"Hacked: URL injection": spam pages you never created
"A hacker has created new pages on your site, often containing spammy words or links." Google adds that some of these pages run code you did not intend, like redirecting users elsewhere or making your server take part in attacks on other sites. On WordPress this is the family behind the well-known Japanese keyword hack and gibberish hack: thousands of URLs appear in Google under your domain, full of product spam or nonsense text, while your real pages look untouched.
The cleanup has two halves: delete the pages, and delete whatever generates them, which is often a single PHP file or a few rewrite rules. Hydrogen SEO cannot detect or remove injected pages; it only lists the content you publish.
Measuring how many pages there are
Start with the report's examples, then look wider:
site:example.comon a small site shows what is indexed. For larger ones, add spam terms:site:example.com pharmacy, or Japanese characters for the Japanese keyword hack. Google also suggestssite:example.com/wp-admin/to look for pages indexed inside the admin area.- The Pages indexing report and the Performance report filtered by page often show thousands of new URLs with a shared pattern, such as random folders or
?parameters. - The Sitemaps report may list sitemaps you never submitted.
Google warns that these pages are often cloaked. A visitor may get a 404 or your homepage while Googlebot gets spam, so check URLs with URL Inspection rather than trusting what you see in a browser.
Taking back Search Console first
Google's guide to the Japanese keyword hack starts somewhere surprising: attackers often verify themselves as owners of your Search Console property so they can submit their own sitemaps. Open Settings → Users and permissions, remove anyone you do not know, and then remove the verification token they used (an HTML verification file in your web root, a meta tag in the theme, or a dynamically generated rule in .htaccess), or they can re-verify.
While you are in Settings, check the verification details for each remaining owner too; Google's guide says to revoke unknown access as soon as possible, since an attacker with owner rights can also request removals, change settings and read your data.
In Sitemaps, remove any you did not add. Hydrogen SEO's sitemap only lists your real posts, pages and terms, so an unfamiliar sitemap URL with thousands of spam entries is the attacker's, not your plugin's. Delete the file if it exists on disk.
Finding the generator
Spam pages at this scale are rarely stored one by one. Something turns requests into pages on the fly:
.htaccessrewrites sending unknown URLs to an attacker's PHP file. Google's guide recommends replacing.htaccesswith a clean default version unless you have customized it.- A PHP file in the web root,
wp-content/uploads, or a folder named to look official, such aswp-includes/css/or a fake plugin directory. - A must-use plugin or code added to the theme's
functions.phpthat hooks into WordPress routing. - Posts in the database under a hidden post type, less common but quick to find with
wp post list --post_type=any.
# PHP files that are not part of core, sorted by newest first
find . -name '*.php' -mtime -60 -not -path './wp-includes/*' -not -path './wp-admin/*' -printf '%T+ %p\n' | sort -r | head -30
wp core verify-checksums
grep -nE 'RewriteRule|RewriteCond' .htaccess
Then finish the full cleanup and hardening on the Hacked: Malware page.
Removing the pages and requesting review
Once the generator is gone, the spam URLs should return 404 or 410. Do not redirect them to your homepage or to real content; they were never yours, and a redirect keeps them alive. Check a sample:
for u in $(head -20 spam-urls.txt); do curl -s -o /dev/null -w "%{http_code} $u\n" -A 'Googlebot' "$u"; done
The Removals tool in Search Console can hide URL prefixes from results quickly while Google recrawls, but it is temporary and does not replace fixing the site. When the samples return 404 for both Googlebot and visitors, select Request Review in the Security issues report, stating the generator you removed, the number of spam URLs, and the entry point.
Google says reviews take from a few days to a few weeks. Spam URLs fall out of the index as Google recrawls them, which can take much longer for large infections, and Google does not give a timetable for that.
Common questions
Should I redirect the spam URLs to my homepage?
No. Let them return 404 or 410. They are not your content, and redirecting keeps them alive in Google's eyes. A missing page is the correct answer.
Why does a spam URL show a 404 for me but spam in Google?
The hack is probably cloaked, serving spam only to Googlebot. Use URL Inspection to see what Google gets, and test with a Googlebot user agent.
The hacker added themselves to Search Console. How?
They placed a verification file, meta tag or rewrite rule on your site while they had access. Remove the unknown owner, then remove the verification token so they cannot verify again.