A Real Case: WordPress Spam Injection That Went Undetected for 4 Years

Everything about this site looked normal. Leads were coming in, pages loaded fine. Underneath, it had been hacked for 4 years.

During a routine SEO audit for a client, I found something no business owner wants to hear about: hidden spam content injected into their WordPress site, and indexed by Google.

The site belonged to a small service business, and it was one of their main sources of new inquiries. On the surface, nothing looked wrong. The visible pages worked fine, leads kept coming in, and there were no obvious signs of a hack.

Once I looked closer, it was clear the site had been compromised for a long time.

The first red flag: strange page titles in Ahrefs

The issue surfaced during an SEO audit. I was reviewing organic visibility and noticed page titles and URLs in Ahrefs that had nothing to do with the client’s business or industry.

That’s a strong signal something is wrong. A normal business site shouldn’t suddenly rank for unrelated terms, especially when those pages don’t show up anywhere in the WordPress dashboard.

Ahrefs.com Organic Keywords Report
Ahrefs.com Organic Keywords Report shows the most prominent keywords and pages in SERPs.

Spam content that was invisible in the dashboard

Digging further confirmed it. Dozens of pages had been injected with spam content covering prescription drugs, alcohol, and adult topics.

None of it was visible inside WordPress. Logging in and checking the Pages section wouldn’t have shown a thing. But Google could crawl and index every page. Both Google Search Console and Ahrefs confirmed these pages were showing up in search results.

Google Search Console Performance Report for 7 days
Google Search Console Performance Report shows the main queries for a website. This report is for 7 days.

A four-year-old backdoor

Connecting via FTP, I found a suspicious PHP file sitting in the root directory. The code was obfuscated, and the file dated back to 2019.

That puts the compromise at roughly four years. Not every hacked site gets defaced or taken down. Sometimes it keeps working normally for visitors while hidden content runs in the background.

The hosting plan included SiteLock, and its automated scans never caught it. Automated security tools help, but they’re not a substitute for manual checks and ongoing maintenance.

Rebuilding on a new host instead of cleaning the old install

After talking through the options with the client, we agreed the safest path was to move off the old hosting setup entirely and rebuild from scratch rather than try to clean and reuse a compromised installation.

We moved the site to SiteGround, which is what I typically recommend for small business WordPress sites. I manually transferred only the essential content onto a fresh staging install while the old site stayed live. Once the client reviewed and approved the new version, I completed the migration and took the compromised site down.

Performance before and after the rebuild

Since we were rebuilding anyway, this was a chance to fix performance and technical SEO at the same time.

GTMetrix Performance Report: Old Website
GTMetrix Performance Report: Old Website

Before: GTmetrix gave the homepage a D grade, 55% performance, 83% structure, 3.7 second LCP, and 0.13 CLS.

PageSpeed Insights failed the Core Web Vitals assessment on both mobile and desktop.

Mobile scored 74 performance, 94 accessibility, 83 best practices, 82 SEO, with FCP at 3.6 seconds and LCP at 3.7 seconds.

Desktop scored 80 performance, 94 accessibility, 83 best practices, 83 SEO, with FCP at 1.0 second and LCP at 1.5 seconds.

GTMetrix Performance Report: New Website
GTMetrix Performance Report: New Website

After: GTmetrix gave the new homepage an A grade, 100% performance, 100% structure, 0.5 second LCP, and 0 CLS.

PageSpeed Insights passed Core Web Vitals on both mobile and desktop.

Mobile scored 93 performance, 100 across accessibility, best practices, and SEO, with LCP at 3.0 seconds.

Desktop scored 95 performance, 100 across the rest, with LCP at 1.0 second and CLS at 0.001.

The result was a cleaner, faster, safer site, and one the client could actually maintain going forward.

Watching the recovery

After migration, I kept monitoring the site in Search Console, Google Business Profile, and Ahrefs. Cleanup is only half the job. The other half is watching how Google responds and whether normal visibility comes back.

What this case actually teaches

A hacked WordPress site doesn’t always look hacked. The visible pages can run fine while spam content, backlinks, or malicious files sit hidden deeper in the install.

Security scans and hosting-level tools are useful, but they’re not enough by themselves. Any WordPress site that brings in real business deserves regular, hands-on maintenance, especially once it’s been running for years across multiple plugins, themes, updates, and hosting moves.

Common questions

How do I know if my WordPress site has been hacked?

Check Ahrefs or Google Search Console for page titles and URLs that don't match your business or content. Hidden spam is often invisible inside the WordPress dashboard but still gets crawled and indexed by Google.

Can a hacked WordPress site look completely normal to visitors?

Yes. This is one of the more common patterns with spam injection. The visible site keeps working fine for real visitors while spam pages are served separately to search engine crawlers.

Do security plugins like SiteLock catch this kind of hack?

Not always. Automated scans can miss obfuscated backdoor files, especially older ones. They're a useful layer, but not a replacement for manual review.

Should I clean a hacked WordPress install or rebuild it?

It depends on how deep the compromise goes and how old the install is. For long-running compromises with unknown backdoors, a rebuild on fresh hosting is often safer than trying to fully clean and trust the old files.

How long does it take Google to recognize a site is clean after a hack?

It varies, but expect it to take weeks to a few months. Keep monitoring Search Console, Google Business Profile, and your rank tracker to confirm the spam pages drop out and normal visibility returns.

Leave a Reply

Your email address will not be published. Required fields are marked *