Published on 2 September, 2026 by Lana Miro
The website hack that left an e-commerce owner with lasting traffic loss
All responses in this series were submitted by real people and reviewed by the Melapress team. Some details may be generalized to protect anonymity.
After logging in to Google Search Console, I saw traffic had basically gone to 0.
For the owner of a small reptile blog and e-commerce store, the first indication of a security incident did not come from the website itself, but from Google Search Console.
The first sign of trouble was an email warning that malware had been detected on the site. When the owner checked what was happening, the effect on the business was already visible in its search traffic.
The compromise was traced back to a plugin that had not been updated for some time. The website was eventually cleaned and brought back online. But getting the site working again did not mean the traffic returned to where it had been before the hack.
Cleaning the website took several days
The website was a side project rather than a business supported by a dedicated technical team, so the owner was not in a position to respond immediately. Responding to the incident also took time.
I ended up hiring a freelancer who cleans up hacked websites to clean things and get the site back online.
The cleanup took around three to four days. By then, the site had been flagged by Google, and its search traffic had collapsed to 0.
Unfortunately, the rankings never fully recovered, and I was left with about 65% of the traffic I had pre-hack.
For a blog and ecommerce website that depended on people finding it through search, restoring visibility also mattered. After the hack, that growth was interrupted and the site never returned to its previous level of visibility.
The fact that you lose traffic long-term for something that is, to some extent, outside of your control (or at least not actively done by you) is rough.
The longer-term impact became especially clear when the owner eventually sold the website. Because its traffic had never fully recovered, they estimated the site sold for about half of what it might have been worth at its pre-hack traffic level. Before the incident, traffic had also been growing month over month, so the potential loss may have been even greater.
The lesson
The experience changed how the owner approached routine WordPress security.
I ensured there was always a security plugin on my site, started more actively updating plugins and themes, and implemented some basic security steps like adding 2FA to my admin account.
The incident showed how something as routine as falling behind on plugin updates could have consequences far beyond the initial cleanup. In this case, the effects included lost search visibility and, eventually, a lower sale price when the website was sold.
None of those measures can guarantee that a website will never be compromised. But after experiencing how quickly a security incident could affect the site and how long the effects could persist, the owner paid more attention to security.
Have you dealt with a WordPress security incident?
Your story can show what security incidents really look like beyond the statistics, including the impact and lessons that are easy to miss.
Tell us what happened, what the experience was like, and what you learned from it. Stories may be published anonymously.