# Spam pages have appeared in my search results

> You type your store's name into Google and pages you never wrote show up, often on topics unrelated to your business: this is a specific infection technique, targeting your site's search rankings rather than its visitors directly.

- Source canonique : [https://allaux.fr/en/securite/pages-de-spam-dans-google](https://allaux.fr/en/securite/pages-de-spam-dans-google)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Measure the extent first: a site: search on your domain, then the Google Search Console indexing report, which lists indexed addresses you never created. Run the URL inspection tool live test on one of them: it shows what the crawler sees, while your own browser often shows nothing. Deleting the pages without dealing with the injection brings them straight back.

## What a "site:example.com" search reveals

- Dozens, sometimes hundreds, of indexed pages you never created
- Titles in English, Russian or Chinese while your store runs in another language
- Recurring topics: online pharmacy, casino, sports betting, counterfeit branded goods
- The links open normally when Google displays them, but return an error or different content when clicked from another context
- A sudden drop in legitimate organic traffic, as Google starts to downrank the whole domain
- Search Console flags a manual action or a spike in crawl errors on unknown URLs

## How SEO spam works

This technique has a precise name: SEO spam, or "SEO spam injection". It doesn't try to trick your visitors directly, it exploits the reputation and age of your domain with Google. A domain active for several years, already indexed and trusted by the search engine, is a valuable resource for getting content to appear quickly in results, rather than starting from a brand-new domain with no history.

In practice, an attacker who has gained access (usually through an outdated plugin or theme) automatically generates hundreds of content pages, each targeting commercially valuable keywords: over-the-counter medication, online casinos, replica luxury goods. These pages are sometimes invisible to a normal visitor and only show to indexing bots or to visitors coming specifically from Google, which is why a merchant browsing their own site often notices nothing unusual.

The most common entry point remains a plugin or theme that no one updates any more. According to Sucuri's 2023 Hacked Website & Malware Threat Report, 39.1% of compromised CMS applications were out of date at the time of infection, and 13.97% of compromised sites had at least one vulnerable plugin or theme still present at the time of remediation. That's consistent with what's seen with SEO spam: an extension abandoned long ago, installed for a minor feature, stays reachable online while no one keeps an eye on it any more.

## Why you don't notice it while browsing normally

> Many SEO spam injections only display the injected content to indexing bots (via the User-Agent) or to visitors arriving directly from a Google result. A merchant testing the site by typing the address directly will often see nothing.

## How to confirm the scale of the problem

1. **Run a "site:yourdomain" search** — This Google command lists every page indexed under your domain. It's the fastest way to gauge how many injected pages actually exist.
2. **Check the coverage report in Search Console** — The number of URLs submitted in your sitemap and the number actually indexed should roughly match your catalogue and content pages, not several hundred unknown URLs.
3. **Compare your active plugins and theme against their latest official version** — A WooCommerce plugin or WordPress theme that hasn't been updated for a long time, even if it seems to work fine, is the most likely suspect.
4. **Check recently modified files on the server** — Spam pages usually rely on one or more injected PHP files that generate the content on the fly, often inside a theme or plugin folder rather than the WordPress core.

## Going further

- **Abandoned plugins and extensions** — Why this is the leading real-world entry point on WordPress. ([/securite/modules-et-extensions-abandonnes](/securite/modules-et-extensions-abandonnes))
- **Cleaning up an infected site** — The full method, and why restoring a backup isn't enough. ([/securite/nettoyer-un-site-infecte](/securite/nettoyer-un-site-infecte))
- **Hacked WordPress site** — The reference page for an already-identified WordPress hack. ([/wordpress-woocommerce/site-pirate](/wordpress-woocommerce/site-pirate))

## FAQ

### Why does Google index content I never published?

Because the injected pages genuinely exist on your server, generated by a malicious file. Google crawls and indexes them like any other normal page on your site.

### Is this kind of spam dangerous for my customers?

The direct risk to your customers is generally lower than with a payment skimmer, but the damage to your search rankings and reputation can be significant if the domain gets downranked or flagged.

### Is removing the pages one by one in Google enough?

No. As long as the file generating those pages stays active on the server, new ones reappear within days, often more of them than before.

### How long does Google take to remove these pages once the site is cleaned?

It depends on how many pages are involved and how often Google crawls your site. Requesting a review in Search Console generally speeds things up once the flaw is closed.

### How do you find out which extension was the entry point?

By cross-referencing when the first spam pages likely appeared with the history of installed plugins and their last official update. It's investigative work I always do before cleaning up.
