Confirm the site is no longer actively compromised
Review users, administrator access, themes, plugins, files, database content, scheduled tasks, hosting access and connected services. Update or replace vulnerable components and rotate affected credentials.
The public recovery report should not reveal exact server paths, keys or controls that would help an attacker.