Spam links you did not add
WordPress has links you did not add. That is malware, not a mystery.
Footer, sidebar, blog posts, or a block of tiny links to casinos and pharmacies that nobody on staff wrote. If WordPress has links you did not add, someone has write access you did not intend — or a file is generating them on every page load.
What this usually is
Unwanted links are either sitting in content (widgets, post content, theme customizer) or being printed by PHP you cannot see in the editor. The second kind is the actual incident: a modified footer.php, a must-use plugin, an eval() in an otherwise-real file, or a database option that a leftover cron reprints. Staff did not “accidentally” add fifty casino anchors in Korean.
What you are probably seeing
- Footer or sidebar filled with casino, loan, or “buy pills” anchors
- Links with CSS that hides them (display:none, 1px font, off-screen)
- The same block of links on every page, including pages you never edit
- Links that only appear in view-source or to logged-out visitors
- You deleted them yesterday and they are back this morning
What not to do
- Do not only delete the links in the widget or the block editor. If they return after a refresh, the generator is still live.
- Do not replace the theme blindly. You will lose the design and often leave the dropper in wp-content/mu-plugins or in wp-config.php.
- Do not assume a freelancer “must have added them.” Check the user list and the file dates before you accuse the wrong person.
What we actually do
We tell you whether the links live in the database, in the theme, or in a file that is not supposed to exist. Then we remove the generator and the leftover admin or FTP account that put it there. That is the published WordPress IR job — Phase A from $2,500 — not a “SEO cleanup” retainer.
Published rates live on the WordPress incident-response packages page: Phase A from $2,500, Phase B from $2,000, combined from $4,200. Remote nationwide. Onsite in the Tri-Cities and Western North Carolina if you want someone in the room. If the WordPress site is the front door to a larger business compromise, start at emergency incident response instead.
Related WordPress problems
Same practice, same packages. Different search, different first paragraph.
Hacked WordPress
The site is compromised and you need it cleaned carefully, not rebuilt from a blank theme.
Gambling / casino / loan spam
Google shows casino, loan, or pill titles. Your pages look normal when you visit them logged in.
Unknown WordPress admin
A WordPress administrator or author appeared that nobody on staff created.
Redirect malware
Phones, Google visitors, or logged-out users get sent to a site you do not own.
Packages & pricing
Phase A, Phase B, and combined. Written report. Hosting can stay yours.
If this is your WordPress site
I deleted the links and they came back.
Then you deleted the output, not the generator. A cron, a must-use plugin, or a modified core/theme file is reprinting them. That is the cleanup, not another pass through the widgets screen.
Could a contractor have added them on purpose?
Possible, and rare. More often a stolen admin password, a vulnerable plugin, or a nulled theme dropped a file. We look at user creation dates and file timestamps before anyone gets blamed.
Are the links in the database or the files?
Either, or both. Visible widget text is usually the database. Links that survive a database export/import are usually files. We check both. A “database-only” cleanup on a file-based injector is why host one-click tools fail.
Need the site cleaned without taking the store down?
Tri-Cities 423-888-0252 · Western NC 828-484-1257