Free: first-24-hours checklist
Download the printable compromise checklist. Evidence, access hygiene, and stop-lines. Not a full clean by itself.
SERP spam · casino / loan titles
You search your own site and Google shows casino, loan, or pill titles you never wrote. You log into WordPress and the homepage looks normal. Friends on phones see something different. The mismatch feels like a glitch. It usually is not.
This pattern is one of the most common WordPress compromise signals: search engines and logged-out visitors see planted content; a logged-in admin session often does not. This post explains what that usually means, what to capture on day one, and when DIY should stop. It is not a full malware-removal guide.
If you are still in the first hours after noticing it, start with our first 24 hours after a WordPress hack guide, then the free checklist below.
wp-admin, the site can look cleanRelated live guides if you already recognize a sibling pattern:
If checkout is taking bad payments, visitors are being redirected to harm right now, or you are locked out of admin and host, skip long DIY and get incident-response help.
Attackers often plant SEO spam and conditional injectors that treat authenticated admins differently from Googlebot and anonymous visitors. A blind "it looks fine to me" check from an admin browser misses what search engines and customers see.
Common plant classes (pattern-level, not a claim about your site):
functions.php edits and rogue drop-in filesDeleting the visible casino posts without hunting persistence is why many owners see the same titles again a week later.
functions.php recipes that make forensics harder.More on day-one order: First 24 hours after a WordPress hack.
Stop scrubbing alone and use WordPress incident response when any of these are true:
Published cleanup packages start around $2,500 (typical ranges and combined cleanup + harden options are on the IR page). Work is remote nationwide; Tri-Cities / Western NC onsite is by appointment.
After cleanup, hardening and ongoing Care ($149 / $249 / $399) are optional sequels so the same door is less likely to reopen. They are not a substitute for Phase A cleanup while the SERP is still poisoned. Care details: WordPress maintenance.
Download the printable compromise checklist. Evidence, access hygiene, and stop-lines. Not a full clean by itself.
Published cleanup packages with a written report. Remote nationwide.
TN 423-888-0252 · NC 828-484-1257
Attackers often plant SEO spam and conditional injectors that treat authenticated admins differently from Googlebot and anonymous visitors. A logged-in check can miss what search engines and customers see.
Usually not. Persistence (backdoor, rogue admin, cron, or modified core/theme file) is why similar titles often return within days. Preserve evidence first, then escalate if spam comes back.
No. It is a first-24-hours triage sheet: evidence, access hygiene, and stop-lines. Published cleanup packages with a written report live on the WordPress incident-response page.
Tri-Cities 423-888-0252 · Western NC 828-484-1257