"Hacked: Content injection": pharma links and spam text in your pages

"A hacker has added spammy links or text to your site's pages," usually pharmaceutical terms or other spam unrelated to your content. Unlike URL injection, the pages are your own existing ones; the attacker has edited them. Results for those pages may be labelled as possibly hacked, and your own titles and snippets can start showing pill names.

Google lists how this usually happens: an insecure directory with open permissions, a vulnerability in the software running your site (it names older WordPress versions among others), or a hacked third-party plugin. Hydrogen SEO is not a security plugin and cannot find or clean injected content, but the steps below show where to look.

Why you may not see the spam

Content injection is usually cloaked. The spam often appears only to Googlebot or only to logged-out visitors, and it is frequently hidden with CSS so a casual visit looks normal. Google recommends URL Inspection and command-line fetches rather than your browser for that reason. A quick check:

bash
curl -s -A 'Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)' https://example.com/about/ | grep -ioE '(viagra|cialis|pharmacy|casino|payday|replica)[^<]{0,60}' | head

Test while logged out, and from a network other than your office if you can, because some variants skip IP addresses that have logged in to wp-admin. Search Google too: site:example.com viagra, site:example.com casino and similar. Results whose snippets show terms you never wrote are the pages to start with, and Google's hacked-spam guides for the "cloaked keywords and links" pattern cover this family of infection.

Where the injected content is stored

On WordPress the spam lives in one of three places:

  • Post and page content in wp_posts.post_content, often appended as a hidden <div> of links at the end of each post, including old ones.
  • Widgets and options: the widget_text and widget_custom_html rows, theme option rows that print footer HTML, and sometimes custom options added by the malware.
  • Theme and plugin PHP: footer.php or functions.php echoing a link list, sometimes fetched from a remote server on each request so the spam changes over time.
bash
wp db search 'viagra' --all-tables --one_line
wp db search 'display:none' wp_posts --one_line | head -40
grep -rniE 'file_get_contents\(.?https?://|curl_exec' wp-content/themes wp-content/plugins | grep -v vendor | head

If injected text shows on every page but is not in the database, the theme or a plugin is printing it. A remote fetch is the nastiest variant: the PHP pulls fresh links from the attacker's server on each request, so nothing spammy is stored on your site at all, only a few lines of code that are easy to overlook.

Removing it without damaging real content

Google's two options are to restore affected files from the last good backup, or remove the spam content and links from each page. For database content, use a backup of the database first, then clean precisely. WP-CLI's search-replace can strip one exact injected block if it is identical everywhere:

bash
wp search-replace '<div style="display:none"><a href="https://spam.example/">cheap pills</a></div>' '' wp_posts --dry-run

Run it with --dry-run first and check the count. Injected blocks often vary per post, in which case a careful SQL or manual review is safer than a broad pattern. Remember revisions: WordPress keeps old revisions in wp_posts, and restoring one can restore the spam.

Then do the full cleanup on the Hacked: Malware page: replace plugins and themes from clean sources, change passwords, rotate salts, and update. Google also asks you to look for other hacked pages with site: searches and by searching your source files, since the report shows only examples.

Requesting the review and the aftermath

Once fetches as Googlebot and as a visitor come back clean, select Request Review in the Security issues report. Say where the spam was stored, how many pages were affected, and what you changed to close the entry point.

Google puts the review at a few days to a few weeks. After it succeeds, the warning label goes, but Google still has to recrawl each page before the spammy snippets disappear. You can speed individual important URLs with Request indexing in URL Inspection. Spam links that were in your pages may also have triggered outbound-link concerns; if the Manual actions report shows unnatural links from your site or hidden text, handle those too.

Common questions

Why do my Google snippets show drug names I never wrote?

Content injection often adds spam text that only crawlers see, so Google indexes it even though your visitors do not. Fetch the page as Googlebot or use URL Inspection to see what Google received.

Can I just delete the spam from the WordPress editor?

Sometimes, but injected blocks are often hidden in HTML the visual editor does not show, in widgets, or printed by theme code. Search the database and theme files, and remove the entry point or it will return.

How long until the spam disappears from search results?

After a successful review Google needs to recrawl the pages. Requesting indexing for key URLs can help, but Google sets the pace.