I have a system for assessing the security of a WordPress website. The first thing i do is log into the back end and see what plugins, themes, and core files need to be updated. This is the most common exploit, much like not updating apps on your phone and computer. After that, i like to run an initial scan of the system using various tools to see if there are open doors that could be exploited. Often times website are hacked and users don't even know it because the hack is hidden from plain site.
My clients obtain great benefit from this service knowing their website is not hijacked and is working for them, not some nefarious hacker.