Spam pages have appeared in my search results
You type your store's name into Google and pages you never wrote show up, often on topics unrelated to your business: this is a specific infection technique, targeting your site's search rankings rather than its visitors directly.
What a "site:example.com" search reveals
- Dozens, sometimes hundreds, of indexed pages you never created
- Titles in English, Russian or Chinese while your store runs in another language
- Recurring topics: online pharmacy, casino, sports betting, counterfeit branded goods
- The links open normally when Google displays them, but return an error or different content when clicked from another context
- A sudden drop in legitimate organic traffic, as Google starts to downrank the whole domain
- Search Console flags a manual action or a spike in crawl errors on unknown URLs
How SEO spam works
This technique has a precise name: SEO spam, or "SEO spam injection". It doesn't try to trick your visitors directly, it exploits the reputation and age of your domain with Google. A domain active for several years, already indexed and trusted by the search engine, is a valuable resource for getting content to appear quickly in results, rather than starting from a brand-new domain with no history.
In practice, an attacker who has gained access (usually through an outdated plugin or theme) automatically generates hundreds of content pages, each targeting commercially valuable keywords: over-the-counter medication, online casinos, replica luxury goods. These pages are sometimes invisible to a normal visitor and only show to indexing bots or to visitors coming specifically from Google, which is why a merchant browsing their own site often notices nothing unusual.
The most common entry point remains a plugin or theme that no one updates any more. According to Sucuri's 2023 Hacked Website & Malware Threat Report, 39.1% of compromised CMS applications were out of date at the time of infection, and 13.97% of compromised sites had at least one vulnerable plugin or theme still present at the time of remediation. That's consistent with what's seen with SEO spam: an extension abandoned long ago, installed for a minor feature, stays reachable online while no one keeps an eye on it any more.
How to confirm the scale of the problem
-
Run a "site:yourdomain" search
This Google command lists every page indexed under your domain. It's the fastest way to gauge how many injected pages actually exist.
-
Check the coverage report in Search Console
The number of URLs submitted in your sitemap and the number actually indexed should roughly match your catalogue and content pages, not several hundred unknown URLs.
-
Compare your active plugins and theme against their latest official version
A WooCommerce plugin or WordPress theme that hasn't been updated for a long time, even if it seems to work fine, is the most likely suspect.
-
Check recently modified files on the server
Spam pages usually rely on one or more injected PHP files that generate the content on the fly, often inside a theme or plugin folder rather than the WordPress core.
Going further
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.