Skip to content
Frano Čokljat

Kompas · Croatian travel and news publisher

Kompas: recovering a hacked publisher by shrinking its index

A spam injection took Kompas from 500+ organic clicks a day to near zero. Known URLs fell from ~70,000 to under 15,000, and traffic is back to about half and rising.

Client
Kompas
Sector
Travel and news publishing
Engagement
Hack cleanup and archive retirement, 2025–2026
Published
  • ~70k → <15k

    URLs known to Google

  • 44

    pages indexed, all on the keep list

  • ~50%

    of pre-incident traffic, still rising

Context

Kompas is a Croatian travel and news publisher. Its WordPress site was compromised through a hacked plugin, and spam pages were injected into it at scale. Google crawled and indexed them. I was brought in to clean it up.

Problem

Organic traffic collapsed in late September 2025, from more than 500 clicks a day to near zero within a few weeks.

Alongside the cleanup, the client wanted to retire a large part of the legacy archive. So the index had to shrink for two different reasons at once, and the two kinds of page needed opposite treatment. Spam had to disappear. Retired articles still had links and history worth keeping.

What I did

Agreed a keep list first. Before removing anything, the client and I agreed which URLs the site should keep. Everything else was either injected spam or retired archive, and that list was the reference for every decision after it.

Spam was removed outright. Injected URLs returned 410 Gone, which tells Google the page was removed on purpose rather than temporarily missing. The worst patterns also went through the Search Console removals tool, so they left the results while recrawling caught up.

Retired pages got redirect decisions. These were real articles with links pointing at them, and deleting them would have thrown that equity away. Where a retired page had a relevant equivalent on the keep list, it was redirected there. Where it didn’t, it was noindexed and left to drop out.

Sitemaps listed only what should be indexed. The sitemaps were rebuilt from the keep list, so Google had one clean statement of what the site is, separate from everything it was being told to forget.

There was no manual action to clear. The Manual actions report was empty. The drop was algorithmic, so recovery depended on Google recrawling and re-evaluating the site, not on a reconsideration request.

The way in was closed. The compromised plugin was removed, and the site was rebuilt as a static Astro site, which removes the plugin attack surface altogether.

What I owned

I owned the diagnosis, the URL triage, the removal and redirect plan, and the Search Console work. The client decided which parts of the archive to retire, and we agreed the keep list together.

Result

  • URLs known to Google fell from about 70,000 to under 15,000. Of those, 13,400 are now correctly excluded and 44 are indexed.
  • Organic traffic started recovering in May 2026. It is now around half of its pre-incident level and still climbing.
Search Console page indexing chart for Kompas. Known pages hold at about 74,000 from late July 2026, step down through late August and early September, and settle at about 14,000 by late September: 13,400 not indexed and 44 indexed.
Google Search Console, Page indexing, July to October 2026 · Open full size

The site Google indexes went from tens of thousands of URLs to 44 pages, and traffic is rising on those 44. Fewer, better pages.

What I’d do differently

Report the two removals separately from day one. The spam cleanup and the archive retirement ran at the same time, so it’s hard to say how much of the recovery came from each. Tagging the two URL sets separately in reporting from the start would have answered that.

Treat page count as an alert, not just traffic. A spam injection shows up in the page indexing report before it shows up in clicks. A sudden rise in known pages deserves its own alert, so the next one is caught before traffic moves.