SECURITY FINDING
SEO cloaking: different content shown to Google than to visitors
What it is
This site serves different content to Google and search-engine visitors than it shows a regular visitor — a redirect or injected spam links that only appear to crawlers or first-time visitors. This is how SEO-spam infections stay invisible to the owner while wrecking search rankings.
How to fix it
This confirms an active infection. Clean malware across the whole hosting account (not just WordPress), remove the injected code, then request a review in Google Search Console — the WordPress Plugin's AI Repair removes the cloaking payload after a backup.
In depth
We detected that your website contains harmful code that tricks search engines by showing fake content and spam links to Google while your visitors see your normal page. Attackers use this to rank higher in search results without you noticing, which damages your business's online reputation. Google will eventually penalize your site by removing it from search results, so it is urgent to act now. You need to make a complete backup of your website and then remove all the malicious code from your server, a task you can assign to a WordPress security specialist or try fixing with security plugins like Wordfence. Once the site is clean, go to Google Search Console, select your website, and request a security review so Google can re-index your page normally.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.