Detect WordPress Pharma Hack & Japanese Keyword Spam
Free scanner to detect the most common WordPress hack - pharma spam injection with viagra/cialis keywords and Japanese/Russian spam cloaking.
The #1 Most Common WordPress Hack
The "Pharma Hack" affects over 500,000 WordPress sites annually. Hackers inject hidden pharmaceutical spam (viagra, cialis, etc.) that's only visible to search engines, causing your site to rank for embarrassing keywords and potentially get deindexed by Google.
Detection is critical: Most site owners don't realize they're hacked until Google Search Console shows thousands of spam pages or their rankings completely disappear.
What is the Pharma Hack?
The Pharma Hack is a sophisticated cloaking attack where hackers inject spam content promoting pharmaceuticals (viagra, cialis, levitra) or other products. The malicious code shows different content to search engines versus regular visitors.
👤 What Regular Visitors See
Your normal website content - blog posts, pages, products. Everything looks completely normal.
🤖 What Googlebot Sees
Spam content: "Buy Viagra Online", "Cheap Cialis", pharmaceutical links, Japanese/Russian keywords, gambling sites.
⚠️ Why It's Dangerous: Google sees spam content and penalizes or deindexes your site. You lose all organic traffic overnight. Recovery can take 3-6 months even after cleanup.
Common Pharma Hack Variations
💊 Classic Pharma Spam
Injection of pharmaceutical keywords and links throughout your site's HTML, visible only to search engine crawlers.
Common Keywords Injected:
🈯 Japanese Keyword Spam
Injection of Japanese characters promoting gambling, adult content, or counterfeit goods. Extremely common in 2023-2024.
What Our Scanner Detects:
- ✓ Japanese/Chinese/Korean characters in meta tags
- ✓ Cloaked content showing different languages to bots
- ✓ Hidden links to gambling/adult sites
- ✓ Spam pages with Asian character URLs
🎰 Gambling & Adult Spam
Links and keywords for online casinos, poker sites, adult content - often combined with pharma spam.
Common Indicators:
- ✓ Casino/poker/gambling keywords in title tags
- ✓ External links to .ru, .cn, .tk domains
- ✓ Hidden divs with spam content (display:none)
- ✓ Meta refresh redirects to gambling sites
👜 Counterfeit Goods Spam
Spam promoting fake designer goods, replica watches, counterfeit handbags - often targeting high-value keywords.
Typical Patterns:
- ✓ "Replica", "fake", "knockoff" keywords
- ✓ Designer brand names + "cheap" or "discount"
- ✓ Links to suspicious e-commerce sites
- ✓ Cloaked product pages only visible to bots
How to Tell If You're Hacked
Google Search Console Warnings
Alerts about "hacked content", "cloaking", or "thin content with little value"
Sudden Traffic Drop
Organic traffic drops 50-100% overnight without explanation
Weird Google Results
Your site shows up for "viagra", "cialis", Japanese keywords you never targeted
Spam Pages in Index
site:yourdomain.com shows thousands of pages you didn't create
Browser Warnings
"This site may be hacked" or "Deceptive site ahead" warnings
Suspicious Links in Source
View source shows hidden links to pharmaceutical/gambling sites
Spam Emails from Your Domain
Your domain is sending pharmaceutical spam emails
Modified Core Files
WordPress core files have unexpected modifications or timestamps
How to Use Our Scanner to Detect Pharma Hack
Enter Your Homepage URL
Start with your main domain to check for cloaking on the homepage.
https://yourdomain.com
Check the Cloaking Detection Results
Our scanner compares what Googlebot sees vs. what regular users see. Look for:
- Content similarity < 95%: Strong indicator of cloaking
- Different meta titles/descriptions: Pharma keywords in bot version
- Length differences > 20%: Hidden spam content
Review Hidden Elements
Check for hidden divs, CSS cloaking, and invisible text containing spam keywords.
Check External Links
Look for suspicious links to pharmaceutical, gambling, or adult sites - especially to .ru, .cn, .tk domains.
Scan Multiple Pages
Test several pages - hackers often inject spam on specific pages only:
- Homepage
- Top blog posts (check Google Analytics for most visited)
- Category/archive pages
- Old posts (often targeted due to lack of monitoring)
Real-World Case Study
News Blog - 95% Traffic Loss in 48 Hours
Industry: News & Media | Platform: WordPress 5.8 | Traffic: 50,000/month → 2,500/month
The Problem:
A popular news blog saw organic traffic drop from 50,000 to 2,500 monthly visitors in just 48 hours. Google Search Console showed "Manual Action: Hacked Content" penalty.
What Our Scanner Found:
- Cloaking detected: 47% content similarity between Googlebot and regular users
- Meta title for Googlebot: "Buy Viagra Online - Cheap Cialis - Pharmacy"
- Meta title for users: Original news article title (normal)
- 1,247 hidden links to pharmaceutical sites in footer (display:none)
- Japanese keywords injected in <head> section
- Modified wp-includes/class-wp-widget.php with base64 encoded spam
Root Cause:
Outdated "Contact Form 7" plugin (version 4.9) with known vulnerability. Hackers exploited it to inject malicious code into WordPress core files and database.
The Impact:
- $12,000/month in lost ad revenue (4 months to recover)
- Manual penalty from Google (required reconsideration request)
- Brand reputation damage (site showed up for viagra searches)
- 3 weeks of full-time work to clean and restore
✅ How It Was Fixed:
- Restored WordPress core files from clean backup
- Cleaned database: removed spam from wp_posts, wp_options, wp_postmeta
- Updated all plugins to latest versions
- Changed all passwords + implemented 2FA
- Submitted reconsideration request to Google with cleanup evidence
- Implemented weekly scans with our tool
Result: Manual penalty lifted after 3 weeks. Traffic recovered to 80% of original levels after 4 months.
How to Clean Pharma Hack Infection
🔍 Step 1: Identify All Infected Files
Use our scanner + file integrity checker to find all modified files.
Common locations:
- • wp-includes/*.php (especially class-wp-*.php files)
- • wp-content/themes/[your-theme]/*.php
- • wp-content/plugins/[plugin-name]/*.php
- • .htaccess file (check for suspicious redirects)
🗑️ Step 2: Clean WordPress Core Files
Replace all WordPress core files with fresh copies from wordpress.org
Download WordPress → Delete wp-includes/ and wp-admin/ → Upload fresh copies
🗄️ Step 3: Clean Database
Search database for spam keywords and remove injected content.
Tables to check: wp_posts, wp_postmeta, wp_options, wp_users
Search for: viagra, cialis, base64, eval, hidden links
🔐 Step 4: Security Hardening
- ✓ Change all passwords (WordPress, hosting, FTP, database)
- ✓ Update all plugins and themes to latest versions
- ✓ Delete unused plugins and themes
- ✓ Implement 2FA for admin accounts
- ✓ Install security plugin (Wordfence/iThemes Security)
📋 Step 5: Submit Reconsideration Request
If you received a manual penalty, submit reconsideration request to Google.
Google Search Console → Security & Manual Actions → Request Review
Include: What you found, how you fixed it, steps to prevent recurrence
✅ Step 6: Verify Cleanup
Scan your site again with our tool to confirm all malware is removed.
Prevention: How Pharma Hack Happens
Outdated Plugins (60%)
Most common entry point. Update plugins within 24 hours of new releases.
Nulled Themes (25%)
"Free" premium themes from shady sites contain pre-installed malware.
Weak Passwords (10%)
Brute force attacks on admin accounts with simple passwords.
Hosting Vulnerabilities (5%)
Shared hosting compromises affecting multiple sites.
Scan Your WordPress Site for Pharma Hack
Free cloaking detection - find hidden pharmaceutical spam, Japanese keywords, and malicious code in under 60 seconds.
100% Free • No Registration • Detects Cloaking & Hidden Spam