SECURITY FINDING
Spam content injected on the page (SEO spam)
What it is
The home page has an unusually high density of spam-associated terms (casino/pharma/betting and similar). On a site that isn't actually about those topics, this usually means spam content was injected to manipulate search rankings ('SEO spam').
How to fix it
Review the page for content you didn't write. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).
In depth
Your website contains hidden spam text about casinos, prescription drugs, or similar products inserted by hackers to boost their own websites in search results using your site's reputation. This happens when attackers exploit security vulnerabilities in your WordPress installation, themes, or plugins to inject this content without your knowledge. The problem is serious because search engines will penalize or delist your site, and your visitors may see these unwanted pages when they search for your content. To fix it, you need to find and delete the spam text from your pages, then identify how the hackers got in by checking your installed plugins and themes for outdated or vulnerable versions. Update everything to the latest version, change all your WordPress passwords, and consider using a security plugin like Wordfence or Sucuri to scan for malware and monitor for future attacks. If the spam is extensive or you cannot find the injection point, contact your web hosting provider or a WordPress security specialist for help.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.