Malware

SEO spam

SEO spam is content and links injected into a hacked site to help someone else rank, usually for pills, gambling, or counterfeit goods. The owner rarely sees it, because it is often shown only to search engines.

How it is measured

Search Google for site:yourdomain.com with words like viagra, casino, or replica, and check Search Console for pages you never created. Then fetch your own pages with a Googlebot user agent and compare the HTML to what a normal browser gets; cloaked spam differs.

Count the injected URLs, the new sitemap entries, and the outbound links in templates. Check for new files in the root and uploads, odd entries in .htaccess, and posts created by users you do not recognize.

Worked example

A plumber's WordPress site gets 11 clicks a day from searches for 'cheap designer handbags'. Search Console lists 3,800 indexed URLs where the owner counts 40. A curl with Googlebot's user agent returns /product-7312.html filled with handbag links, while a browser sees a 404.

The doors are an .htaccess rewrite and a root file called wp-feed.php that generates the pages from a remote list. After deleting both and closing the vulnerable plugin, the owner submits the cleaned site for reconsideration, and the spam URLs drop out over several weeks.

How it differs

A doorway page is built to rank for a keyword and funnel visitors elsewhere; the site owner may have made it. SEO spam is the hacked version, where the pages and links are put there without permission, often hundreds at a time. Doorway is a tactic; SEO spam is an intrusion.

Common errors

Checking only the homepage in a browser. Deleting the spam pages but not the generator file. Blocking the URLs in robots.txt, which stops Google from recrawling and noticing they are gone. Forgetting the sitemap. Ignoring a sudden jump in indexed pages.

In practice

Compare indexed page counts with what you published, and check Search Console security and manual-action reports. Search the filesystem and database for the spam keywords, remove the generator and the way in, then request review. Set an alert for new admin users and new root-level files.

See also

Doorway page, Defacement

Sources

Count this on a real site.

Watch my website