Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Google Is Showing Spam Pages Under Our WordPress Site's Name. How Do We Clean It Up?
Problems We Solve

Google Is Showing Spam Pages Under Our WordPress Site's Name. How Do We Clean It Up?

WordPress hacked and spam pages in Google under your domain? SpiderHunts removes the infection, closes the way in and clears the junk from search results.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

When searches for your business show pages about pills, replica goods or gambling in foreign languages, the site has almost certainly been compromised and is generating spam pages for search engines. We remove the malicious code and backdoors, find and close the way in, rebuild from clean sources where needed, and use Search Console to get the spam URLs dropped from Google.

Your name, somebody else's pages

A customer mentions that your site showed up in Google with a strange title. You search for your company and see results under your domain in Japanese characters, or about cheap medication, or casino bonuses. Clicking one might show your normal homepage, or might redirect to another site entirely. Visiting the site directly from your office, everything looks fine.

That last detail is what confuses people. Much of this kind of malware shows spam only to search engine crawlers or to visitors arriving from Google, so the owner sees nothing wrong.

How the spam got there

Attackers are not interested in your business. They want a domain Google already trusts, so they can use it to rank their pages. WordPress sites are targeted in bulk by automated tools looking for a known weakness.

Common way inWhy it works
Outdated plugin or theme with a published vulnerabilityAutomated scans find it and exploit it without anyone logging in
Weak or reused admin passwordPassword lists from other breaches are tried against the login page
Nulled (pirated) premium pluginIt often ships with a backdoor already inside
Old admin accounts for former staff or developersNobody notices an extra login using them
Other sites on the same hosting accountOne compromised site spreads to its neighbours

Once in, the attacker typically leaves several backdoors, hidden files that let them back in, so deleting the obvious spam without finding those just means it returns.

What it is costing you

Google may label the site as hacked in results, or show a warning before visitors reach it. Search Console can report a security issue and your genuine pages can lose ranking while thousands of spam pages compete with them. Customers who see the results lose trust. Your host may suspend the account, and email from your domain can start landing in spam if the server has been used to send it.

How we clean it up

  1. Take a full copy of the site as it is, for evidence and so nothing is lost if something goes wrong during the clean.
  2. Scan the files and database for malicious code, unknown files, modified core files and injected content, comparing against clean copies of WordPress, plugins and themes.
  3. Replace WordPress core, plugins and themes with fresh copies from their official sources rather than trying to patch infected ones.
  4. Remove backdoors, rogue admin users, malicious scheduled tasks and injected database entries.
  5. Find the way in by checking server logs and versions, and close it: update or remove the vulnerable component, reset every password and security key.
  6. Harden the site: two-factor login, limited admin accounts, file editing disabled in the dashboard, and sensible file permissions.
  7. In Search Console, request a review if Google has flagged the site, submit a clean sitemap and have the spam URLs return a gone status so they drop out of results.
  8. Set up monitoring for file changes and new admin accounts, so any return is spotted quickly.

If the site is too badly compromised to trust, we rebuild it on clean hosting from the content, which is sometimes quicker and safer than cleaning.

What you are left with

A clean site with the way in closed, fresh software and a short record of what happened and what changed. Spam URLs return an error and drop out of Google over time as it recrawls. Your team has their own logins with two-factor, and someone is alerted if files change unexpectedly.

Signs your site has been hijacked

  • Google results for your domain show foreign or spam titles
  • Search Console reports a security issue or thousands of unfamiliar URLs
  • Visitors from Google are redirected somewhere else
  • Admin users appear that nobody created
  • Your host has warned about malware or suspended the account
  • Plugins have not been updated in a long time

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Can a security plugin fix this on its own?

Scanners help find infected files, but they often miss backdoors and do not tell you how the attacker got in. Cleaning without closing the way in usually means reinfection.

How long will the spam stay in Google?

It drops out as Google recrawls the removed URLs, which happens at Google's pace. Search Console tools can speed up the most visible ones.

Do we need a new website?

Usually not. A thorough clean and fresh core and plugins are enough. We only suggest a rebuild if the site cannot be trusted after cleaning.

What affects the cost?

How widely the infection spread, how many sites share the hosting account, and whether a rebuild is needed.

What do you need from us?

Access to the hosting, WordPress admin, Search Console and DNS, and any history you know of changes or developers.

Keep reading

More on Problems We Solve

Start here

Spam appearing under your domain?

Tell us what you are seeing in Google and on the site, and whether you have Search Console access. We will find out how far it has spread and tell you honestly what the clean-up involves.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →