Active incident or hacked WordPress? Ransomware Hacked WordPress 423-888-0252 · 828-484-1257

Reinfection · spam keeps coming back

Spam links keep coming back after I delete them

You found spam links, casino pages, or strange posts on your WordPress site. You deleted them. A few days later they are back, sometimes with new names. Maybe you even restored a backup, and the same thing happened.

Avery Parker · principal Support since the early 1990s Networks & security since the late 1990s Linux since ~2000 Johnson City office · you talk to the same person

When spam returns after you delete it, the spam itself is usually not the real problem. Something that keeps writing it back is still on the site. This post explains what that usually means, what to save before you touch anything else, and when it makes sense to stop doing it yourself. It is not a full malware-removal guide.

If you only just noticed the problem, start with our first 24 hours after a WordPress hack guide and the free checklist.

What reinfection usually looks like

  • Spam posts, pages, or links return days after you deleted them
  • New administrator accounts show up again after you removed one
  • A security plugin reports the same infected files again after "cleaning" them
  • Google keeps showing spam titles even after the visible posts are gone
  • A host restore looks clean for a while, then the same symptoms come back

Related live guides if you recognize a sibling pattern:

Why deleting the spam does not fix it

Spam you can see is the output. What attackers usually leave behind is a way back in or a way to regenerate content. Common persistence classes (pattern-level, not a claim about your site):

  • A dropped PHP file (backdoor) hidden among normal-looking theme, plugin, or upload files
  • A rogue administrator account, or an extra account with a role you did not grant
  • A scheduled task (WordPress cron or server cron) that re-creates the spam
  • Modified theme files, functions.php, or must-use plugins
  • A fake plugin that does not show up the way normal plugins do
  • The original weak point, such as an outdated plugin or a reused password, still open

If you delete the spam but leave any of these in place, the site will usually get re-infected. Restoring a backup has the same problem when the backup already contains the door, or when the original weak point is still open after the restore.

What to do first (preserve, do not "fix")

  1. Stop deleting and restoring in a loop. Each round can erase evidence of how the spam is getting back in.
  2. Capture evidence: screenshots of the spam, the URLs, the dates it reappeared, the Users list, and any security plugin reports. Note times.
  3. Take an off-server backup of files and the database if you can. Label it "pre-cleanup evidence."
  4. Change passwords for WordPress administrators, hosting, SFTP, and the database from a clean device, and do not reuse old ones.
  5. Avoid random "cleanup" plugins and forum code snippets pasted into functions.php.
  6. Work through the calm order of operations in our free WordPress compromise checklist. It helps you decide what is safe to touch. It does not fully clean a compromised site by itself.

When DIY should stop (book)

Reinfection is one of the clearest signs that DIY cleanup has reached its limit. Use WordPress incident response when any of these are true:

  • Spam came back at least once after you deleted it or restored a backup
  • You cannot tell which administrator accounts are legitimate
  • Search Console or Chrome warnings remain after your deletes
  • WooCommerce or lead forms need to stay up while cleanup happens carefully
  • You need a written report of what was found and changed, not another round of trial and error

Published cleanup packages start around $2,500 (typical ranges and combined cleanup and hardening options are on the IR page). Work is remote nationwide; Tri-Cities and Western NC onsite is by appointment.

What careful cleanup usually means (expectations)

  • Preserve evidence first, then find how the spam is getting back in
  • Remove planted content and the persistence behind it, not just the visible spam
  • Close the original weak point where it can be identified
  • Deliver a written report of what was found and changed
  • Search Console or Safe Browsing review is an owner step after the site is actually clean; we do not promise Google timelines or ranking recovery dates

After cleanup, hardening and ongoing Care ($149 / $249 / $399) are optional next steps so the same door is less likely to reopen. They do not replace cleanup while spam is still coming back.

Spam-coming-back questions

Why does spam come back after I delete it?

Usually because something that creates it is still on the site, such as a backdoor file, a rogue admin account, a scheduled task, or a modified theme file.

Will restoring a backup fix it?

Not always. If the backup already contains the backdoor, or the original weak point is still open, the spam often returns.

Can the free checklist clean my site?

No. It helps you preserve evidence and decide what is safe to touch in the first day. It does not fully clean a compromised site.

Need the site cleaned without making it worse?

Tri-Cities 423-888-0252 · Western NC 828-484-1257