Blog · 7 min read

Hidden spam links in WordPress: how to find them

Published 2026-10-08

Hidden spam links are one of the most common signs that a WordPress site has been hacked. Visitors never see them, but Google does, and they quietly point your site's reputation at pill shops, casino pages and other sites you would never link to.

This guide uses WordPress for its examples because it is the most common target, but the same problem hits Joomla, Drupal, Magento, Shopify themes, Wix and Squarespace embeds, and custom-built sites. Where a step is WordPress-specific, the same idea applies elsewhere: look at the theme or template files, plugins or extensions, and the database.

What hidden spam links are

A hacker adds links to your pages that are invisible to people. The usual tricks are CSS such as display:none, font-size:0 or position:absolute; left:-9999px, and links tucked into a tiny or white-on-white block of text. Their goal is to borrow your site's authority for the pages they are promoting.

Some versions are sneakier still. This is called cloaking: the spam is shown only when the visitor is Googlebot, or only to people arriving from a Google search, so you never see it when you open your own site.

Warning signs

6 ways to find hidden spam links

1. Search Google for your own site

Type site:yourdomain.com into Google and scroll through the results. Then try site:yourdomain.com viagra, site:yourdomain.com casino and site:yourdomain.com loans. Any hit you did not write is a red flag.

2. View the page source

Open your home page, right-click, choose View page source and search (Ctrl+F) for display:none, left:-9999, font-size:0 and <a href. Look for links to domains that mean nothing to you. Check the footer and the bottom of the source especially.

3. View the site the way Googlebot does

In Google Search Console, open URL Inspection, enter a page and run Test live URL, then view the crawled page. If Google's version contains links or text that your own browser does not show, you are probably dealing with cloaking.

4. Search your files

If you have SSH or file access, search the WordPress folder for code that hides or injects content. Common places are the theme's footer.php and functions.php, plugin files and the uploads folder. Warning signs in PHP are base64_decode, eval(, gzinflate and long unreadable strings. PHP files inside wp-content/uploads should not exist at all.

grep -rIl "base64_decode\|eval(" wp-content/ | head

Many legitimate plugins use these functions, so treat a match as a lead to inspect, not proof.

5. Check the database

Spam can live in your database rather than in files. In phpMyAdmin, search the wp_posts and wp_options tables for display:none and for domains you do not recognise. Also check Appearance → Widgets for text or HTML widgets you did not add.

6. Use a scanner that checks from outside

An outside-in scanner fetches your public pages and looks for hidden links, spam keywords, malicious JavaScript and cloaking in one pass. UrKavach does this on a schedule and alerts you when something new appears, so you do not depend on stumbling across it.

How to remove them

  1. Back up first so you can compare before and after, and keep a copy for any investigation.
  2. Remove the injected links and code from files and the database. Replace WordPress core, plugins and themes with fresh copies from official sources rather than editing them by hand.
  3. Delete unknown admin users (Users → All Users), and remove plugins or themes you do not use.
  4. Change every password: WordPress admins, hosting, FTP/SFTP and the database. Then reset the secret keys in wp-config.php to log everyone out.
  5. Update everything. Most spam injections get in through an outdated plugin or theme.
  6. Ask Google to re-crawl. Submit your sitemap again in Search Console and, if you had a security warning, request a review.

How to stop them coming back

If you are not comfortable editing files and databases yourself, ask your host or a WordPress security professional. Cleaning only the visible symptom is the most common reason spam returns a week later.