Post-hack recovery guide

PrestaShop SEO after a hack
repair your rankings, not just remove the malware

A hack doesn't just infect your files: it wrecks your SEO. Meta descriptions replaced by Chinese or Japanese spam, thousands of doorway pages indexed, a “This site may be hacked” warning… Removing the malware is not enough — Google keeps showing the damage until your clean pages are regenerated and recrawled. Here is the full plan.

The 3 SEO symptoms of a hacked store

If you recognize any of these in your store's Google results, the hack has reached your SEO:

Chinese or Japanese metas in Google

Your SERP titles and descriptions show Asian characters, counterfeit or pharma keywords. That's the “Japanese keyword hack”: malware injects its own tags, often served only to Googlebot — your site can look perfectly normal in a browser.

Pages you never created

A site:yourstore.com search reveals hundreds of unknown URLs — counterfeit, casino or streaming doorway pages. They dilute your crawl budget and associate your domain with spam.

Google warning and traffic collapse

“This site may be hacked” under your link, a Security issue in Search Console, organic traffic in free fall — clicks collapse even on still-healthy pages.

Recovery happens in 2 phases — in this order

Fixing the SEO of a still-infected store is pointless: the malware re-injects its spam. And disinfecting without repairing the SEO leaves Google showing the damage for months. You need both, in order.

Phase 1 — Disinfect the store (files AND database)

Cleanup must cover files AND the database: SEO injections often persist in the DB (modified configurations, hooked modules, rogue admin accounts) and survive file-only cleanups — the #1 cause of re-infection. For a complete read-only diagnosis, our parent company Genisoft (the PrestaShop agency that publishes Fexa AI) built a dedicated scanner:

  • Detects webshells, backdoors, card skimmers and MySQL credential theft
  • ALSO scans the database: injected configurations, rogue admin accounts, malicious crons
  • 100% read-only — zero risk for the store, detailed evidence-based report
  • PrestaShop 1.7, 8 and 9 (PHP 5.6 → 8.4)
Genisoft Security Scanner — scan my store
Transparency: Security Scanner is a Genisoft product — Fexa AI's publisher. Any other security tool or professional works too; what matters is disinfecting files + database before phase 2.

Phase 2 — Rebuild the wrecked SEO (where Fexa comes in)

A clean store doesn't mean clean SERPs: Google keeps the spam metas and doorway pages in its index until it recrawls healthy versions. This phase is about mass-regenerating what was polluted and pushing Google to come back:

  • Free, unlimited SEO scan of the catalogue: spot every sheet with polluted or emptied tags
  • BULK regeneration of titles, meta descriptions and descriptions by AI anchored to your real product data
  • Clean structured data re-injected (FAQ, Product, Breadcrumb)
  • Sitemap and llms.txt regenerated — Google and AI engines recrawl healthy pages
  • Built-in Search Console tracking to measure recovery, sheet by sheet
Run my free SEO scan

The recovery plan, step by step

  1. 1

    Diagnose the infection

    Scan files + database (phase 1). Never clean blindly: a precise report avoids breaking the store and proves disinfection.

  2. 2

    Disinfect and patch

    Remove identified payloads, change ALL passwords (admin, MySQL, FTP), update PrestaShop and vulnerable modules.

  3. 3

    Scan the catalogue's SEO

    Free unlimited Fexa scan: every sheet is scored; tags polluted, duplicated or emptied by the malware stand out immediately.

  4. 4

    Bulk-regenerate polluted tags

    Regenerate titles, metas and descriptions in batches — the AI anchors on your real product data, not the infected text. Weeks of manual rewriting become hours.

  5. 5

    Get Google to recrawl

    Clean sitemap resubmitted in Search Console, URL inspection on key pages, reconsideration request if a Security warning was active.

  6. 6

    Monitor the recovery

    Track impressions and positions in Search Console (integrated in Fexa): healthy metas replace the spam as recrawl progresses — from days to several weeks depending on site size.

Why Google still shows spam after the cleanup

Google doesn't display your live site: it displays its index. Each SERP shows the last crawled version of a page — if Googlebot visited during the infection, the spammed version keeps showing until the next crawl. On a catalogue of thousands of URLs, that full recrawl can take weeks: every day counts.

That's why mass regeneration is the core of recovery: it's not enough for a page to be “back to normal” — every sheet must re-present Google with clean, consistent, useful content. A store that exits cleanup with empty or identical tags everywhere stays penalized, hack or no hack.

A hack also degrades your trust signal for answer engines (ChatGPT, Perplexity…) that cite stores. Quickly republishing a clean llms.txt and valid structured data is part of the recovery — both regenerated automatically by Fexa.

Frequently asked questions after a hack

Why does Google show Chinese descriptions for my store?

It's the signature of the “Japanese/Chinese keyword hack”: malware injects spam tags into your pages, often served only to Google's crawlers (cloaking). Your site looks normal in a browser, but Google's index holds the spammed version. Disinfect the store, then get clean pages recrawled.

I removed the malware but the spam is still in Google. Is that normal?

Yes: Google shows its last crawled version, not your live site. Until each page is recrawled with clean tags, the spam stays visible. Speed it up with a resubmitted sitemap, URL inspection on important pages, and regenerated tags that give Google a real reason to update.

Does Fexa AI remove malware?

No — and be wary of anyone claiming to do everything. Fexa repairs the SEO (scan, tag and content regeneration, structured data, reindexing, tracking). Disinfection is a security job: use a dedicated scanner like Genisoft Security Scanner (files + database, read-only) or a trusted professional.

How long until my rankings recover?

No serious guarantee is possible: it depends on how long the infection lasted, catalogue size and recrawl speed. Observed orders of magnitude: a few days for main pages, several weeks for a large catalogue. The sooner clean tags are live, the sooner the index corrects itself.

Should I regenerate all metas or only affected pages?

Start with the polluted pages (the scan identifies them). But hacks often leave tags emptied or duplicated at scale: if your coverage was already weak, it's the right moment to regenerate the whole catalogue — the free scan gives you the exact state before deciding.

How do I avoid re-infection?

The #1 cause of relapse: a file cleanup that misses the database (rogue admin accounts, hooked modules, malicious crons). Scan both, rotate all credentials, keep PrestaShop updated, and schedule recurring monitoring — Security Scanner offers scheduled scans via a token-protected URL.

Store clean? Now rebuild.

Scan your catalogue for free: see in 2 minutes which sheets still carry polluted, empty or duplicated tags.

Run my free SEO scan