Active incident or hacked WordPress? Ransomware Hacked WordPress 423-888-0252 · 828-484-1257

SERP spam · casino / loan titles

WordPress shows casino titles in Google but looks fine when I'm logged in

You search your own site and Google shows casino, loan, or pill titles you never wrote. You log into WordPress and the homepage looks normal. Friends on phones see something different. The mismatch feels like a glitch. It usually is not.

Avery Parker · principal Support since the early 1990s Networks & security since the late 1990s Linux since ~2000 Johnson City office · you talk to the same person

This pattern is one of the most common WordPress compromise signals: search engines and logged-out visitors see planted content; a logged-in admin session often does not. This post explains what that usually means, what to capture on day one, and when DIY should stop. It is not a full malware-removal guide.

If you are still in the first hours after noticing it, start with our first 24 hours after a WordPress hack guide, then the free checklist below.

What this symptom usually looks like

  • Google (or Bing) result titles mention casinos, sports betting, payday loans, pills, or adult keywords
  • The public URL may still be your real domain; the title and snippet are poisoned
  • Logged into wp-admin, the site can look clean
  • Phones or logged-out browsers sometimes redirect while desktop admins do not
  • After you delete a few spam posts, similar titles or pages reappear within days

Related live guides if you already recognize a sibling pattern:

If checkout is taking bad payments, visitors are being redirected to harm right now, or you are locked out of admin and host, skip long DIY and get incident-response help.

Why "looks fine when I'm logged in" is a trap

Attackers often plant SEO spam and conditional injectors that treat authenticated admins differently from Googlebot and anonymous visitors. A blind "it looks fine to me" check from an admin browser misses what search engines and customers see.

Common plant classes (pattern-level, not a claim about your site):

  • Injected posts, pages, or category spam aimed at search engines
  • Hidden links or doorway content
  • Theme / plugin / functions.php edits and rogue drop-in files
  • Persistence so deleted spam returns (backdoor, rogue admin, cron, modified core/theme file)

Deleting the visible casino posts without hunting persistence is why many owners see the same titles again a week later.

What to do first (preserve, do not "fix")

  1. Do not wipe the host or restore blindly over the live site. You may erase the only copy of the injector and still leave a door open.
  2. Capture evidence: screenshots of the Google titles/snippets, the URL shown, any redirect on a logged-out or phone browser, Search Console messages, and the Users list if something looks wrong. Note the time.
  3. Take an off-server backup of files and the database if you still can. Label it "pre-cleanup evidence."
  4. Avoid random "cleanup" plugins and forum paste-into-functions.php recipes that make forensics harder.
  5. Work the calm order of operations in our free WordPress compromise checklist (first 24 hours). That PDF helps you decide what is safe to touch. It does not fully clean a compromised site by itself.

More on day-one order: First 24 hours after a WordPress hack.

When DIY should stop (call / book)

Stop scrubbing alone and use WordPress incident response when any of these are true:

  • Casino / loan / pill titles return after you delete posts or "restore"
  • You cannot trust remaining administrator accounts
  • Safe Browsing or Search Console flags remain after your deletes
  • WooCommerce or lead forms must stay up while cleanup is careful, not a wipe
  • You are out of time and need a written cleanup report, not more trial and error

Published cleanup packages start around $2,500 (typical ranges and combined cleanup + harden options are on the IR page). Work is remote nationwide; Tri-Cities / Western NC onsite is by appointment.

What careful cleanup usually means (expectations)

  • Preserve evidence, then remove planted content and persistence mechanisms
  • Avoid "one-click host clean" as the whole plan
  • Deliver a written report of what was found and changed
  • Search Console / Safe Browsing review is an owner step after pages are actually clean; we do not promise Google timelines or ranking recovery dates

After cleanup, hardening and ongoing Care ($149 / $249 / $399) are optional sequels so the same door is less likely to reopen. They are not a substitute for Phase A cleanup while the SERP is still poisoned. Care details: WordPress maintenance.

Soft start vs active fire

Free: first-24-hours checklist

Download the printable compromise checklist. Evidence, access hygiene, and stop-lines. Not a full clean by itself.

Get the free checklist

Casino-title questions

Why do casino titles show in Google when my logged-in homepage looks fine?

Attackers often plant SEO spam and conditional injectors that treat authenticated admins differently from Googlebot and anonymous visitors. A logged-in check can miss what search engines and customers see.

Is deleting the casino posts enough?

Usually not. Persistence (backdoor, rogue admin, cron, or modified core/theme file) is why similar titles often return within days. Preserve evidence first, then escalate if spam comes back.

Does the free checklist fully clean the site?

No. It is a first-24-hours triage sheet: evidence, access hygiene, and stop-lines. Published cleanup packages with a written report live on the WordPress incident-response page.

Need the site cleaned without making it worse?

Tri-Cities 423-888-0252 · Western NC 828-484-1257