Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress malwareJapanese keyword hack cleanup for WordPress

Japanese keyword hack cleanup for WordPress

A Japanese keyword hack creates or alters pages so your domain appears in Google for Japanese-language commercial search terms you did not publish. The spam may be difficult to see when you visit the website normally.

Signs you might see

  • Japanese text in your Google results
  • Thousands of new pages in Search Console
  • Unknown sitemap or verified owner in Search Console

Not sure? Run our free WordPress security scanner for a quick outside check.

What is a Japanese keyword hack?

The Japanese keyword hack is a form of hacked search spam. An attacker uses a compromised website to publish pages, titles, links or metadata intended to appear in search results, often while leaving the site's normal public pages looking largely unchanged.

The objective is usually to exploit the reputation and indexing history of an established domain. The injected content may be presented differently according to URL, device, referrer or user agent, which is why the site owner can open the homepage and see nothing unusual while Google has indexed large quantities of unwanted content.

Google describes hacked content as material placed on a site without permission and specifically identifies page injection, content injection, hidden links and cloaking as forms that can affect search results. A Japanese keyword infection should therefore be treated as a site compromise, not simply an SEO problem.

How to check for Japanese spam on WordPress

Start with a Google search for your own domain using the site: operator. Look beyond the first few results for unfamiliar Japanese titles, product pages or URLs that do not belong to the website.

In Google Search Console, inspect Security Issues and the Pages report. A sudden collection of unknown URLs can show that spam pages have been created even if they are not linked from your normal navigation. Check Search Console ownership as well, because an unfamiliar verified owner requires investigation.

Compare what a normal desktop browser shows with a mobile visit and Google's crawled version available through Search Console tools. Hacked spam can be cloaked according to the visitor, so viewing only the page you normally use is not sufficient.

At site level, inspect recently changed WordPress, theme and plugin files and examine the database for unfamiliar posts, options, users, links or injected markup. Compare WordPress core files with clean originals rather than assuming every PHP file belongs there. Our free WordPress security scanner can provide another external check, but a clean scanner result does not rule out every compromise.

How to remove a Japanese keyword hack safely

  1. Preserve the evidence. Take a complete backup of the files and database and keep a copy of the infected site before changing anything.
  2. Secure access. Change passwords for all WordPress users, hosting, the database and FTP or SFTP. Replace the WordPress salts in wp-config.php and remove unauthorised accounts.
  3. Find the injected content. Trace the spam URLs to files, database records, plugins, themes or server configuration rather than deleting only the pages visible in Google.
  4. Replace compromised software. Reinstall clean WordPress core files and clean copies of legitimate themes or plugins where appropriate. Remove software that should not be present.
  5. Close the entry point. Identify the vulnerable component or compromised account that allowed the infection.
  6. Verify the cleanup. Recheck the site, Search Console and indexed URLs before requesting any Google security review that is required.

Our Hacked Site Rescue costs £349 fixed price if you want the investigation and cleanup handled for you.

How to stop Japanese keyword spam coming back

Keep WordPress core, active themes and plugins updated and remove unused extensions rather than leaving dormant code installed. Use unique strong passwords and two-factor sign-in where available, and give each account only the permissions it requires.

File integrity monitoring is useful because it can highlight unexpected changes to application files between legitimate updates. Maintain current off-server backups so recovery does not depend on files stored inside the compromised hosting account.

Continue checking Search Console after cleanup. Old hacked URLs can remain visible while Google recrawls the site, so distinguish historical indexed URLs from pages that are still being generated.

Care plans start from £59 a month and include weekly WordPress updates, daily off-server backups, uptime monitoring and security scanning. See WordPress maintenance for ongoing site care.

Common questions

Answers to the questions we hear most about this.

Why is Japanese text appearing in Google for my website?

If you did not publish it, unexpected Japanese titles or pages on your domain can indicate hacked search spam. Check Search Console, indexed URLs, website files and the WordPress database rather than changing only the visible search snippets.

Why can Google see Japanese spam when I cannot?

Some hacked sites serve different content according to the visitor, device, referrer or user agent. This is a form of cloaking, so the spam may appear to Google or selected visitors while your normal browser session looks unchanged.

Will deleting the Japanese pages fix the hack?

Not necessarily. The files, database changes or backdoor that generated the pages may still exist. The cleanup should remove the injected content and identify and close the route the attacker used to gain access.

Think your site has been hacked?

Hacked Site Rescue is a fixed £249. We remove the malware, close the way in and help clear the warnings.

Get website support