Someone may have put links, pages, or thousands of junk categories on your website that visitors never see, but search engines do. Here is how to check, what it costs you, and how to put it right, one click at a time.
Links to other people's websites have been added to your pages, usually gambling or pharmacy sites. They are styled so that nothing appears on screen. Your website looks completely normal to you and to your customers. A heavier version of the same thing adds whole pages to your website, hundreds of them, wearing your logo and your menu.
It does not always look like that, and this is the part that catches people out. On some sites nothing is added to your posts or your pages at all. Instead the categories and tags get filled up, by the thousand, and WordPress publishes a web address for every one of them. On others a page you already had is quietly rewritten, so the address on your business card still works but what is on it is not yours. The checks below look in all of those places, because looking in only one of them is how this goes unnoticed for years.
Search engines do not look at the screen. They read the code behind the page, and there the links are perfectly visible. That is the whole point of it. Whoever did this is being paid to place links on real, established business websites, because a link from a genuine local firm is worth something to them.
Nobody picked you. This is done by software that works its way across the internet looking for sites running an out of date part, and it happens to thousands of small business websites. It is not a reflection on you, and it is not a reflection on whoever built your site.
Do not take anyone's word for this, including mine. You can see it with your own eyes, you do not need to install anything, and the first check takes about a minute.
There are four checks below. You only need one of them to find something. They look in different places because this is not one single fault: there are several kinds, and a kind that hides from one check will often walk straight past another. If you have ten minutes, do all four.
Start with this one. It is the only check that works on every kind, it needs no login, and it reads your own file rather than anybody else's opinion of your site.
What gives it away is usually the shape rather than the words. One real site we looked at had three blog posts, sixteen pages, and one thousand eight hundred and thirty eight categories. You do not need to know anything about websites to see that is wrong. Anything in a language you do not publish in is worth a second look as well, and so is a number far larger than the site you recognise.
One caution, and it matters. A sitemap lists what your website advertises, not what it currently serves. Some of these get half cleaned up, so an address can still be listed after the page behind it has gone. Open two or three of the odd ones before you decide how big the problem is.
The second check asks Google directly what it has stored under your name. It is the one that shows you what a customer would find.
If Google shows you pages on your own website about casinos, in any language, that is the problem, and you are looking at exactly what a customer would find. This works on a phone, needs nothing installed, and cannot be fooled by anything hidden. One lone result is worth opening before you worry, because Google can briefly keep showing a page that has since been removed; a pile of them, especially in other languages, is the real thing.
Nothing coming back is not the all clear. Google will not show you a page that has been marked hide from search engines, and it may simply not have got round to a page yet. We have seen a site with well over a thousand junk addresses on it where this search returned nothing at all. Do the sitemap check as well.
The second check looks inside the page itself. It catches links that are hidden rather than published as pages, so it is worth doing as well, but it is fiddlier and one wrong step gives a falsely clean result.
A clean page finds nothing. A hit is usually dozens. Run it again with slots, viagra, payday and poker. A caution on short words like bet and spin: they hide inside ordinary English, so "better" matches bet and a booking page may say "book a slot". One or two of those are innocent. Thirty matches naming websites you have never heard of are not.
This sounds too obvious to be worth doing, and it is the one people skip. On some sites the business heading and menu survive while the content underneath has been replaced with casino articles, so the page still looks like yours at a glance. If you have not actually read your own news page this year, read it now.
While you are here, open one or two of any odd addresses the first two checks turned up. Two things to watch for. One is a black screen with a spinner on it. The other is a gambling site filling the whole window, with your own address still in the bar and none of your website around it. Either one is a particular kind, and it has its own steps further down. Do not click anything inside that window.
If any check finds something, do not panic and do not rush. Nothing is on fire. It has most likely been there for months, and an hour spent doing this properly beats ten minutes spent doing it twice. If the checks disagree, believe the one that found something: hidden content is designed to be missed, so finding nothing is never proof on its own.
And if all four come back with nothing. That is genuinely good news and it is the likeliest reading. It is not a guarantee, and I would rather say so than pretend otherwise. There is at least one kind that hides from all four at once. It is a page marked hide from search engines, carrying no readable web address of its own, leaving your front page alone, and pulling a casino in from somebody else's server only when somebody opens it. What you can honestly say after these four checks is that the common kinds are not there. That kind has its own section, immediately below: When deleting the pages is not the end of it.
The four checks above look for spam sitting on your website. This section is about something that can be sitting underneath it, and it is here rather than further down because it changes what you do next. It is not a fifth check of the same kind. It is a check to do before you delete anything, and again afterwards.
On some of these sites, as well as the casino pages themselves, a few extra lines have been added to the page. Those lines contain no gambling words and no web address you could read. When somebody opens the page, they build an address out of four separate pieces, call a computer somewhere else, and ask it to send today's content over. The content is not kept on your website. Only the instruction to go and fetch it is.
Here is why that matters more than it sounds. Deleting the casino pages is right and you should do it. But what you have deleted is your copy of what was sent. The few lines that do the fetching are a separate thing, they hold none of the words you searched for, and they were never in the list of posts you just cleared. The site goes quiet, the sitemap empties, everybody agrees it is sorted, and on some sites the part that produced those pages is still installed.
We found this on 44 of the 114 websites we could look inside, so getting on for four in ten. Two things to say about that number before anyone repeats it. Every one of those sites was already known to be carrying the spam, so it is not a rate for websites in general. And we opened an average of fewer than two addresses per site, so where we found nothing, the honest version is that we did not find it on the addresses we opened.
On 79 of the 86 pages we found it on, the page itself was an ordinary, full sized casino article that loaded perfectly normally, the sort the sitemap check and the Google check turn up by the hundred. So this is not instead of the spam you can see. It sits on top of it, and none of the four checks can tell you whether it is there. The other seven are the ones worth knowing about. On four sites the same lines came back on an address that was all but empty, or that reported not found, or that reported a server error. A deleted post cannot serve anything at all, so on those sites something else was answering.
A hit is unmistakable once you have seen one: the words data:text/javascript;base64, followed by hundreds or thousands of letters and numbers, no spaces, nothing you recognise, running off the side of the screen. That is a set of instructions written in a form a person cannot read. There is no web address in it you would recognise either, because the one it calls is cut into four pieces and only put back together as the page opens. That is exactly why searching a page for casino will never find this part of it: the words the source check looks for genuinely are not in it, on a clean site and an infected one alike.
Two things not to read too much into. data:image is innocent and extremely common: it is how ordinary websites tuck small icons into a page. It is the text/javascript version that matters, because that is instructions rather than a picture. And finding nothing here is not the all clear, no more than the four checks above were. It means this one shape is not on the address you looked at. There is a version of the same trick that is not scrambled at all, which is what the second search is for, and there will be versions nobody has seen yet.
One tell that needs no code at all. If you open an address of yours and it says not found, look at the tab along the top of the browser. If the tab is advertising a casino while the page says not found, then that not found page is theirs rather than yours, and the site is still carrying something.
Nothing about the order of the fix below changes. It gets stricter, that is all.
Take the backup in step 1 before you remove anything. Saving a copy of the code you found is worth doing as well, but that is evidence for whoever fixes it, not a backup. They are two different jobs and you want both.
Clear the pages as step 3 describes, then run this check again on the same addresses. If it comes back clean, the lines went out with the posts, which is the outcome you want. If it still answers, or the address now says not found and still answers, then something in the site's own code is doing it, and no amount of deleting posts will reach that.
Do not go hunting through the site's code files yourself. That is the same rule as everywhere else in this guide, and it matters more here, because finding out that a deletion did not hold is exactly the thing that tempts people into editing files they do not understand. Run the scan in step 4, do not skip it, and hand over the saved report along with your list of addresses.
Assume the passwords are already somebody else's. Anything that can add code to your site can usually read what is on it. Do step 6 properly, and do it after the clean up rather than before: site administrator, hosting, FTP and database.
If you are handing this over, give them this paragraph. The served HTML carries a data:text/javascript;base64, script. Decoded, it assembles a remote script host from four string fragments and document.writes a script tag in, alongside an image beacon to a third party hit counter. Responses come back no-store, and on some sites it is served on 404 and 500 as well as 200, which puts the injector in front of the theme rather than in a post. Places worth looking, and this part is a suggestion rather than anything seen from the inside: post content and the options table in the database, must-use plugins, the theme's functions file, anything recently changed in the plugins folder, the 404 template, .htaccess and any rewrite rules, and stray files in folders that should hold none (injected addresses have turned up living under wp-includes). If the site is not WordPress, the same list applies under different names.
And the limits of this, because they are real. These sites have only ever been looked at from the outside, the way any visitor sees them. Nobody's server has been examined, so where this is injected from is inference and not measurement. What is measured is what the pages sent back: 212 addresses across 115 sites already known to be carrying spam, checked over five runs on 23 August 2026.
These attacks almost always leave a way back in, hidden in a file somewhere. Today it is being used for gambling links because that is what pays this month. The same access could be used to read what people send through your contact form, to send your visitors somewhere else, or to lock you out of your own site later. This is why deleting the links on their own does not fix it.
Google can decide a page it does not trust should not rank, and it can start associating your site with gambling instead of your actual work. It may also put a line under your search result saying the site may be hacked. Customers looking for you may simply not find you.
The heavier version of this puts whole articles on your website, in another language, about online casinos, wearing your logo and your menu. Someone checking you out before they book can end up reading one.
Hosts run their own scans, and a site serving spam can be suspended with very little warning. Then the website is gone until it is cleaned up.
Three separate things are easy to mistake for one thing, and they can be held by three different people. If someone built your site years ago, some of these may still be in their name.
Search your email for renewal receipts. Registrars and hosting companies send one every year. Whoever's name and card is on those receipts is who controls it. If you cannot find any, someone else is paying, and that is worth knowing on its own.
Try to reset your own password. Go to your website address followed by /wp-admin and click the lost password link. If the reset email arrives in your inbox, you control the site. If it does not, you do not, and that is your answer.
If it turns out the domain is registered to a builder you have lost touch with, deal with that first. It matters more than the links do, because when a domain lapses it takes the website and every address at your own name with it.
In this order, because the order matters. Each step below has a plain description, and under it an exact list of where to click, written for someone who has never been behind their own website. Read the step, then open the clicks.
These steps assume WordPress because most affected sites run it, but this is not a WordPress-only problem. Any site with a login and software behind it can be attacked the same way. If yours is built on something else, the steps still apply in the same order; only the names of the tools change.
A backup is a complete copy of the website, downloaded to your own computer, so that a mistake later costs you nothing. Do this before touching anything at all.
If you cannot log in at all, that is not a dead end. Go back a section: the password reset test tells you who can, and your hosting company's support chat can reset access for the account holder. Helping with a hacked site is a normal request for them, they deal with it every day.
You want two logins before going further: the site's administrator login from step 1, and the login for your hosting control panel. Cleaning up without hosting access is working with one hand.
Stuck at this step with no route to either login? This is the earliest sensible hand-over point. Everything you have learned so far, who holds what, is exactly what a professional needs on day one.
What you are removing depends on which check found it, and there is more than one kind. Fake posts are easy to spot and delete in bulk. Fake categories and tags are just as easy once you know they exist, and they are the ones people miss, because nothing looks wrong under Posts. Hidden links are the hardest to find by hand, and it is completely fine to run the scan in step 4 first and let it point at the file they live in, then come back here.
If you found posts or pages you did not write:
If you found hundreds of categories or tags:
This is the kind that hides in plain sight. Your posts and pages are untouched, so the place you would naturally look is clean. What was added is categories and tags, and WordPress quietly publishes a web address for every one of them.
Deleting a category does not delete a single one of your posts. This is the bit worth knowing before you start, because nobody sensible bulk deletes two thousand things without it. A post that loses its only category is simply moved to your default one, usually called Uncategorized. Nothing you wrote is lost. You will also find you cannot delete the default category itself, and that is normal.
Two things that will throw you. First, if you open one of these addresses in a browser it may well say Nothing Found, because there is no article behind it, only the address. That is not proof it has gone: check the list in the admin screens, not the page. Second, if you have someone technical about, the command line tool WP-CLI clears the whole lot in one line and will save you an afternoon. Worth asking before you start clicking.
If your front page or news page has been taken over:
If one of your own pages has been rewritten:
This one is nastier than it sounds, because the address stays the same. A page you hand out on a card still opens, but what is on it is not yours any more. Open Pages, find the page by its name, and look at the revision history in the editor sidebar: you can usually restore the last version you wrote. If there is no earlier version to go back to, that page needs writing again, and the backup in step 1 is the reason you took it.
If it looks like somebody already half cleaned it:
If your sitemap lists thousands of addresses but the ones you open give a not found error, someone has removed the pages and left the mess behind. Look at what that error page itself says. If it carries a casino heading rather than your own, the error template was replaced too, and it is still theirs. But be careful with the opposite result: an error page that looks completely normal, with your own wording on it, does not mean the address is harmless. The fetching code described in When deleting the pages is not the end of it is served on not-found pages too, and a browser still runs it there. Either way, treat the site as still compromised and carry on through the rest of these steps. Your host or whoever built the site may have done a partial clean without telling you, so it is worth asking them before you assume the worst.
If an address of yours opens a black screen, or a casino filling the whole window:
This is the hardest kind to get rid of and the easiest to recognise once you have seen it. The address is yours and your name is still in the tab at the top. What loads is somebody else's gambling site, pulled in live from another server as the page opens. The giveaway is that none of your own website is around it: no header, no menu, no footer, just the one thing edge to edge.
Two things worth knowing before you judge how bad it is. Some of these pages are marked hide from search engines and some are not, so Google may show you nothing at all while they are sitting there serving perfectly well. And whoever put it there is not paying for the gambling site you can see: your address is passed along to it, so somebody is being credited for sending your visitors on. That is why it is worth removing even if no customer has ever mentioned it.
If you are handing this to someone else, give them this sentence. The page bypasses the theme completely, so whatever is producing it runs before the theme does. Ask them to look at must-use plugins and at anything recently changed in the plugins folder, as well as the post itself. That one sentence will save them an hour, and if you cannot get it to stop yourself, this is the sensible point to hand over. It is not a failure on your part. This kind defeats every check on this page except opening it and looking.
If you found hidden links in the code:
If the results screen frightens you or you are not sure what a line means, stop and hand over here rather than guessing. A finished scan report is genuinely useful work; you have done the diagnosis for them.
WordPress itself, every plugin, and the theme. These attacks get in through out of date parts, so this step is what closes the original hole.
A paid theme will quietly stop updating when its licence runs out, which leaves known holes sitting open for years. If your theme shows an update that will not install, or has not updated in years, check whether it is still paid for.
Site administrator, hosting, and any other accounts on the site. Whoever got in may have collected the old ones, so this only counts if it happens after the clean-up, not before.
And never send a website or hosting password in an ordinary email, to anyone. If someone helping you needs access, they should have a better way to receive it, and a separate account of their own that you can remove afterwards.
Google Search Console is Google's own free tool for website owners. It tells you if Google has flagged anything, lets you ask for a fresh look now the spam is gone, and means you hear about it first if anything ever comes back.
Here is the part that usually gets left out. Cleaning the site deals with today. It does not deal with why it happened.
These attacks find websites running something out of date. If nothing changes about how the site is looked after, the same scan finds it again, and the whole thing repeats. Someone needs to be applying updates, and that someone has to be a real person with a real login, not a good intention.
So the honest question after the cleanup is a simple one. Who is going to update this, and how often? If the answer is nobody, the fix will not hold.
And a note on what this guide can honestly promise: it helps you confirm the symptom and take the safe first steps. A clean Google result or a finished scan cannot certify that every way back in has gone. The same ground is covered, more formally, in WordPress's own hacked-site guide and Google's guidance for hacked sites, so you do not have to take any of it on my word alone.
Sometimes cleaning up is the wrong call, and it is worth being straight about when.
If nobody can get into the site and whoever built it has moved on, if it has been cleaned before and it came back, or if it has sat untouched for years and realistically will again, then you are paying to patch something that will keep breaking.
It is also worth asking whether the site needs to work the way it does. A five page site for a trade business is often built on a system designed for publishing several articles a week, and that system is the part that needs constant maintenance. A simpler site with no login and no plugins cannot be broken into this way, because there is nothing to break into, and it costs almost nothing to keep running.
The test is honest and quick. Do you actually change the site yourself? If you update prices or post news most months, you need a system that lets you, and you need somebody maintaining it. If you have not touched it since it was built, you are paying maintenance on a convenience you have never used.
Everything above is yours to use, whether you do it, your builder does it, or someone else does. Nothing in this guide is held back.
If you would prefer to hand it over, I am happy to take a look and tell you what I find, and what it would cost, before anything is agreed.