Most site owners think of a hack as an inconvenience. The reality is a cascade of costs that often far exceeds what was spent building the site. Here's what you're actually risking.
Often, the owner is the last to know. Attackers who compromise a site to serve malware or inject spam links have no incentive to announce themselves — a compromised site they control is valuable only if it keeps operating normally. The signs often come from outside: a Google warning in search results, a customer mentioning something looks wrong, or your hosting provider suspending the account for resource abuse or malware distribution.
By the time any of these happen, the compromise may have been running for weeks or months.
Professional WordPress cleanup services charge between $100 and $500 for a typical compromised site. The work involves scanning all files for malicious code, removing backdoors, checking the database for injected content, restoring clean versions of core files, and identifying and closing the original entry point.
If you attempt it yourself, expect to spend many hours and potentially miss something. Backdoors are often well-hidden — in image files, in database options, in .htaccess, in files you wouldn't think to look at. A site that looks clean but still has a backdoor will be re-compromised quickly.
If your host detects malware or your site is sending spam, they will suspend your account. Your site goes down entirely. Getting unsuspended requires demonstrating the malware has been removed, which requires cleanup — catch-22 if your file manager access is also suspended. Some hosts will restore access temporarily for cleanup; others won't.
Google Safe Browsing flags sites distributing malware. When your site is flagged, Chrome, Firefox, and other browsers show a full-page "This site may harm your computer" warning before visitors can proceed. This effectively destroys traffic overnight.
Removing the flag requires submitting a reconsideration request to Google Search Console after cleanup. Google reviews it within a few days and removes the warning if the malware is gone. But the ranking damage — from the period of being flagged, the lost traffic, and reduced crawling during the incident — takes considerably longer to recover.
If attackers used your server to send spam, your server's IP address may be listed on email blacklists. Your legitimate transactional emails — contact form notifications, WooCommerce order confirmations — will start landing in spam or bouncing entirely. Getting delisted requires submitting removal requests to each blacklist, a process that can take days to weeks.
Google demotes sites with security issues. Even after cleanup and delisting, the ranking recovery period can be months. For a site that depends on organic search traffic, this is directly measurable in lost enquiries or sales.
Customers who encountered a security warning on your site or received a spam email appearing to come from you won't necessarily know you were the victim rather than the source. For professional services businesses, the reputational impact can be disproportionately large relative to the technical incident.
The arithmetic strongly favours prevention. Keeping WordPress and plugins updated, using a strong unique password, choosing a host with proper security configuration, and maintaining regular backups costs a fraction of what cleanup and recovery costs — even in cases where the cleanup is quick.
The backups point is critical: a clean, recent backup means cleanup is a matter of hours rather than days. Without a backup, you're cleaning a site you can't fully trust and may miss something. With a backup from before the compromise, you restore and then investigate the entry point.
At DownUnder WP, daily backups are available as an add-on at $2/month per container. The peace of mind that a clean restore point exists is worth considerably more than that.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.