A slow or compromised site costs real money, in lost conversions, in search rankings, in the time it takes to clean up after a hack. This is about fixing that, and making sure it does not happen again.
Yes. Cleanup includes finding and removing the malware, closing the vulnerability that let it in, and hardening the site so it does not happen again.
It depends on the starting point, but most neglected WordPress sites have significant room: unoptimized images, no caching, and bloated plugins are the usual culprits, and all three are fixable.