Foundation: tracking, indexing & Core Web Vitals
Month one built the measurement layer and technical baseline the whole campaign runs on.
Measurement & crawl foundation
-
›
GA4 + Search Console integrated for traffic, behaviour & index coverage
-
›
Audited robots.txt; clean XML sitemap generated & submitted
-
›
Full Googlebot-simulated deep-crawl across the site
-
›
404s, redirect chains & warnings mapped for remediation
Positioning & backlink gap
-
›
Top 5 competitors identified & organic footprint reverse-engineered
-
›
Backlink intersection analysis → high-authority target pool
-
›
Domains linking to competitors but not Reya isolated for outreach
Stability & payload
-
✓
CLS: custom CSS reserves space for heading animations — layout shift resolved
-
✓
Payload: heavy images converted to modern compressed formats
Render-blocking JS
-
!
Deferring jQuery/builder JS spiked scores but broke Contact-form AJAX
-
↺
Rolled back immediately — live lead-gen protected over a test metric
Why this matters
The change moved render-blocking scripts to the footer and loaded Elementor stylesheets asynchronously. Tool-reported scores jumped, but inquiry submissions failed. Protecting a working lead channel outweighed a synthetic score — documented here for transparency, not hidden.
Strategy & topic mapping
-
›
ICPs & user personas defined
-
›
High-value topic clusters mapped
-
›
Manual EEAT analysis on founder profile woven into strategy
Elementor / builder ceiling
-
›
Surface bloat stripped; layout stabilised
-
›
90+ scores need root-level builder work
-
›
Requires original dev team to avoid breaking the live site
Keyword architecture, silos & the content engine
Month two built the production pipeline — research, silo structure, and the first article wave staged for early-June launch.
Intent mapping
-
›
Intent-led research across longevity, preventive care & clinic management
-
›
Long-tail expansion layered on top
-
›
Organised into prioritised clusters driving the roadmap
Structure & linking
-
›
Silo architecture planned
-
›
Internal links improved across the site
-
›
Unlinked / underlinked pages identified & addressed
June pipeline drafted
-
›
First educational cluster researched & drafted
-
›
Queued for a sequenced early-June rollout
-
›
Staged, not dumped — clean cadence per URL
Consent-policy (Complianz) Resolved
-
›
Cookie-consent rollout required consent-mode re-verification
-
›
Consent configuration handled by Reya's development team
-
›
GA4 & GSC confirmed reporting cleanly before scaling publication
-
›
First high-authority target list curated from the backlink-gap pool
-
›
Relationship-based outreach initiated (batch 1), entering webmaster response cycles
-
›
Page structures & silos audited; meta and structural tags prepared ahead of on-page optimisation
Publishing launches — then a security incident forces a pause
Four articles went live in early-to-mid June. On ~22 June a casino PBN compromised the site; publishing was paused for containment.
4 articles published
-
›
First educational cluster went live on a sequenced cadence
-
›
Strong indexing behaviour — ~3 days to index per article
Casino PBN compromise Contained
-
!
Admin-level account compromised by a Private Blog Network
-
!
Casino posts published, footer links injected, 12 spam posts indexed before detection
Full forensic detail
Entry vector, database persistence and remediation are documented under Additional Services → Casino Exploit Resolution.
Publishing paused
-
›
Footer injection was sitewide — new pages would carry casino markup into the index
-
›
Pausing stopped the spam footprint growing on a YMYL health domain
-
✓
Content production continued in the background — queue kept ready
| # | Article | Published |
|---|---|---|
| 01 | What is longevity medicine | 11 Jun 2026 |
| 02 | What is a longevity clinic and how does it work | 12 Jun 2026 |
| 03 | Healthspan vs lifespan vs longevity, and what longevity medicine actually does about the gap | 15 Jun 2026 |
| 04 | What are the four Ps of medicine and why they matter for longevity clinics | 16 Jun 2026 |
Remediation, verification & controlled resume
The incident window closed 25 July. Publishing resumed 27 July on a controlled cadence; event-page work began in parallel.
Publishing blocked by the incident
-
!
Remediation + one-week verification window ran through 25 July
-
›
Full technical account documented separately
Where the detail lives
File-system audit, database forensics, credential rotation and verification are under Additional Services → Casino Exploit Resolution.
Work continued during the block
-
✓
Off-page guest-post prospecting & data collection
-
✓
Back-end content production — queue built & staged
-
✓
Remediation coordinated with hosting through 25 July
Controlled publishing resumes
-
✓
Site verified clean; publishing resumed 27 July after the 25 July verification close
-
›
5 articles shipped 27–31 July on a steady daily cadence
| # | Article | Published |
|---|---|---|
| 05 | What is biological age and how is it actually measured | 27 Jul 2026 |
| 06 | Epigenetic age test explained | 28 Jul 2026 |
| 07 | How to start a longevity clinic — a complete founder’s guide | 29 Jul 2026 |
| 08 | Patient engagement in a longevity clinic | 30 Jul 2026 |
| 09 | What is longevity intelligence | 31 Jul 2026 |
Recovery publishing at pace, new event pages & off-page scale-up
Nine articles on a steady daily cadence, a second from-scratch event page, and the off-page programme scaled to 100 prospects.
| # | Article | Published |
|---|---|---|
| 10 | Why longevity clinics need a clinical intelligence layer like Reya above the EMR | 3 Aug 2026 |
| 11 | Longevity vs functional medicine — the six differences that actually matter | 4 Aug 2026 |
| 12 | How a functional medicine practice expands into longevity medicine | 5 Aug 2026 |
| 13 | Lifestyle medicine vs longevity medicine | 6 Aug 2026 |
| 14 | How to add longevity medicine to a lifestyle medicine practice | 7 Aug 2026 |
| 15 | Anti-aging vs longevity medicine | 8 Aug 2026 |
| 16 | How to add longevity to a med spa — the operator’s playbook | 10 Aug 2026 |
| 17 | Concierge medicine vs longevity medicine | 11 Aug 2026 |
| 18 | Longevity concierge medicine — how to run and scale it profitably | 12 Aug 2026 |
Refreshed prospect programme
-
›
Batch 1 secured no placements — target pool re-analysed
-
›
Rebuilt into 100 healthcare-relevant prospects, qualified for topical relevance
-
✕
Outreach discontinued — programme wound down
Cadence rebuilds the topic signal
-
›
14 articles across 27 Jul – 12 Aug on a controlled cadence
-
›
Each URL submitted for indexing → Google re-crawls a healthcare-focused site at pace
-
›
3-month indexing velocity now works in the campaign's favour
What’s next
With the project winding down for a 31 August close, only on-page content optimisation and the LLM context file remain in play. The remaining off-page and ongoing-content workstreams are discontinued.
Content optimisation
-
›
Homepage first, then core pages
-
›
Meta, structural tags, intent alignment
LLM context file Waiting for homepage content
-
›
Deploy for accurate AI-crawler parsing
-
›
Extends readiness beyond classic search
Sitemap update Discontinued
-
›
Refresh & resubmit full published set
-
›
Keeps discovery current as URLs ship
Continued production Discontinued
-
›
Hold the cadence through recovery
-
›
Expand cluster coverage & authority
SEO listings Discontinued
-
›
Directory & industry listings
-
›
Citation consistency
Guest posts & backlinks Discontinued
-
›
Advance batch-2 (100 prospects) to placements
-
›
Rebuild & grow domain authority
Where things stand: the home-page content optimisation for Reya as an intelligence layer was created and shared on 24 Aug 2026. On a follow-up call with Jomy we learned about Reya’s pivot, so we produced fresh home-page content for the new positioning and have already shared that too. Both directions also call for a fresh UI for the website, and we are currently awaiting approval on both.
40 articles produced against quota — 22 held back by the pivot Decision needed
Per the content quota, 40 articles have already been written for Reya as the intelligence layer. 18 are published and live. The remaining 22 are not yet published because of the pivot.
Action needed: approve publishing the 22 intelligence-layer articles as they are, or decide not to publish them.
We’d like this decision within a day (by 26 Aug 2026, EOD) so we have time to wrap the project by 31 Aug 2026. All SEO-related work will be discontinued after 31 August.
Keywords we’re now ranking for on Google
Live Google SERP positions for target longevity keywords — several already in the top 3, with the intelligence-layer term at #1 and also cited by Google’s Gemini.
| # | Keyword | Position | Notes |
|---|---|---|---|
| 01 | Longevity Intelligence Layer | #1 | Position 1 — also cited by Google’s Gemini |
| 02 | 4Ps of Medicine | #3 | Top-3 result |
| 03 | Start a Longevity Clinic | #3 | Top-3 result |
| 04 | Longevity Clinic Operating System | #4 | First page, just outside the top 3 |
| 05 | Longevity Concierge Medicine | #7 | First page |
| 06 | Longevity Clinic Patient Engagement | #12 | Page two — climbing |
Positions are as per the live Google SERP. Rankings fluctuate with each crawl — these reflect the standings at the time of this report.
Invoices & payment summary
Summary of invoices issued to date. Two invoices remain outstanding — Invoice 0060 (July 2026) and Invoice 0062 (August 2026) for SEO Management Services.
| # | Invoice No. | Date | Details | Amount | Status |
|---|---|---|---|---|---|
| 1 | 0062 | 25 Aug 2026 | SEO Management Services, August 2026 | $1,025.00 | Unpaid |
| 2 | 0060 | 8 Aug 2026 | SEO Management Services, July 2026 | $1,025.00 | Unpaid |
| 3 | 0041 | 17 Jul 2026 | Malware Removal Service, Casino Hack Fix | $1,000.00 | Paid |
| 4 | 0036 | 1 Jul 2026 | SEO Management Services, June 2026 | $1,020.50 | Paid |
| 5 | 0032 | 25 Apr 2026 | SEO Management Services, May 2026 | $1,020.50 | Paid |
| 6 | 0030 | 25 Mar 2026 | SEO Management Services, April 2026 | $1,020.50 | Paid |
$1,025.00 — SEO Management Services, Growth Plan Unpaid
Invoice date: 8 Aug 2026 · Service period: July 2026
$1,025.00 — SEO Management Services, Growth Plan Unpaid
Invoice date: 25 Aug 2026 · Service period: August 2026
Total outstanding: $2,050.00 — $1,025.00 (July 2026) + $1,025.00 (August 2026).
The persistence mechanism was located and removed. The remediation is executed and now under monitoring.
WordPress admin access was received on 7 July 2026. Elementor hosting access followed on 16 July 2026. The remediation was executed on 18 July 2026. This section documents the work carried out at the file and database level.
Access and remediation Executed
Ace Wix received WordPress admin access on 7 July. We reviewed the site through the file manager and located the loader.
File and database level access followed with the Elementor hosting grant on 16 July.
The remediation was executed on 18 July. The removal work is done.
Status Executed · monitoring
The remediation is executed, not yet formally closed. A monitoring window of one week is now running.
The incident is closed only after the watch confirms nothing regenerates. If any component returns, we re-analyze and remediate at once.
Remediation approach
The work followed a fixed order. Map the infection, remove the source, clear the content, then rotate credentials.
This sequence is deliberate. A wrong order lets this class of infection rebuild itself during cleanup.
-
7 JulyWordPress admin access receivedSite reviewed through the file manager inside WordPress.
-
7–10 JulyFile system auditFull file system downloaded. The Easy Post loader was found in mu-plugins and removed manually. The downloaded copy was verified with ClamAV by 10 July.
-
16 JulyElementor hosting access receivedDatabase access granted for the deeper review.
-
16–18 JulyDatabase forensicsFooter injection and unauthorized access keys located and removed.
-
18 JulyRemediation executedAccess keys revoked. Security keys regenerated. Sessions invalidated.
-
18–25 JulyVerification windowOne week of activity log and file change monitoring.
The audit covered both layers of the site. The file system was examined first, then the database.
The file system held one malicious file, the Easy Post loader. It was removed. The stored injection and the persistence mechanism lived in the database.
The following sections document each layer, the findings and the action taken for each.
A full offline scan of every file on the site
We pulled a complete copy of the file system and scanned it away from the server. An offline scan is stronger. Malware cannot hide from a scanner the way it can on a live server.
Offline copy and scan
Through the file manager we downloaded a full copy of the WordPress file system. We scanned it locally with ClamAV by 10 July and ran a manual signature review.
Coverage
The scan covered the theme, all plugins and the uploads directory. It also covered wp-admin, wp-includes, the root files and wp-config.
Core integrity
We compared the WordPress core files against the official release. No modified core file was found. No added core file was found.
One malicious file found and removed Verified
One malicious file was identified, the Easy Post loader in the mu-plugins directory. It was removed by manual check before the scan completed.
The rest of the file system was clean. We found no injected code, no web shell and no other rogue script.
Direction set
File editing was already disabled through DISALLOW_FILE_EDIT. This confirmed the stored injection had to sit in the database.
The Easy Post loader was the entry vector
The audit traced the injection to a must-use loader. This component ran on every request and stayed hidden from the plugin list. The steps below cover how it was found, checked and removed.
-
Entry vectorEasy Post loaderA must-use loader named Easy Post was found in the mu-plugins directory. It executed on every page load and hid itself from the admin plugin list. The loader was removed.
-
Replication checkSelf-healing copiesThis class of loader often keeps a second copy that rebuilds the first. Every plugin directory was checked for duplicate copies. A Duplicator check was run for any packaged re-installer left behind.
-
SweepPlugin and folder auditEvery plugin folder and the uploads directory were reviewed. We looked for unauthorized PHP files and unfamiliar plugin names.
-
ResultLoader layer cleanAfter removal, the plugin and file layers were clean. No further loader or replicator remained. The stored content and the persistence mechanism still lived in the database, so the audit moved there.
The database held the injection and the persistence mechanism
The file system was clean, so the source had to be in the database. A full database audit confirmed this. It also revealed the persistence mechanism behind the recurring spam.
Footer injection
The casino footer was stored in an options record named easypost_homepage_placements.
It held cloaked anchors set with absolute off-screen positioning. Visitors never saw them. Search engines still read them.
The record was deleted.
Spam content
The 12 spam posts were removed from the site. The URLs now return 410 Gone for permanent deindexing.
The same URLs were already cleared from Google through the Search Console Removals tool.
Scheduled tasks
We audited WordPress cron and the Action Scheduler queue. No malicious scheduled task was present. Every entry was a known plugin task.
Code snippets
We audited the snippets table. Every snippet was legitimate and owned by the site. None created posts or output footer content.
Unauthorized application credentials
The audit found three unauthorized application access keys. These are API credentials that authenticate against the site without a standard login.
They were created between 21 and 22 June. One key was last used on 2 July, which matches the recurring spam.
They were called from two unrecognized external addresses, 207.228.202.152 and 86.54.24.51.
This was the persistence mechanism. It let the operators re-inject content through the API after each earlier cleanup, without any dashboard login.
All three keys were revoked. The WordPress security keys were then regenerated to invalidate every active session and token.
The site is verified clean and now under a monitoring window
After removal, we verified the result from outside the site and locked down the access layer. A monitoring window now confirms nothing regenerates before the incident is formally closed.
Live crawl
We crawled the live homepage and blog from outside the site. The footer injection is gone from both.
Only genuine Reya content remains indexed. No cloaked markup was found in the page source.
Credential rotation
All user passwords were reset. The unauthorized access keys were revoked.
The WordPress security keys were regenerated. This ended any session the operators may still have held.
Monitoring window
We monitor the activity log and file changes for one week. This confirms no component regenerates.
If anything returns, we re-analyze and remediate at once.
Controls in place
Wordfence is active for firewall and malware monitoring. The custom login URL is live.
Two factor authentication is pending rollout for all administrator and editor accounts.
Remediation executed · monitoring in progress 1 week watch
The casino operation is removed from the file system and the database. The entry vector and the persistence mechanism are both closed.
The removal is executed and verified. The one week watch is the final step before the incident is formally closed. Once posting is confirmed stopped, the SEO recovery clock begins.
Publishing was paused for safety. It resumes on 27 July with a stacked pipeline.
The footer injection sat on every page. Publishing during that period would have spread the injected markup and fed Google more polluted pages. So content publishing was paused as a containment step.
Why publishing paused
The injection was sitewide. Every new page would carry the same casino markup into Google's index.
Pausing was the safe call. It stopped the spam footprint from growing while the source was still live.
Work never stopped
The pause was on publishing, not on production. We kept writing and preparing articles throughout.
A queue of ready articles was built up during this window. It is prepared and waiting to publish.
Publishing resumes
The footer is now removed and the site is verified clean. It is safe for Google to crawl again.
Publishing resumes on 27 July 2026, after the one-week verification window closed on 25 July. We push the prepared queue and let Google crawl clean pages.
Stacked publishing
The prepared queue lets us publish on a steady, continuous cadence rather than in one burst.
Consistent publishing rebuilds topical authority and trust signals. It is the fastest safe way back.
The pipeline drives the recovery timeline
The recovery timeline in the Casino Hack Report depends on fresh, clean content reaching Google at pace.
The stacked queue is exactly what feeds that. Steady publishing from 27 July restores the healthcare topic signal and rebuilds the authority lost during the incident.
The site's strong indexing velocity, built over the first three months, now works in our favour again. Clean articles get picked up fast and compound over the recovery window.
The site was hacked by a casino spam network. It is contained, but not fully cleaned yet.
Around 22 June 2026, reya.ai was compromised through a user account with administrator access. The attackers run a PBN (Private Blog Network) — an operation that hacks trusted sites to publish casino content and links. Everything reachable from WordPress admin has been cleaned; the remaining infection sits deeper and needs hosting-level access to remove.
-
~22 JuneAttack beginsFirst malicious activity through a compromised account, per the activity log.
-
22–29 JuneSpam published & indexedCasino posts go live; footer links injected; Google indexes 12 spam posts within days.
-
~29 JuneDetection & first responseEntry point traced; malicious plugins and rogue users removed; all passwords reset.
-
Early JulySearch cleanup beginsAll 12 spam URLs hidden via Search Console Removals. No manual action confirmed.
-
TodayInfection still active below the surfaceSpam keeps reappearing; footer injection still live. Points to a file/database-level backdoor.
-
NextDeep clean with hosting accessFull file and database audit with the hosting provider.
The good news Verified
Search Console shows no manual action and no security warning. Google has not penalised the site — the damage is to trust signals, not a formal penalty. Acting within the first week likely prevented browser warnings that would have hit every visitor.
The open risk Urgent
The casino footer links are still live on the site today. Every day they stay, Google re-reads a healthcare domain endorsing gambling sites. The SEO recovery clock cannot start until the backdoor is found and removed — which needs hosting-level access.
This month In progress
Aggressive SEO measures underway: deleted spam URLs are being moved from 404 to 410 Gone to force faster permanent deindexing, while hosting access is arranged for the deep clean.
A casino spam network took control and published through the site
Spam posts 12 indexed
The attackers published casino-related blog posts on reya.ai. Google crawled and indexed 12 of them before they could be caught.
Footer link injection Still live
Casino links were injected into the site footer — anchor text in Russian, French, Polish, Turkish, Hungarian and Danish, all pointing to gambling websites. This injection is still visible on the site today.
Why they do it: the PBN model
A Private Blog Network hacks legitimate, trusted websites and uses them as link farms. Reya.ai's domain trust — built through real content and real authority — is exactly what makes it valuable to them: every casino link on the site passes some of that trust to their gambling pages. They target sites like this deliberately, and they build in ways to stay.
The uncomfortable irony: our own indexing velocity
Over the past three months, our SEO work raised the site's crawl frequency and indexing velocity to the point where a new article could be indexed in about 3 days — content was even being picked up by Google's Gemini. That same speed worked against us during the attack: Google indexed the spam before it could be caught. On a slower site, most of those 12 posts would never have reached the index.
That velocity is not the problem — it's an asset. Once the site is clean, the same speed accelerates the recovery.
Possible entry through a compromised plugin or account with administrator access
Compromised plugin / administrator account
The initial scan identified the likely entry point as either a compromised plugin or a user account with administrator privileges. The available evidence does not conclusively identify the initial entry point.
Two malicious plugins
Using that access, the attackers installed modified plugins disguised as normal utilities — "Easy Post" and "Speed Optimiser". These did the actual damage: publishing spam and planting deeper hooks into the site.
Extra accounts & a bot
They created multiple extra user accounts and a bot account, so losing one door would not lock them out. Standard practice for PBN operations — they plan to stay.
What Ace Wix could reach
Ace Wix held WordPress admin access only — the level an SEO agency normally works at. Everything visible and fixable from that level has been handled. The remaining infection lives below it, at the hosting level. Currently Ace Wix holds only Wordpress Editor access.
Immediate containment and search cleanup
Inside WordPress Done
· Traced the entry point through the WP Activity Log
· Deleted the two malicious plugins
· Removed every rogue user account, including the bot
· Reset the password of every user on the site
· Deleted all casino spam posts
In Google Search Done
Submitted all 12 indexed spam URLs through Search Console's Removals tool — they are now hidden from results. The hold lasts about 6 months, covering us while permanent removal completes.
Verified in Search Console: no manual action, no security issue. That keeps the recovery path clean.
This month's aggressive SEO measures In progress
Moving the deleted spam URLs from 404 (Not Found) to 410 (Gone). A 404 tells Google "missing, maybe temporary"; a 410 says "removed on purpose, permanently". Google drops 410 pages from the index noticeably faster — this is one of the levers we're pulling to shorten the recovery.
The infection sits below WordPress — and every day it stays live matters
The symptom
After the cleanup, spam posts kept reappearing at regular intervals — and the casino footer links are still live on the site today, weeks after the plugins, users and passwords were dealt with.
The conclusion
The attackers left a backdoor at the file or database level — hidden code that recreates their access and content even after the visible pieces are removed. This layer is not reachable from the WordPress dashboard; it needs hosting-level access to the site's files and database.
Why this is serious Priority 1
Reya.ai is a healthcare platform. Every day the footer keeps linking to gambling sites, Google re-reads a health domain endorsing casinos — the exact opposite of the trust profile the site needs. And the SEO recovery clock cannot start until the infection is fully removed: cleaning search results while the site re-infects itself is pouring water into a leaking bucket. Closing the backdoor is the single most urgent item in this report — which is why the next phase, done with the hosting provider, matters more than anything else here.
A health site linked to casinos: the worst mismatch under Google's trust rules
Google treats health websites as YMYL ("Your Money or Your Life") — topics where bad information can hurt people. For YMYL sites, Google leans heavily on E-E-A-T: Experience, Expertise, Authoritativeness, Trustworthiness. Reya.ai's rankings depend on Google trusting it as a serious healthcare platform — and the hack attacks exactly that trust.
Topic dilution
Search Console now shows casino terms and anchor texts connected to reya.ai. Google's picture of what the site is "about" has been polluted with gambling topics — a drag on every healthcare keyword until it fades.
Trust signals
Outbound casino links from a health domain, spam pages in the index, and spam anchor text all lower the trust side of E-E-A-T. These fade only after the source is gone and Google re-crawls the clean site.
No penalty
No manual action, no security warning. A "hacked site" flag could have put warnings in Chrome for every visitor — far worse for a healthcare company. Acting within the first week likely prevented it.
Timeline cost: the target moves from month 6 to month 9
Deindexing the spam, letting the casino terms fade, and rebuilding trust signals adds roughly one quarter. The keyword set originally projected to reach top positions around month 6 is now projected for month 9.
Ranking projections always depend on Google — these are informed estimates, not guarantees.
A complete audit of the WordPress files and database, with the hosting provider
With hosting access granted, we run a systematic sweep of every layer the attackers could have touched. The goal is simple: find and remove every backdoor, then prove the site stays clean.
This plan was executed on 18 July 2026. The completed work is documented in Casino Exploit Resolution.
Core integrity
Verify the WordPress core files against the official clean versions, so any modified or added file stands out immediately.
Theme & plugin audit
Review the theme and all plugin code for injected code — including the footer injection that is still live. Reinstall from clean official sources where needed.
Malware scan
Scan the full file system for hidden scripts and webshells — attackers commonly plant these where the WordPress dashboard never shows them.
Database audit
Check the database content for injected entries, hidden users and stored spam — including anything that regenerates the spam posts.
Scheduled tasks
Review all scheduled tasks, WordPress and server level. Spam recurring at regular intervals often means a malicious scheduled job is doing the publishing.
Full credential rotation
Rotate every credential the attackers could have copied — hosting, database and FTP passwords, plus WordPress's internal security keys, which force-logs-out every session they might still hold.
Verification window
After the clean, monitor the activity log and file changes for a set period to confirm nothing regenerates. Only then do we call the incident closed — and start the SEO recovery clock.
This work is coordinated with the hosting provider's support team. Specific findings — file locations, affected records — are documented privately during the audit and shared in the closure report.
Prevention and hardening plan
Custom login URL Live
The default WordPress login URL has been changed to a custom one, cutting off the automated bots that hammer the standard login page.
Two-factor authentication Rolling out
Enforce 2FA for every account, mandatory for administrator and editor roles. Each person enrols their own authenticator app — a stolen password alone will never be enough again. This directly closes the door the attackers used.
Security plugin (Wordfence) Active
Wordfence is already installed by the development team. It provides login rate limiting, lockouts, firewall rules, file change detection and continuous monitoring.
Ongoing watch Continuous
Keep the WP Activity Log running with regular reviews, plus scheduled malware scans and file integrity checks — so any future attempt is caught in hours, not days.
How the search damage unwinds — step by step
Google does not forget instantly, but it does forget. Here is the realistic sequence once the deep clean is complete. The key dependency: every clock below starts only after the infection is fully removed.
Aggressive cleanup measures In progress
Spam URLs hidden via the Removals tool (done) and moved from 404 to 410 Gone this month, telling Google the pages are permanently removed. Hosting access requested for the deep clean.
Permanent deindexing
As Google re-crawls the 410 pages, the 12 spam URLs drop out of the index permanently — not just hidden, gone. The homepage and remaining blog post re-crawl clean once the footer injection is removed.
Casino terms fade from Search Console
With the spam pages and footer links gone, the casino queries and anchor texts lose their source and fade over several weeks of re-crawling.
Trust and topic signals recover
Google's picture of reya.ai re-centres on healthcare. Fresh, high-quality content published in this window speeds it up — the site's strong indexing velocity now works for us again.
Push to the ranking target
With clean signals restored, the original growth plan resumes at full force. The target keyword set is projected to reach top positions around month 9.
Summary: the hack costs roughly one quarter. The foundation built in the first three months — crawl frequency, indexing velocity, content quality — is intact, and it is exactly what makes the recovery this fast.