WP Clinic
Log in Sign up

SECURITY FINDING

Hidden SEO spam links injected on the page

What it is

The home page contains a hidden block of links (positioned off-screen or display:none) — a classic SEO-spam injection technique that shows search engines links a human visitor never sees, often for pharma/casino/counterfeit sites.

How to fix it

Search the page's source for the hidden block and remove it. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).

In depth

Our security scan detected hidden links buried in your website's home page that are invisible to your visitors but visible to search engines. Cybercriminals inject this code to promote spammy or malicious sites without you knowing, and Google treats this as a serious violation that can result in your site being delisted from search results. This directly damages your traffic and credibility because potential customers won't find you anymore. To fix this, you need to remove the hidden code block from your home page, which you can do by editing the page's HTML if you're comfortable with code, or by using a WordPress security plugin like Wordfence or Sucuri that can automatically detect and clean up this hidden content. After removing it, change any passwords that might have been compromised and run another security scan to confirm the injection is gone.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.