Found Spam Text on Your Own Site? Don't Buy SEO Yet
Contents8
A Singapore business owner could have opened their homepage today, read it top to bottom, and seen nothing wrong. We fetched that same homepage as a search engine would and found four long paragraphs about an online gambling platform sitting above the business's own copy. The word "casino" appeared 224 times in the HTML, 204 of them in the visible text.
If that is your site, no amount of marketing spend fixes it, and the first invoice you should pay is your developer's, not an agency's. We are an agency saying that, and we mean it. Buying search work for a site carrying content you never wrote is paying to amplify someone else's page.
This is not rare enough to ignore. It was 1 of 10 pages in a small sample we ran the same day.
What injected content actually looks like
It looks like nothing, in a browser. That is the whole design.
Google's spam policies call this hacked content, defined as "any content placed on a site without permission, due to vulnerabilities in a site's security", and the policy separates it into kinds. Code injection puts code into your existing pages. Page injection adds new pages you never made. Content injection, which is the one that caught our eye, is when someone tries to "subtly manipulate existing pages on your site", adding text search engines read and visitors do not notice. Redirects send some visitors elsewhere depending on the referrer, the device or the user agent.
The page we found looked like content injection. Its title tag was correct and described the business. Its meta description was correct. Its navigation worked. The injected block sat in the body, where a visitor scrolling a phone would skate past it looking for a phone number, and where a crawler reading raw HTML would meet it first.
The detail that matters commercially: the first long paragraph on that page, the paragraph a machine is most likely to quote when summarising what the business does, was about something else entirely.
Why the owner is the last to know
Three reasons, all boring.
You do not read your own homepage. You built it two years ago, you check it on your phone for the phone number, and the top of the page is a slideshow you stopped noticing. Nobody reads their own site the way a stranger does.
The injected text is usually styled to be unobtrusive or placed where your theme does not render it prominently. It is written for a crawler, not for you.
And your enquiries do not fall off a cliff. People who already know your name still ring you. What you lose is the slow half: the search where someone did not know you, found you, and judged you in six seconds.
Demand for the answer is real and badly served. We pulled Google Autocomplete for the Singapore market on 5 October 2026 and 7 of the 32 suggestions for "website hacked" were an owner trying to act: "website hacked what to do", "website hacked checker", "website hacked check", "how to check website hacked or not", "how to fix hacked website", "how to recover hacked website", "how to report hacked website". The rest were news, curiosity, courses and people asking how it happens at all.
15 of 60 slots in one category were auto-generated pages
Injected content on your site is one half of this. The other half is sitting in the results you are trying to win.
On 5 October 2026 we ran four Singapore pest control searches through our own metasearch and tagged all 60 result slots by what held them. 23 slots were a Singapore provider's own website. 15 were auto-generated blog pages spread across 12 different throwaway hosts, with titles in the familiar spun pattern: "Top Guidelines Of", "An Unbiased View of", "5 Easy Facts About". 12 were overseas pages, some about other countries entirely. The remainder were best-of lists, a marketplace, a social page, a magazine, a press-release site and a cleaning company.
So 37 of 60 slots were not a Singapore provider, and a quarter of the whole set was machine-made filler. Those pages are the same economics as the text injected into a real business's homepage: volume, placed where a crawler will read it.
Google's spam policies describe scaled content abuse as "when many pages are generated for the primary purpose of manipulating search rankings and not helping users", and say sites in breach "may rank lower in results or not appear in results at all". We are not accusing anyone of anything and we name none of these hosts. For your decision only one thing matters: these are not competitors you need to beat on quality, and building a page to out-argue them is the wrong use of a budget.
The 15-minute check, in order
Do these four in order. Stop as soon as one comes back dirty, because the next step is a developer either way.
- Read your own raw HTML. Open your homepage, press Ctrl+U to view source, then Ctrl+F and search for words that have no business being there: casino, slot, togel, judi, loan, viagra, escort, replica. Search for the name of any industry that is not yours. Two minutes.
- Search Google for your own domain. Type
site:yourdomain.cominto Google and page through the results. You are looking for page titles you do not recognise, URLs in another language, or far more pages than you have ever published. This catches page injection, which view-source will not. - Open the Security issues report in Search Console. Google's help page says the report shows its findings when "your site was hacked, or that it exhibits behavior that could potentially harm a visitor or their computer", and that affected pages "can appear with a warning label in search results or an interstitial warning page in the browser". If you have no Search Console access, that is its own problem and worth fixing today. The Security issues report documentation explains what each finding means.
- Load your homepage from a Google search result, on a phone, on mobile data. Not from a bookmark. Redirect injections often fire only on a particular referrer or device, so the bookmark route is the one path that looks fine.
If all four come back clean, you can stop reading. This is not your problem, and whatever is wrong with your search performance is an ordinary marketing problem. Our guide to what a real SEO audit covers is the better next read.
When this is not your problem, and when it is
The check above is cheap enough that the honest answer is to run it regardless. What you do with a dirty result depends on what you found.
Injected text in your existing pages, or pages you never created, is a hosting and development job. Your web developer, your host's support desk, or an IT contractor removes the content, finds how it got in, patches that, and changes the credentials. An SEO agency is not the right supplier for any step of that, and an agency that offers to "clean it up" as part of a monthly retainer should be asked exactly who is doing the patching.
A security warning showing in Search Console is the same job, with a review request at the end once the site is clean.
Auto-generated pages holding slots in your category are not your problem to fix at all. You cannot remove someone else's page. You can report it to Google through its spam reporting form, and then you should go back to your own site, because that is the only surface you control.
What a clean-up costs, and what it does not buy
A small Singapore business site cleaned, patched and credential-rotated is typically a day or two of a developer's time, plus whatever your host charges for a restore. We are not going to put a dollar figure on it, because we do not sell that work and have not priced it this year.
What it buys is the removal of an own-goal. It does not buy a ranking. A clean homepage that still opens with a paragraph about your company's "passion for excellence" will not be quoted by anything, and clearing injected text does not improve a page that was never specific in the first place.
And the part that costs us: if your check comes back dirty, do not hire us this month. Hire the developer, get the site clean, let Google re-crawl it, and then look at whether search work is worth buying. Spending on content and links while a site serves someone else's pages is the clearest version of the argument we make in three times SEO is the wrong thing to buy.
There is a sibling check worth running at the same time, since it costs another five minutes and fails for different reasons: whether crawlers can reach your pages at all, which we set out in before you buy AI visibility, check the bot gets in. Two of the twelve pest control sites we queued for today's licence study refused our fetcher outright.
One next step
Send us your domain and we will run all four checks and tell you plainly which bucket you are in: clean, a developer's job, or an ordinary marketing problem. If it is the middle one we will say so and send you away. It starts as a free visibility check through our contact page.
Figures here come from pages and search results we fetched on 5 October 2026: a 10-page Singapore pest control sample, 60 tagged result slots from four metasearch queries, and 32 Google Autocomplete suggestions for the Singapore market. No business is named, and nothing here is a statement about any company's security.
FAQ
How do I know if my website has injected spam content?
Read your own raw HTML with Ctrl+U and search it for words from industries that are not yours, then run a site:yourdomain.com search in Google looking for page titles you do not recognise. Then check the Security issues report in Search Console. Each takes a few minutes and together they cover the common cases.
Can a hacked page look completely normal in a browser?
Yes. Google's spam policies describe content injection as an attempt to "subtly manipulate existing pages on your site", with text search engines read that is harder for owners and visitors to spot. The page we found had a correct title, a correct meta description and working navigation.
Should I pay an SEO agency to fix a hacked site?
In our view, no. Removing injected content, finding the vulnerability, patching it and rotating credentials is development and hosting work. Have your developer or host do it, then reconsider search spend once the site is clean and Google has re-crawled it.
What about the spam pages ranking in my category?
You cannot remove someone else's page, and we would not spend a budget trying to outrank machine-made filler. Report it to Google through its spam reporting form if you want to, then put the effort into your own pages, which are the only surface you control.
Does Google warn you when your site is hacked?
Sometimes, through the Security issues report in Search Console. Google says affected pages "can appear with a warning label in search results or an interstitial warning page in the browser". That is a reason to have Search Console connected to your own account rather than only your agency's.