What is a WordPress pharma hack?
A pharma hack is a type of hacked search spam. An attacker modifies a legitimate website so the domain publishes or appears to publish pharmaceutical content, links or search snippets that the owner never created.
The infection does not have to replace the homepage. Spam can be inserted into existing content, generated as additional URLs or hidden in markup that is served selectively. Google documents page injection, content injection, hidden links and cloaking among the ways compromised websites can be abused.
The attacker's purpose is normally to make use of a legitimate domain's presence in search rather than to improve the owner's website. For the site owner, the practical problem is broader than unwanted keywords. The presence of injected content shows that somebody obtained a way to alter the site, so the access route and any persistent backdoor also need to be found.
How to check WordPress for pharma spam
Search Google for your domain using the site: operator and look for pharmacy terms, unfamiliar product titles or URLs that you never created. Search Console's Security Issues and Pages reports can provide further evidence, particularly when Google has discovered URLs that are absent from your normal WordPress navigation.
Do not rely on viewing the homepage while logged in as an administrator. Compare desktop and mobile behaviour and use Google's Search Console inspection tools to see what Google has crawled. Search spam can be cloaked so Google or visitors arriving from particular sources receive different content.
Inspect the page source for unfamiliar hidden links, scripts or markup. At server level, compare WordPress core files with clean originals and review theme and plugin files for unexpected modifications. The database also matters. Spam can be stored in posts, options, widgets, user records or other tables and then rendered dynamically.
Our free WordPress security scanner can provide an additional external signal. Treat it as one diagnostic check rather than proof that every file and database record is clean.
How to remove a WordPress pharma hack
- Make a forensic copy. Back up all files and the complete database and keep the infected copy before cleanup starts.
- Reset access. Change passwords for WordPress users, hosting, the database and FTP or SFTP. Replace the WordPress salts in wp-config.php and investigate unfamiliar accounts.
- Locate every affected component. Trace spam pages and links back to their files, database entries or injected configuration.
- Restore clean application code. Replace compromised WordPress core, plugin and theme files with clean legitimate copies where appropriate.
- Remove persistence. Find unauthorised users, backdoors and other mechanisms that could recreate the spam.
- Find and close the original weakness. A cleanup is incomplete if the vulnerable extension, stolen account or other access route remains usable.
Once the site is clean, recheck Search Console and follow Google's security review process if a review is offered. Our Hacked Site Rescue is £349 fixed price.
Reducing the risk of another pharma hack
Apply WordPress core, plugin and theme security updates promptly and remove plugins or themes that are no longer required. An inactive extension still leaves code on the server unless it is deleted.
Use separate, strong passwords and two-factor sign-in where available. Restrict administrator access to people who actually need it and remove old accounts. File integrity checks can then make unexpected application changes easier to identify.
Backups should include the database as well as files and should be stored away from the live server. A backup that shares the same compromised account can itself be altered or removed.
Care plans start from £59 a month with weekly updates, daily off-server backups, uptime monitoring and security scanning. More information is available under WordPress maintenance.