What casino and SEO spam does to WordPress
SEO spam is a compromise in which an attacker uses your domain to publish or promote content for search visibility. Common examples include casino pages, betting terms, loans, pharmaceuticals and large numbers of keyword-focused URLs that have nothing to do with the legitimate website.
The attacker benefits from using an established domain rather than building a new site from scratch. Malware may create WordPress posts, insert records directly into the database, generate pages dynamically or modify PHP files so apparently normal URLs return spam. More sophisticated infections use cloaking, showing ordinary content to the site owner while serving different content to Googlebot, mobile visitors or traffic arriving from search results.
Deleting the visible spam pages is therefore not enough. If the code, compromised account or vulnerable plugin that created them remains, the pages can return.
How to check a WordPress site for SEO spam
Start by searching Google for site:yourdomain.co.uk and scan the results for unfamiliar titles, casino terms and URLs you did not publish. In Google Search Console, check Security Issues and the Pages report for unexpected indexed URLs or sudden changes in the number of pages Google has discovered.
Do not rely only on what appears when you visit the homepage normally. Compare affected pages from a desktop browser and phone, inspect the page source, and use Search Console inspection information where available. If a technical diagnostic can request the page using Googlebot's user agent, compare that response with the normal version. Differences can expose cloaked spam.
At server level, examine recently changed PHP files, unfamiliar files in WordPress directories, unexpected rewrite rules and code added to theme or plugin files. Check the database for spam posts, altered options, injected JavaScript and unknown administrator accounts. Our free WordPress security scanner can provide an additional external check, but a clean scanner result does not rule out a hidden server-side infection.
How to remove casino spam from WordPress safely
- Preserve evidence first. Take a complete backup of the files and database before changing anything, and retain a separate copy of the infected site for investigation.
- Restrict the compromised site if necessary. If visitors are being redirected or exposed to malicious content, consider temporarily limiting public access while the investigation is carried out.
- Find the entry point. Review vulnerable or abandoned plugins and themes, compromised administrator accounts, hosting access and unexpected file changes. Cleaning without closing the original route in commonly leads to reinfection.
- Remove the malicious content and code. Delete spam records and injected database content, replace modified WordPress core files with trusted copies, and reinstall affected plugins or themes from legitimate sources rather than trying to preserve suspicious code.
- Rotate credentials. Change WordPress user passwords, hosting credentials, database passwords, FTP or SFTP credentials and relevant API keys. Replace the WordPress security salts in wp-config.php so existing login sessions are invalidated.
- Verify the result. Rescan the filesystem and database, check administrator users, review the site from different devices and repeat the Google site search over time. Where Search Console reports a security issue, request a review only after the site is fully cleaned and the cause has been addressed.
If you want the infection investigated and removed for you, Hacked Site Rescue is £349 fixed price.
How to stop WordPress SEO spam coming back
Keep WordPress core, themes and plugins current, and remove extensions that are no longer used rather than simply deactivating them. Old code that remains on the server can still increase the attack surface.
Use unique strong passwords and two-factor sign-in for privileged accounts. Administrator access should be limited to people who genuinely need it, with lower-privilege roles used for routine publishing. File integrity monitoring can also make unexpected changes easier to spot.
Maintain recoverable off-server backups and periodically confirm that they can actually be restored. Web Support Services care plans start from £59 a month and include weekly updates, daily off-server backups, 24/7 uptime monitoring and security scanning.