Spam URL patterns
Slugs, directories and parameters help identify how the pages are generated.
Gambling, pharmaceutical, fake-product or unknown pages can indicate an SEO spam compromise. The work has two parts: stop what is generating the spam and clean up the search signals already collected.
Indexed URLs are the visible symptom. The cause may sit in files, database records, plugins, users, scheduled tasks or server rules serving different content to crawlers.
Slugs, directories and parameters help identify how the pages are generated.
Added XML files can push large volumes of spam URLs to search engines.
Files, plugins or scheduled tasks can recreate spam after superficial cleanup.
Altered posts, options or records can keep generating malicious pages.
Admin or hosting access may keep the incident open.
Redirects or configuration can serve different content to crawlers and visitors.
The compromise is removed first, then the search index is cleaned up.
Collect URLs, patterns, sitemaps and anomalous behavior without immediately deleting useful evidence.
Inspect application, users, files, database, scheduled tasks and server configuration.
Remove malicious components and restore files or packages from trusted sources.
Rotate relevant credentials and review privileges and entry points.
Review status codes, sitemaps, redirects and residual signals so spam URLs can leave the index.
Security and SEO are reviewed together, but with different goals.
The site needs to stay clean and search engines need consistent signals for URLs that should no longer exist.
Send a few example URLs. We can check the compromise, persistence and search impact.