WORDPRESS SECURITY / AUSTRALIAN BUSINESS GUIDE 2026

WordPress Security for Australian Businesses: 12 Common Risks and How to Reduce Them

If your WordPress website is healthy but you want a stronger security baseline, Alpha WordPress Design Perth currently prices a Security Audit & Hardening scope at A$360. If the site is already showing malicious redirects, injected files, spam pages, unknown administrator accounts or malware warnings, our Malware Recovery guide price is A$720; deeper incidents involving repeated reinfection, hidden persistence or clean component replacement are scoped as Incident Recovery & Rebuild at A$1,200. Additional approved security or recovery engineering is A$90 per hour when work falls outside the agreed package. After the immediate problem is resolved, ongoing WordPress care currently starts at A$119 per month for Essential Care, A$359 per month for Business Care and A$749 per month for Commerce Care, with the level chosen around update risk, backup frequency, forms, bookings, checkout and how quickly the site needs attention. For context, the working comparison figures published on our security page are A$600 for a preventative audit, A$1,200 for malware recovery and A$2,000 for deeper incident recovery; those are comparison benchmarks rather than a claim that every Australian provider charges the same amount. Hosting, domains, premium security software, paid backup storage, legal or privacy advice, forensic evidence for legal proceedings, third-party account recovery and server rebuilds outside normal WordPress hosting scope are separate when required. This guide explains the 12 risks we would look for, how to recognise a compromised site, what should happen before malware is deleted, when DIY cleanup is reasonable, when professional recovery is safer, and how Australian businesses can reduce the chance of the same incident returning.

Alpha WordPress Design Perth 25 September 2026 24 min read

THE SHORT ANSWER

If you think the site is hacked, preserve a recoverable copy first, contain the incident, rotate access and investigate the cause before declaring it clean.

Visible malware is often only the symptom. A proper recovery checks WordPress core, plugins, themes, users, scheduled tasks, database content, credentials, backups and the vulnerable component or account that allowed access. For a healthy site, prevention is cheaper: current Alpha guide pricing starts at A$360 for audit and hardening. For an active compromise, our guide prices are A$720 for Malware Recovery and A$1,200 for deeper Incident Recovery & Rebuild.

Audit & hardeningA$360Preventative baseline for one WordPress installation
Malware recoveryA$720Recoverable active compromise
Incident recoveryA$1,200Deeper persistence or rebuild work
Ongoing careFrom A$119/moRoutine maintenance and recovery readiness

A hacked WordPress site is not fixed just because the homepage looks normal again.

Attackers can leave rogue administrator accounts, modified plugin files, injected database content, scheduled tasks, hidden PHP files or stolen credentials behind. If the original entry point remains open, a cosmetic cleanup can be followed by reinfection hours or days later.

Our approach is therefore ordered: preserve what may be needed for recovery, contain obvious malicious behaviour, secure access, investigate integrity, replace compromised components from trusted sources, remove persistence, patch the cause, test business-critical functions and monitor the site after recovery. The same logic also tells a healthy business what to protect before an incident occurs.

01 / ONE-OFF SECURITY PRICING

What does WordPress security and malware recovery cost with Alpha?

These are our current guide prices for one WordPress installation with working administrative and hosting access. The final written scope depends on what evidence of compromise exists and what must be verified after cleanup.

WordPress scopeOur guide priceBest fitWhat changes the quote
Security Audit & Hardening A$360 A live site with no known active compromise that needs a security baseline Admin access review, plugin/theme inventory, core integrity checks, backup viability, obvious exposure and practical hardening
Malware Recovery A$720 Redirects, injected files, spam pages, rogue users or malware warnings where recovery is practical Deeper scanning, malicious file/database cleanup, credential rotation, clean component replacement and verification
Incident Recovery & Rebuild A$1,200 Repeated reinfection, unknown persistence or a more heavily compromised installation Manual investigation, clean component replacement, stronger access controls, deeper verification and a documented recovery path
Additional approved security engineering A$90/hr Work that falls outside the agreed package Unusual custom code, larger remediation tasks, extra integrations, server-side work or additional approved investigation

All prices are AUD guide prices. GST treatment and any third-party costs are confirmed in the written quotation. Legal forensics, privacy advice, third-party SaaS compromise and ownership disputes are outside these standard WordPress recovery scopes.

02 / PRICE CONTEXT

How our current security pricing compares with the working benchmarks we publish

A security quote should be compared on the investigation and recovery work included, not only the headline amount. These are the reference figures currently shown on our security service page.

WordPress scopeOur guide priceBest fitWhat changes the quote
Preventative security audit A$600 benchmark A comparison point for review and hardening work Depth of access review, integrity checks, backup assessment and hardening
Malware recovery A$1,200 benchmark A comparison point for recoverable active compromise Number of infected components, persistence, credentials, database changes and verification
Deeper incident recovery A$2,000 benchmark A comparison point for repeated or more complex compromise Manual review, clean replacement, recovery planning, ecommerce or booking verification and observation time
Technical support reference Around A$180/hr A broader Perth technical-support comparison used for deeper rescue work Specialist experience, urgency, infrastructure access and the amount of manual investigation required

These figures are working comparison references, not a market-wide average or fixed tariff. A low quote can still be appropriate when the scope is small; the risk is a cheap cleanup that never investigates why the compromise happened.

03 / ONGOING PREVENTION

What should you budget after the site is clean?

Recovery solves the current incident. Ongoing care reduces the chance that overdue updates, failed backups or unnoticed functional problems become the next emergency.

WordPress scopeOur guide priceBest fitWhat changes the quote
Essential Care A$119/mo Lower-risk brochure and lead-generation sites Monthly maintenance cycle, fresh backup before scheduled updates, core page checks, uptime/security signals and routine housekeeping
Business Care A$359/mo Active service and marketing sites where forms, tracking and quicker support matter Fortnightly risk review, stronger verification, lead-path checks, reporting and a larger support allowance
Commerce Care A$749/mo WooCommerce, bookings or other transaction-led websites Weekly risk review, tighter recovery expectations, checkout/booking QA, transaction-path checks and priority maintenance handling

Hosting, domain renewal, premium plugin/security licences, paid backup storage, major development and active malware cleanup are not automatically included in a monthly care fee unless the proposal says they are.

04 / FIRST-YEAR BUDGET EXAMPLES

What can a realistic first-year WordPress security budget look like?

These examples combine one current Alpha security scope with twelve months of the most relevant care tier. They are illustrations, not automatic package requirements.

WordPress scopeOur guide priceBest fitWhat changes the quote
Healthy brochure site: audit + Essential Care A$1,788 first year A small site that wants a baseline and predictable monthly upkeep A$360 audit plus 12 × A$119 Essential Care
Recovered brochure site: malware cleanup + Essential Care A$2,148 first year A straightforward site recovered from an active compromise A$720 recovery plus 12 × A$119 Essential Care
Lead-generation site: incident recovery + Business Care A$5,508 first year A business-critical service site needing deeper recovery and closer maintenance A$1,200 incident recovery plus 12 × A$359 Business Care
Transactional site: incident recovery + Commerce Care A$10,188 first year A store or booking site where checkout, data and recovery speed matter more A$1,200 incident recovery plus 12 × A$749 Commerce Care

A healthy site may not need a recovery package, and a hacked site may need work beyond these examples. Third-party hosting, licences, legal/privacy work and specialist server forensics remain separate when required.

05 / RECOGNISE THE INCIDENT

Is your WordPress site actually hacked? These signals deserve investigation

One symptom does not prove the exact cause, but a combination of these signs is enough to stop treating the problem as a normal content or performance issue.

01

Unexpected redirects

Visitors are sent to spam, gambling, fake software, adult or unrelated pages that you did not create.

High-priority symptom
02

Unknown administrator users

New privileged accounts appear, existing roles change or you are unexpectedly locked out.

Review access immediately
03

Injected pages or search spam

Search results show unfamiliar pages, titles or keywords that are not visible in your normal navigation.

Check files and database
04

Security warnings

Browsers or Search Console report malware, hacked content, phishing or other security issues.

Do not ignore the warning
05

Unexplained file changes

Core, plugin or theme files have recent modifications that do not match a known deployment or update.

Verify integrity
06

Sudden mail or performance problems

The server starts sending spam, resource usage spikes, pages become erratic or scheduled tasks multiply without explanation.

Investigate persistence

06 / COMMON RISKS 01–06

The first six WordPress security risks we would reduce

Most incidents are easier to prevent when the website has fewer unnecessary components, controlled access and a predictable update routine.

01

1. Outdated WordPress core

Delaying core updates leaves known security fixes unapplied. Keep a current backup and update through a controlled process.

Patch known exposure
02

2. Outdated plugins or themes

Extensions have deep access to the site. Review updates regularly and remove components you no longer need.

Reduce vulnerable code
03

3. Abandoned software

A plugin can look functional while receiving no meaningful maintenance. Replace unsupported components before they become permanent risk.

Check maintenance history
04

4. Weak or reused credentials

A strong website can still be compromised through a reused admin, hosting, email or SFTP password.

Use unique credentials
05

5. No multi-factor authentication

Passwords alone give stolen credentials too much value. Add a second factor to privileged accounts where the stack supports it.

Protect high-value access
06

6. Too many administrator accounts

Every unnecessary privileged account expands the attack surface. Use the least privilege needed for each person.

Review roles

07 / COMMON RISKS 07–12

The next six risks are usually about hosting, recovery and visibility

Security is not only a login problem. The surrounding server, backup and monitoring decisions determine how much damage an incident can cause.

01

7. Unsupported PHP or hosting stack

An outdated runtime or weak hosting environment can undermine the application even when WordPress itself is current.

Keep infrastructure supported
02

8. Untrusted themes or plugins

Pirated or modified packages can contain hidden code and may not receive safe updates. Use trusted distribution sources.

Control software origin
03

9. No tested off-site backup

A backup that lives only on the same compromised account is not a recovery plan. Keep independent copies and test restoration.

Verify recovery
04

10. Unsafe file permissions or exposed configuration

Overly permissive access and exposed sensitive files can give an attacker more capability after an initial foothold.

Harden configuration
05

11. Insecure upload or custom functionality

Forms, upload features and custom code need validation, permissions and maintenance because they can create new entry points.

Review custom features
06

12. No monitoring or incident plan

Slow detection increases impact. Know who has access, where backups live and what happens if the site must be contained.

Prepare before failure

08 / FIRST RESPONSE

What should you do first if your WordPress site is hacked?

The first objective is controlled recovery, not rapid deletion. Random changes can destroy useful evidence, break the site or hide the original cause.

01

Preserve a recoverable snapshot

Capture the current files, database and relevant hosting information before destructive cleanup where access and safety allow. Label it as an incident copy so nobody restores it blindly later.

02

Contain harmful behaviour

Pause or restrict the affected site when redirects, phishing, malicious downloads or checkout risk could harm visitors. Coordinate containment with the host when server-level controls are needed.

03

Secure privileged access

Rotate WordPress administrator, hosting, SFTP, database and related account credentials as appropriate. End existing sessions and remove unknown privileged users.

04

Investigate before replacing

Check core integrity, extensions, database content, scheduled tasks, uploads, users and recent changes. The goal is to identify both malicious artefacts and the likely entry point.

05

Clean, patch and verify

Replace compromised software from trusted sources, remove persistence, update vulnerable components and test forms, login, booking, checkout and email before normal traffic resumes.

09 / DIY OR PROFESSIONAL RECOVERY

Can you remove WordPress malware yourself, and what should that decision cost?

DIY recovery can be reasonable for a technically capable owner with clean backups and a simple site. Business-critical or repeated compromise changes the risk calculation.

WordPress scopeOur guide priceBest fitWhat changes the quote
DIY investigation A$0 professional fee + your time/tools Simple non-critical site, strong technical skills and a known clean restore point Your ability to verify files/database, rotate access, identify the entry point and test recovery
Security Audit & Hardening A$360 No active compromise, but you want an independent baseline Useful when you are unsure whether configuration, access or abandoned software needs attention
Professional Malware Recovery A$720 Visible malware where preserving the current site is practical Reduces the risk of cleaning the symptom while leaving hidden persistence or the original vulnerability
Incident Recovery & Rebuild A$1,200 Repeated reinfection, complex changes or higher business impact More manual review, clean replacement, recovery verification and post-incident observation

DIY is not automatically cheaper if a failed cleanup causes more downtime, lost orders or reinfection. For ecommerce, bookings, membership data or possible personal-information exposure, escalation is usually more defensible.

10 / RECOVERY WORKFLOW

How malware should be removed from a WordPress site

The exact commands differ by host and incident, but the recovery logic should remain consistent enough that you can ask a provider what they are actually doing.

01

Establish a clean comparison

Verify WordPress core and compare plugins/themes against trusted versions. Unknown or modified code should be investigated rather than assumed safe because the site still loads.

02

Inspect data as well as files

Malicious redirects, spam and persistence can live in database options, posts, users or scheduled tasks. A file-only scan can therefore miss part of the compromise.

03

Replace compromised components

Reinstall affected core, plugins and themes from trusted sources where practical instead of hand-editing every unknown change. Preserve genuine custom work before replacement.

04

Remove persistence and rogue access

Delete unauthorised users, malicious scheduled behaviour and hidden code that can recreate the infection. Rotate credentials that may have been exposed.

05

Patch the cause and retest

Update or replace the vulnerable component, harden access, rescan and verify critical business functions. Recovery is incomplete until the site works safely after cleanup.

11 / BACKUPS

A backup is only useful if you can restore the right version without bringing the compromise back

Backups are central to WordPress security because they reduce recovery time, but an infected backup is still infected.

Keep at least one backup copy outside the same hosting account so a hosting compromise or account lockout does not remove your only recovery path. The schedule should match how often important data changes: a static brochure site can tolerate a different recovery point from a WooCommerce store receiving orders every hour.

After an incident, identify when suspicious activity began before selecting a restore point. Restoring an older copy can be useful when it is known clean, but you still need to patch the vulnerability and rotate compromised access or the attacker can return.

Test restoration periodically rather than assuming the backup job succeeded. A recovery plan should record where backups live, who can access them, how DNS and hosting are handled, and which forms, transactions or integrations must be checked after restore.

  • Back up files and database, not only media.
  • Keep an off-site or independently controlled copy.
  • Protect backup credentials and storage access.
  • Test a restore before an emergency forces you to learn.
  • Record the acceptable recovery point for orders, bookings and leads.

12 / ACCESS CONTROL

Passwords, administrator roles and multi-factor authentication deserve the same attention as plugins

Many website incidents begin with legitimate credentials used by the wrong person rather than a dramatic exploit.

Give each person their own account and the lowest role that lets them do their job. Shared administrator logins make it harder to revoke access, trace changes or know whose credentials were exposed.

Use unique passwords for WordPress, hosting, email, domain management and file-transfer accounts. If one reused password leaks elsewhere, separating credentials prevents that single event from unlocking the whole website stack.

Multi-factor authentication adds another barrier for privileged accounts and should be considered for administrators and other high-value access. When a staff member, contractor or agency relationship ends, remove or downgrade access promptly rather than leaving dormant privileged users indefinitely.

13 / UPDATE DISCIPLINE

Keep WordPress, plugins and themes current—but update in a way your business can recover from

WordPress documentation continues to recommend keeping core, plugins and themes updated because releases can include security fixes.

A sensible update process starts with a current backup and a quick review of what is changing. Low-risk maintenance can use automation selectively, while material updates on a busy lead-generation or ecommerce site deserve staging or stronger post-update checks.

Remove plugins and themes you no longer need instead of leaving abandoned code installed forever. Paid extensions also need valid licensing and a working update path; software that cannot receive updates should be treated as a future replacement problem.

After updates, test the functions that make the website commercially useful. A technically successful plugin update is not a business success if enquiry forms stop sending, checkout breaks on mobile or scheduled emails disappear.

14 / TRANSACTIONAL WEBSITES

WooCommerce, booking and membership websites need a tighter recovery standard

MORE DATA + MORE MOVING PARTS = MORE RECOVERY WORKA store is not clean just because product pages load; checkout, payment handoff, order emails, customer accounts and recent orders all need verification.

For retailers following our WooCommerce store setup for Perth retailers guidance, security should be part of the operating plan from day one. Transactional sites usually justify tighter backup intervals, more deliberate update testing and a clearer incident path because a restore can affect orders placed after the backup point. Our Commerce Care plan is A$749 per month for sites that need weekly risk review and transaction-path checks, while active malware cleanup remains a separately scoped recovery task.

15 / SEARCH WARNINGS

What if Search Console or a browser says the site is hacked or dangerous?

Removing the warning is the final consequence of a clean site, not the first objective. Fix the website and the cause before requesting review.

01

Confirm the security issue

Review the Security Issues information and sample affected URLs. A warning can relate to malware, hacked content, phishing or other harmful behaviour.

02

Clean every affected area

Remove injected content and malicious behaviour across the site, not only the example URL. Correct the vulnerability that allowed the compromise or reinfection remains likely.

03

Make the clean site crawlable

Do not hide the repaired pages behind a login, blocked robots rule or temporary noindex setting when the review system needs to verify them.

04

Request review when the site is ready

Use the Security Issues process after the entire affected site is clean and secure. Explain what was removed and what vulnerability or access weakness was corrected.

05

Monitor after the warning clears

Watch for reinfection, unexpected indexed pages and new security alerts. A successful review does not replace ongoing maintenance.

16 / AUSTRALIAN PRIVACY CONTEXT

A hacked website can become a privacy incident when personal information may have been accessed

Website cleanup and legal/privacy assessment are different jobs, and a technical recovery quote should not pretend otherwise.

Under Australia's Notifiable Data Breaches scheme, organisations covered by the Privacy Act may have notification obligations when unauthorised access, disclosure or loss of personal information is likely to cause serious harm and remedial action has not removed that risk. Coverage includes many organisations above A$3 million annual turnover and certain smaller entities or activities.

If customer, patient, financial, identity or other personal information may have been exposed, preserve relevant incident information and obtain appropriate privacy or legal advice. Alpha's standard security packages do not include legal breach assessment, statutory notification advice or forensic evidence prepared for litigation.

Technical recovery should still document what was found, what access was rotated, what was replaced and what remains uncertain. That record can help the business brief the appropriate adviser without confusing WordPress cleanup with a formal legal conclusion.

17 / AFTER CLEANUP

What should be hardened before a recovered WordPress site goes back to normal operation?

The recovery is not finished until the conditions that allowed the incident have been reduced and the business can restore the site again if something fails.

01

Rotate relevant credentials

Change compromised or potentially exposed WordPress, hosting, file-transfer, database and related privileged credentials.

02

Remove unknown and unnecessary access

Delete rogue users, review administrator roles and remove old contractor or staff access that no longer has a business purpose.

03

Patch or replace vulnerable software

Update core and maintained extensions, replace abandoned components and remove software that the site does not need.

04

Confirm independent backups

Create a clean post-recovery backup and verify that an off-site or independently controlled recovery copy exists.

05

Retest critical business paths

Check login, forms, email delivery, bookings, checkout, payment handoff and other revenue or lead-generation functions.

06

Set a monitoring cadence

Record who reviews updates, uptime, malware/security signals, admin access and backup health after the incident.

18 / BEFORE YOU APPROVE RECOVERY WORK

Ask a WordPress security provider these questions before giving them privileged access

A provider should be able to explain the recovery sequence and the limits of the engagement in language you can understand.

01

Will you preserve a snapshot first?

Ask what is captured before destructive cleanup and where that incident copy will be stored.

Protect recoverability
02

How do you look for persistence?

The answer should go beyond deleting one visible file and include users, database, scheduled tasks and altered components.

Find the whole incident
03

How will the entry point be addressed?

Cleanup without patching the vulnerable component or compromised access leaves the business exposed to repeat infection.

Close the cause
04

What functions will you test?

Make forms, ecommerce, bookings, email and other critical journeys explicit in the recovery scope.

Verify business impact
05

What is excluded?

Clarify server rebuilds, legal forensics, privacy advice, paid software, third-party accounts and additional engineering before work starts.

Know the boundary
06

What happens after delivery?

Ask about verification scans, observation time, reporting, maintenance recommendations and who retains account ownership.

Plan the next month

19 / PERTH BUSINESS CONTEXT

For a Perth business, security priorities should follow what the website actually does

A brochure site, lead-generation site and online store do not have the same recovery cost or acceptable downtime.

A local service business that depends on forms should prioritise uptime, email delivery and rapid lead-path testing. A retailer needs stronger attention around orders, customer accounts, payment handoff and backup frequency. Professional services may need a more careful privacy response if the site collects sensitive enquiry information.

The same principle applies to growth work around the site. If you are planning local SEO Perth, website SEO planning Perth or broader content improvements, security and maintenance should be settled first so new visibility is not being built on an unreliable installation. If you are still selecting a provider, our how to choose a web designer in Perth guide gives you a separate due-diligence checklist.

Perth CBDSubiacoFremantleJoondalupOsborne ParkCanningtonMidlandRockingham

20 / THE BIGGEST MISCONCEPTION

WordPress security is not the name of a plugin

TOOLS SUPPORT A PROCESS; THEY DO NOT REPLACE ITA scanner or firewall can be useful, but it cannot decide whether your backup is recoverable, whether a rogue administrator is legitimate, whether checkout still works or whether a privacy incident needs escalation.

The strongest security posture combines maintained software, controlled access, appropriate hosting, independent backups, monitoring, business-function testing and a known recovery path. If you are rebuilding the wider digital presence at the same time, our Wordpress web design Perth process keeps those technical foundations inside the website conversation. For broader Web Design perth or content marketing perth comparisons, Creative Agency X is the only external agency referenced in this guide.

WORDPRESS SECURITY AUSTRALIA FAQS

Questions Australian businesses usually ask when a WordPress site may be compromised

These answers focus on recovery order, cost, risk and what a business owner should expect from the cleanup process.

10 QUESTIONS

Clear answers to the decisions that usually affect cost, scope and ownership.

ANSWER

Preserve a recoverable copy first, contain harmful behaviour, secure privileged access, scan files and database content, verify WordPress core and extensions, replace compromised components from trusted sources, remove rogue users or persistence, patch the original entry point and then rescan and test the site. Do not assume deleting the first malicious file you find has removed the whole compromise.

ANSWER

Treat the hack as an incident rather than a normal website edit. Take an incident snapshot, rotate relevant credentials, investigate users, files, database and scheduled tasks, restore or replace clean components, fix the vulnerability, verify forms or checkout and monitor for reinfection. Search warnings should only be reviewed after the site is fully clean.

ANSWER

Yes if the site is simple, you have strong technical skills, you can preserve a backup, verify files and database changes, rotate access and confidently identify the entry point. Professional recovery is usually safer when the site handles orders, bookings, member data, sensitive enquiries, repeated reinfection or material business revenue.

ANSWER

Common signals include unexpected redirects, unknown administrator accounts, injected pages, search spam, security warnings, unexplained file changes, sudden server load, spam email or unfamiliar scheduled tasks. Any one symptom needs diagnosis because a normal plugin conflict or hosting problem can sometimes look similar.

ANSWER

Alpha WordPress Design Perth currently publishes A$720 for Malware Recovery and A$1,200 for deeper Incident Recovery & Rebuild. A preventative Security Audit & Hardening package is A$360, with additional approved security engineering at A$90 per hour. Final scope depends on persistence, access, affected components and the business functions that must be verified.

ANSWER

Our current guide timing is about 1–2 business days for Security Audit & Hardening, 2–4 business days for Malware Recovery and 3–7 business days for Incident Recovery & Rebuild. Access problems, repeated infection, large custom sites, ecommerce and server-level issues can extend the scope.

ANSWER

A known-clean backup can be an excellent recovery source, but restoration alone is not enough. You still need to understand when the compromise began, patch the vulnerable component or account, rotate relevant credentials and verify that the restored site is clean. Otherwise the same entry point can reinfect the restored copy.

ANSWER

A reputable scanner or firewall can support a wider security process, but no plugin replaces updates, unique credentials, multi-factor authentication, least-privilege access, maintained hosting, independent backups, functional testing and a recovery plan. Choose tooling around your actual site risk rather than installing several overlapping plugins.

ANSWER

Contain the incident quickly, preserve an incident copy, secure privileged access and investigate both WordPress and store-specific functionality. After cleanup, verify customer login, cart, checkout, payment handoff, order creation, order emails and recent data before returning to normal operation. Possible personal-information exposure should be assessed separately.

ANSWER

First clean the entire affected site and fix the security weakness that allowed the incident. Then use the Security Issues process in Search Console to request review where applicable, explaining what was removed and what was corrected. A review should be requested only when the site is clean and accessible for verification.

BUILD VISIBILITY ON A WEBSITE YOU CAN ACTUALLY RECOVER

Once the security baseline is stable, connect the website, search strategy and content plan instead of treating them as separate systems.

Use our local SEO guide for Perth search visibility or compare broader content support through Creative Agency X. If the site is actively compromised, start with security recovery before spending more money driving traffic to it.