This URL still looks like a WordPress security emergency guide. People arriving from Google may have a hacked admin and a domain they also care about. Both problems can be true. Only one of them is the asset.
I’m Mostapha. I buy and sell names from Morocco. A malware plugin can make a decent domain look poisonous on Wayback and in a buyer’s browser. It can also be a reason to walk away if the name was never strong. Score the letters first: Domain Value Checker. Then decide whether you are cleaning a shop window or spending the weekend on a leftover.
A hack is not a valuation
Buyers who can pay retail will type the name, open the site, and sometimes open Wayback. Pharma spam, a fake login, or a browser warning does not lower the structure of a short .com. It lowers trust. Trust is what closes. I have seen names that would pass the checker sit unsold because the first snapshot looked like a casino. History still comes before hardening: five steps before you buy.
If the checker already says hyphen, stuffing, weak TLD, do not “secure WordPress” to rescue it. Let the host lapse. Keep or drop the domain on its own. That is the same order as when the website is the problem.

If you are keeping the name
Lock the registrar before you fight files. 2FA, transfer lock, do not change nameservers in a panic. A hijack during an incident is worse than a spam plugin. Practical lock steps: domain security.
Email to the domain may still work while WordPress is on fire. DNS is not the CMS. Leave MX alone unless the mailbox itself is the abuse source.
Clean the site without performing on the live hostname
Copy first. The public name should not display your malware scan in progress. That is the staging lesson: don’t test on the domain you want to sell.
- Take a backup you might never restore (for forensics), then a clean copy to staging.
- On the copy: default theme, disable all plugins, reset salts, replace infected core files with a fresh WordPress package of the same version.
- Delete unused admin users. One leftover “support” account is enough to reopen the door.
- Rotate the database password and the registrar email. If the attacker had admin, they may have had the mailbox that resets the registrar too.
- When the copy is clean, put a boring lander or a minimal site on the live name. Do not redeploy a jungle of plugins “because it was the old blog.”
Search Console and hosting malware flags should be cleared before you list the name. Selling “aged WP + DR” with an injected hack is how you inherit a dispute. For drops with a dirty profile use expired-domain valuation, not a security checklist as perfume.
What to tell a buyer
If you cleaned it, say so in one sentence: the name was compromised, it was rebuilt, here is Wayback before and after. Do not hide snapshots. Do not ask them to trust a WordPress login. Push at the registrar. Price the name with the checker, not the recovered CMS: before you sell.
If you cannot clean it quickly, park, or transfer the name away from the infected host. The letters can still be sold. The install does not have to come along.

Decision
- Run the checker. Weak name: stop paying to “harden” it.
- Strong name: lock the registrar, copy the site, clean the copy, put something boring on the live hostname.
- Disclose history. Buyers will find it anyway.
WordPress security errors are a server event. Unsellable is a trust event. This page keeps the old URL so the search result still lands. The job is to keep you from treating a malware plugin as if it were the domain.