Detect WordPress Pharma Hack & Japanese Keyword Spam

Free scanner to detect the most common WordPress hack - pharma spam injection with viagra/cialis keywords and Japanese/Russian spam cloaking.

💊

The #1 Most Common WordPress Hack

The "Pharma Hack" affects over 500,000 WordPress sites annually. Hackers inject hidden pharmaceutical spam (viagra, cialis, etc.) that's only visible to search engines, causing your site to rank for embarrassing keywords and potentially get deindexed by Google.

Detection is critical: Most site owners don't realize they're hacked until Google Search Console shows thousands of spam pages or their rankings completely disappear.

What is the Pharma Hack?

The Pharma Hack is a sophisticated cloaking attack where hackers inject spam content promoting pharmaceuticals (viagra, cialis, levitra) or other products. The malicious code shows different content to search engines versus regular visitors.

👤 What Regular Visitors See

Your normal website content - blog posts, pages, products. Everything looks completely normal.

🤖 What Googlebot Sees

Spam content: "Buy Viagra Online", "Cheap Cialis", pharmaceutical links, Japanese/Russian keywords, gambling sites.

⚠️ Why It's Dangerous: Google sees spam content and penalizes or deindexes your site. You lose all organic traffic overnight. Recovery can take 3-6 months even after cleanup.

Common Pharma Hack Variations

💊 Classic Pharma Spam

Injection of pharmaceutical keywords and links throughout your site's HTML, visible only to search engine crawlers.

Common Keywords Injected:

viagra cialis levitra pharmacy buy pills online cheap medication

🈯 Japanese Keyword Spam

Injection of Japanese characters promoting gambling, adult content, or counterfeit goods. Extremely common in 2023-2024.

What Our Scanner Detects:

  • ✓ Japanese/Chinese/Korean characters in meta tags
  • ✓ Cloaked content showing different languages to bots
  • ✓ Hidden links to gambling/adult sites
  • ✓ Spam pages with Asian character URLs

🎰 Gambling & Adult Spam

Links and keywords for online casinos, poker sites, adult content - often combined with pharma spam.

Common Indicators:

  • ✓ Casino/poker/gambling keywords in title tags
  • ✓ External links to .ru, .cn, .tk domains
  • ✓ Hidden divs with spam content (display:none)
  • ✓ Meta refresh redirects to gambling sites

👜 Counterfeit Goods Spam

Spam promoting fake designer goods, replica watches, counterfeit handbags - often targeting high-value keywords.

Typical Patterns:

  • ✓ "Replica", "fake", "knockoff" keywords
  • ✓ Designer brand names + "cheap" or "discount"
  • ✓ Links to suspicious e-commerce sites
  • ✓ Cloaked product pages only visible to bots

How to Tell If You're Hacked

🔍

Google Search Console Warnings

Alerts about "hacked content", "cloaking", or "thin content with little value"

📉

Sudden Traffic Drop

Organic traffic drops 50-100% overnight without explanation

🔎

Weird Google Results

Your site shows up for "viagra", "cialis", Japanese keywords you never targeted

📄

Spam Pages in Index

site:yourdomain.com shows thousands of pages you didn't create

⚠️

Browser Warnings

"This site may be hacked" or "Deceptive site ahead" warnings

🔗

Suspicious Links in Source

View source shows hidden links to pharmaceutical/gambling sites

📧

Spam Emails from Your Domain

Your domain is sending pharmaceutical spam emails

🌐

Modified Core Files

WordPress core files have unexpected modifications or timestamps

How to Use Our Scanner to Detect Pharma Hack

1

Enter Your Homepage URL

Start with your main domain to check for cloaking on the homepage.

https://yourdomain.com
2

Check the Cloaking Detection Results

Our scanner compares what Googlebot sees vs. what regular users see. Look for:

  • Content similarity < 95%: Strong indicator of cloaking
  • Different meta titles/descriptions: Pharma keywords in bot version
  • Length differences > 20%: Hidden spam content
3

Review Hidden Elements

Check for hidden divs, CSS cloaking, and invisible text containing spam keywords.

4

Check External Links

Look for suspicious links to pharmaceutical, gambling, or adult sites - especially to .ru, .cn, .tk domains.

5

Scan Multiple Pages

Test several pages - hackers often inject spam on specific pages only:

  • Homepage
  • Top blog posts (check Google Analytics for most visited)
  • Category/archive pages
  • Old posts (often targeted due to lack of monitoring)

Real-World Case Study

📰

News Blog - 95% Traffic Loss in 48 Hours

Industry: News & Media | Platform: WordPress 5.8 | Traffic: 50,000/month → 2,500/month

The Problem:

A popular news blog saw organic traffic drop from 50,000 to 2,500 monthly visitors in just 48 hours. Google Search Console showed "Manual Action: Hacked Content" penalty.

What Our Scanner Found:

  • Cloaking detected: 47% content similarity between Googlebot and regular users
  • Meta title for Googlebot: "Buy Viagra Online - Cheap Cialis - Pharmacy"
  • Meta title for users: Original news article title (normal)
  • 1,247 hidden links to pharmaceutical sites in footer (display:none)
  • Japanese keywords injected in <head> section
  • Modified wp-includes/class-wp-widget.php with base64 encoded spam

Root Cause:

Outdated "Contact Form 7" plugin (version 4.9) with known vulnerability. Hackers exploited it to inject malicious code into WordPress core files and database.

The Impact:

  • $12,000/month in lost ad revenue (4 months to recover)
  • Manual penalty from Google (required reconsideration request)
  • Brand reputation damage (site showed up for viagra searches)
  • 3 weeks of full-time work to clean and restore

✅ How It Was Fixed:

  1. Restored WordPress core files from clean backup
  2. Cleaned database: removed spam from wp_posts, wp_options, wp_postmeta
  3. Updated all plugins to latest versions
  4. Changed all passwords + implemented 2FA
  5. Submitted reconsideration request to Google with cleanup evidence
  6. Implemented weekly scans with our tool

Result: Manual penalty lifted after 3 weeks. Traffic recovered to 80% of original levels after 4 months.

How to Clean Pharma Hack Infection

🔍 Step 1: Identify All Infected Files

Use our scanner + file integrity checker to find all modified files.

Common locations:

  • • wp-includes/*.php (especially class-wp-*.php files)
  • • wp-content/themes/[your-theme]/*.php
  • • wp-content/plugins/[plugin-name]/*.php
  • • .htaccess file (check for suspicious redirects)

🗑️ Step 2: Clean WordPress Core Files

Replace all WordPress core files with fresh copies from wordpress.org

Download WordPress → Delete wp-includes/ and wp-admin/ → Upload fresh copies

🗄️ Step 3: Clean Database

Search database for spam keywords and remove injected content.

Tables to check: wp_posts, wp_postmeta, wp_options, wp_users

Search for: viagra, cialis, base64, eval, hidden links

🔐 Step 4: Security Hardening

  • ✓ Change all passwords (WordPress, hosting, FTP, database)
  • ✓ Update all plugins and themes to latest versions
  • ✓ Delete unused plugins and themes
  • ✓ Implement 2FA for admin accounts
  • ✓ Install security plugin (Wordfence/iThemes Security)

📋 Step 5: Submit Reconsideration Request

If you received a manual penalty, submit reconsideration request to Google.

Google Search Console → Security & Manual Actions → Request Review

Include: What you found, how you fixed it, steps to prevent recurrence

✅ Step 6: Verify Cleanup

Scan your site again with our tool to confirm all malware is removed.

Prevention: How Pharma Hack Happens

🔌

Outdated Plugins (60%)

Most common entry point. Update plugins within 24 hours of new releases.

🎨

Nulled Themes (25%)

"Free" premium themes from shady sites contain pre-installed malware.

🔑

Weak Passwords (10%)

Brute force attacks on admin accounts with simple passwords.

🌐

Hosting Vulnerabilities (5%)

Shared hosting compromises affecting multiple sites.

Scan Your WordPress Site for Pharma Hack

Free cloaking detection - find hidden pharmaceutical spam, Japanese keywords, and malicious code in under 60 seconds.

100% Free • No Registration • Detects Cloaking & Hidden Spam