Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress malwareWordPress pharma hack cleanup and removal

WordPress pharma hack cleanup and removal

A WordPress pharma hack injects pharmaceutical spam into a compromised website so unwanted pages, keywords or links can appear in search results. The injected material may be hidden from ordinary visitors, which can make the infection easy to miss.

Signs you might see

  • Viagra or pharmacy words in Google results
  • Spam shown to Google but not to you
  • Hidden links in the page source

Not sure? Run our free WordPress security scanner for a quick outside check.

What is a WordPress pharma hack?

A pharma hack is a type of hacked search spam. An attacker modifies a legitimate website so the domain publishes or appears to publish pharmaceutical content, links or search snippets that the owner never created.

The infection does not have to replace the homepage. Spam can be inserted into existing content, generated as additional URLs or hidden in markup that is served selectively. Google documents page injection, content injection, hidden links and cloaking among the ways compromised websites can be abused.

The attacker's purpose is normally to make use of a legitimate domain's presence in search rather than to improve the owner's website. For the site owner, the practical problem is broader than unwanted keywords. The presence of injected content shows that somebody obtained a way to alter the site, so the access route and any persistent backdoor also need to be found.

How to check WordPress for pharma spam

Search Google for your domain using the site: operator and look for pharmacy terms, unfamiliar product titles or URLs that you never created. Search Console's Security Issues and Pages reports can provide further evidence, particularly when Google has discovered URLs that are absent from your normal WordPress navigation.

Do not rely on viewing the homepage while logged in as an administrator. Compare desktop and mobile behaviour and use Google's Search Console inspection tools to see what Google has crawled. Search spam can be cloaked so Google or visitors arriving from particular sources receive different content.

Inspect the page source for unfamiliar hidden links, scripts or markup. At server level, compare WordPress core files with clean originals and review theme and plugin files for unexpected modifications. The database also matters. Spam can be stored in posts, options, widgets, user records or other tables and then rendered dynamically.

Our free WordPress security scanner can provide an additional external signal. Treat it as one diagnostic check rather than proof that every file and database record is clean.

How to remove a WordPress pharma hack

  1. Make a forensic copy. Back up all files and the complete database and keep the infected copy before cleanup starts.
  2. Reset access. Change passwords for WordPress users, hosting, the database and FTP or SFTP. Replace the WordPress salts in wp-config.php and investigate unfamiliar accounts.
  3. Locate every affected component. Trace spam pages and links back to their files, database entries or injected configuration.
  4. Restore clean application code. Replace compromised WordPress core, plugin and theme files with clean legitimate copies where appropriate.
  5. Remove persistence. Find unauthorised users, backdoors and other mechanisms that could recreate the spam.
  6. Find and close the original weakness. A cleanup is incomplete if the vulnerable extension, stolen account or other access route remains usable.

Once the site is clean, recheck Search Console and follow Google's security review process if a review is offered. Our Hacked Site Rescue is £349 fixed price.

Reducing the risk of another pharma hack

Apply WordPress core, plugin and theme security updates promptly and remove plugins or themes that are no longer required. An inactive extension still leaves code on the server unless it is deleted.

Use separate, strong passwords and two-factor sign-in where available. Restrict administrator access to people who actually need it and remove old accounts. File integrity checks can then make unexpected application changes easier to identify.

Backups should include the database as well as files and should be stored away from the live server. A backup that shares the same compromised account can itself be altered or removed.

Care plans start from £59 a month with weekly updates, daily off-server backups, uptime monitoring and security scanning. More information is available under WordPress maintenance.

Common questions

Answers to the questions we hear most about this.

Why are Viagra or pharmacy words showing in my Google results?

If those terms are unrelated to your website and you did not publish them, hacked search spam is one possible cause. Check Search Console, your indexed URLs, page source, WordPress files and the database.

Can a pharma hack be hidden from the website owner?

Yes. Compromised sites can serve different content according to device, referrer or user agent. Spam may therefore appear to Google or selected visitors without appearing during an ordinary visit to the site.

Will reinstalling WordPress remove pharma spam?

Replacing compromised WordPress core files can be part of cleanup, but it does not automatically clean themes, plugins, the database, hosting configuration or attacker-created access. The original entry point must also be identified and closed.

Think your site has been hacked?

Hacked Site Rescue is a fixed £249. We remove the malware, close the way in and help clear the warnings.

Get website support