Thank you for responding @bcworkz and helping with placing us in the correct forum.
I agree that the site got hacked (it happens) but while it was being built/developed? Then, for us to inform the developer right away (a few days after delivery/launch) and provide the reports that a layman person received by clicking on a simple link in the dashboard on the (Yoast/Ryte) plugin that the developer installed. I’m sure you can understand why we’re so frustrated.
The hack obviously got worse as the hosting company alerted us today and when I contacted the developer, the developer sent back an email that it’s ONLY a ‘sales pitch’ by the hosting company. If this was a private developer I got off some 3rd party website or freelancer site, I guess it would be more on me but this is a business/developer with a presence on the internet as a WP Developer with a large portfolio.
We updated the plugins & changed the PW’s (strong) but would you be kind and step me through:
“Change the salts in wp-config.php to force anyone currently logged in to need to log in again.”
Thank you very much, in advance.