"Site abused with third-party spam": internal search, uploads and open sections

This action is broader than user-generated spam. Google found "a significant portion" of your site abused by spam from visitors or other third parties, and lists the places it tends to appear: forums, guestbooks, social features, file uploaders, free hosting areas and internal search pages. The spam exists to promote someone else's pages, not your subject.

The good news, in Google's words, is that it "generally" thinks your site is of sufficient quality that it did not need to act on the whole site. Only the spammy pages are affected. The warning is that if the spam keeps growing, it can change Google's overall view of the site.

Expand the entry in the Manual actions report to see the affected patterns. For this action they often point straight at the channel: a list of /?s= URLs, a /wp-content/uploads/ path full of documents, or a forum directory. Treat the listed examples as a sample and assume there are more of the same kind.

Entry points specific to this action

Beyond comments and forums, check the less obvious places where outsiders can create a URL on your domain:

  • Search result pages. Spammers link to URLs like /?s=watch+free+movies+online+casino from elsewhere. Many themes print the query in the title and heading ("Search results for ..."), so the spam text appears on a real page on your domain.
  • File uploads. Form plugins that store uploads in a public folder, or a media library open to contributors, can end up hosting PDFs and HTML files full of spam.
  • Open subsites or user blogs on a Multisite network.
  • Classified, directory or listing plugins that publish submissions automatically.
  • Profile pages from membership or course plugins.

Google suggests searching site:yourdomain.com with unrelated commercial or adult keywords, and checking server logs for spikes of traffic to new URLs with irrelevant keywords.

Shutting down search page spam on WordPress

Hydrogen SEO already outputs noindex, follow on internal search results, which keeps new ones out of the index. That does not remove URLs Google has already stored, and it does not stop the spam text rendering on your domain. Also:

  • Make sure robots.txt does not block /?s= while you wait for Google to see the noindex; a blocked page cannot be recrawled to find the tag.
  • Edit your theme's search.php so it does not print the raw query in the <title> and <h1>, or escapes and truncates it.
  • Consider returning a 404 for searches with no results, and limit query length; genuine searches rarely run past a few words, while spam queries often carry whole sentences and URLs.
  • Check the Performance report filtered to URLs containing ?s= to see how many were indexed.
bash
# Count search URLs Google has been requesting
grep -c 'GET /?s=' /var/log/nginx/access.log
grep 'GET /?s=' /var/log/nginx/access.log | grep -oE 's=[^ &]+' | sort | uniq -c | sort -rn | head

Uploads, listings and blocklists

For upload fields, move file storage out of the public web root, or restrict uploads to images and scan what arrives. Remove any spam files already present; if they include HTML or PHP files, treat it as a possible compromise and check Hacked: URL injection.

For directories and listings, switch submissions to pending review. Google recommends blocking obviously inappropriate content with a list of spammy terms, naming streaming, download, adult, gambling and pharma terms as examples. WordPress's Disallowed Comment Keys covers comments; most forum and directory plugins have their own word filters.

Google also suggests consolidating interactive content into one file path, such as /community/. That makes monitoring easier and lets you apply noindex or moderation rules to one place under Hydrogen SEO → Robots.

Requesting review, then staying on top of it

Review the example URLs in the Search Console message, clean every similar page, and then select Request Review. Describe each entry point and the control you put on it:

text
Spam reached us through internal search URLs and an open upload form.
Search pages no longer print the query in the title or heading, and
return 404 when empty. The upload form now accepts images only and
stores files privately; 212 spam PDFs were deleted.

Google's recommended actions for this one end with a reminder to keep monitoring and cleaning after you submit, and to fix system vulnerabilities. You will receive the result by email. Decisions usually take days, sometimes weeks. A successful review does not stop spammers from trying again, so keep the log check and the site: searches as a monthly habit.

Common questions

How is this different from the user-generated spam action?

User-generated spam focuses on forums, comments and profiles. Site abused with third-party spam covers any channel third parties can use, including internal search pages, file uploaders and free hosting areas, and signals that a significant portion of the site is affected.

Does noindexing search results fix this?

It keeps new search pages out of the index, which helps, but you still need to stop the spam text appearing on your pages and clear the entry points before requesting review.

Is my whole site penalized?

Google says this action only affects the spammy pages, and that it generally means the rest of the site was judged good enough not to act on. Heavy, ongoing spam can still affect how the whole site is assessed.