SECURITY FINDING
robots.txt tampered with to hide SEO spam
What it is
This site's robots.txt blocks SEO/security crawlers (like Ahrefs or Semrush) and/or lists spam sitemaps (gambling/casino pages). Attackers do this to hide injected spam from the tools that would expose it while still getting it indexed by Google.
How to fix it
Replace robots.txt with a clean version (remove the crawler blocks and any sitemap you didn't add), and run a full malware scan — a poisoned robots.txt usually means there's injected spam to clean too.
In depth
A security scan found that your robots.txt file, which tells search engines and bots how to access your website, has been modified in ways you likely didn't authorize. Attackers use this to hide spam pages they've injected into your site by blocking legitimate security scanners from seeing them, while allowing search engines to still index the spam content. This damages your reputation with search engines and can cause your site to be penalized or removed from search results. To fix this, log into your website's file manager or hosting control panel, find the robots.txt file in your root directory, and replace it with a clean version that only contains rules you recognize and intentionally set. After that, scan your site thoroughly using a security tool to find and remove any spam pages or malicious links the attacker added, and change all your WordPress passwords to prevent further unauthorized access.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.