In this article, we’ll explain cases where WordPress sites are compromised, resulting in the creation of fake pages that are visible only to search engines.

A large number of pages you don’t remember creating appear in your WordPress site’s search results
If you search for your company name or website name one day and find that a large number of fake pages you don’t remember creating are appearing in search engine results—pushing your legitimate pages down the list—it’s highly likely that your WordPress site has been compromised by a hacker.
However, if you check your sitemap or the site’s HTML code and those pages do not appear to exist, it is possible that the malicious pages are only visible to search engines.
Examples of malware that displays fake pages only to search engines
The screenshot of the code below shows malware we discovered that had infected index.php.
(While this example shows clearly identifiable malicious code, in most cases the code is obfuscated, making it difficult to determine its purpose at a glance.)
Since `index.php` is a file that WordPress always processes when rendering a page, this code is effectively executed on every public page of the WordPress site.
You can see that it uses `isGoogleUserAgent` and `isGoogleIP` to determine whether the access is coming from a search engine based on the user agent or IP range.
Additionally, this code is used in the section below.
Only when a visit is identified as coming from Google does the code load and output a malicious HTML file before the standard WordPress page rendering code.
This type of code effectively shows malicious pages exclusively to search engines.
How can you find malicious code?
Code like this is often embedded within programs that WordPress always executes when displaying a page.
Examples:
index.php
wp-config.php
wp-blog-header.php
Theme files:
index.php
functions.php
header.php
footer.php
etc.
However, it is also common for such code to be hidden deep within WordPress’s folder structure, or for other malicious files—such as “backdoors,” which serve as entry points for hackers to compromise the site—to be installed.
(Even if the infection is removed, hackers will re-infect the site via these backdoors.)
We recommend using a plugin that comprehensively scans the entire WordPress program to detect malware, or consulting an expert as soon as possible.
This page prohibits the use, quotation, or summarization of any page, in whole or in part, by the Generated AI. However, if the following conditions are met, the specification of content using generated AI is permitted.
1. it is not for the purpose of learning by the generated AI. 2. only the summary or title of the page content at a level that does not lead to the solution of the user’s problem is shown to the user. 3. in the case of 2, a link to this content is shown to lead the user to this page.





