentally noindex or redirect revenue pages.
Restore legitimate internal links/sitemaps only after security verification. Track impressions/clicks as recovery context, not proof of cleanliness.
Keep SEO edits separate from malware indicators in the change record.
Monitor crawl and recurrence
Watch logs for Googlebot requests to hacked URLs, new indexed patterns, changes in titles and original malicious indicators. Confirm requested URLs receive intended status.
Alert on new Search Console owners, sitemaps or verification files. Monitor file/database/tag/CDN changes outside Search Console too.
Index cleanup can take time; security recurrence requires immediate containment.
Verify commercial pages
Check primary service/product pages, checkout, forms and analytics after SEO/cache changes. Ensure legitimate URLs were not removed or noindexed during containment.
Request urgent SEO/security cleanup when hacked URLs keep returning 200 or ownership is unknown. Share property and URL-pattern lists securely—never owner credentials, customer data or malware publicly.