Wordpress can easily be hacked what a shame on this worldclass best cms in the world.
The most vulnerable doors a hacker can get into are; your wp-directory, wp-content, and wp-config.php and your admin login url.
Your webhost not they have really good security to block hackers.
So for this hide your wp-directory, hide the wp-config file, use for the Database a different prefix then wp, use a different login name as admin and hide your admin login url, use the stop enumeration plugin, with that the hacker can not find out your admin name.
Then you have a good layer of security, the hacker not can see your directory files, not knows your admin name and not knows the login url.
When your wp site is hacked, then your database is hacked (through wp-config.php DB credentials) you can import this hacked database to save your pages on new webhost, but after that you must delete the hacked database, without that the hacker comes again, or your redirects to spammy porn sites
coming back again....
I see on my clients website (small site) 5 products with woocommerce, what a complicated setup, his site was hacked. He moved to ionos (germany) webhost with wordpress and now all is fine.
But I must setup his small site completely, because after migration (only the basic wp-content folder) managed wordpress has limit data sizes for uploads, all content and images are gone, same with the simple css plugin codes and all the woocommerce settings ! This make no sense to have a backup and doing migration to another host- right?
A real pain in the ass, the wp team brings up new updates every second month, but not improved the system backup process when you must make backup and migrate your site to new domain or webhost.
Often these free backup plugins stop the backup when the size is too big (your site). A big leak hole....
On the other side, now I work on my clients side, the ionos managed wordpress is fantastic, easy to use, easy flat dashboard, you have access to file manager, database, email and domain settings claro in their dashboard, but the most important part is their backups- daily, when your site is hacked or crashed, you see in the dashboard you backup from yesterday, one click , wait 3 minutes and voila! You have a new site with all the content and images, plugins etc, etc.... But it has the old previous database, to stop a hacker to hack in again, change the database prefixes, login url and the login credentials in the database and you are fine.
Yes his site runs fast the slim ionos wordpress dashboard is fast but all managed wordpress hositng has limitations.