WordPress SEO spam can survive inside wp_posts and wp_postmeta after suspicious files are removed. Attackers may alter real pages, hidden drafts, revisions, or metadata that a plugin later renders.
A global search-and-replace is unsafe. Preserve the database, identify changed records, remove the writer, and repair only confirmed malicious values.
I’m Ryohei Yokoyama, founder of SiteFixNow. I’ve worked as an IT engineer for over 20 years and have handled many WordPress recovery, malware removal, hacked site repair, and security cleanup cases. This guide explains how to investigate database SEO spam without sacrificing legitimate content.
- How SEO spam appears in posts, revisions, metadata, and rendered pages
- Which read-only queries help narrow the incident without changing data
- Why the writer or backdoor must be removed before database cleanup
- How to repair targeted records and prove the spam does not return
WordPress SEO spam in wp_posts and wp_postmeta must be confirmed before cleanup
Start by proving what visitors and search engines receive. SEO spam may appear as pharmaceutical links, casino terms, doorway pages, unfamiliar canonical URLs, injected JavaScript, or titles in another language. It may affect only logged-out visitors, mobile users, or requests arriving from a search engine.
Compare the visual page and source with the editor, REST output, database value, cached HTML, XML sitemap, and Search Console. A clean editor does not prove that metadata or a template is not adding spam later.
The related Japanese Keyword Hack guide explains the wider symptom pattern. This article focuses on the database evidence and safe record-level repair process.
- Unknown content or recent unexplained modifications
- Links, scripts, iframes, or encoded strings inside legitimate post content
- Unexpected metadata, SEO, canonical, or redirect values
- Spam that returns after a page is edited or a cache is purged
WordPress SEO spam evidence should be preserved before any database edit
Export the full database before editing. Store it outside the public web root, record the time zone, and note affected URLs, suspicious domains, and recent admin or plugin changes.
Confirm the table prefix in wp-config.php; examples use wp_, but your site may not. Identify multisite and staging tables before querying them.
# Run from the correct WordPress document root.
wp option get home
wp option get siteurl
wp db export incident-before-cleanup.sql
# Preserve a suspected post and its metadata.
wp post get 123 --field=content > post-123-before.html
wp post meta list 123 --format=json > post-123-meta-before.json
If you also suspect altered files, use the malware and hidden-backdoor scanning guide before treating the database as the only infected layer.
WordPress SEO spam in wp_posts can be narrowed with read-only queries
Query first and edit later. Review IDs, types, statuses, parents, timestamps, titles, excerpts, and content. Include revisions, reusable blocks, navigation items, templates, and attachments—not only published posts.
List recently modified records and unexpected post types
SELECT ID, post_type, post_status, post_parent,
post_date_gmt, post_modified_gmt,
LEFT(post_title, 100) AS title_preview
FROM wp_posts
WHERE post_modified_gmt >= '2026-09-01 00:00:00'
ORDER BY post_modified_gmt DESC
LIMIT 500;Use the confirmed prefix and incident window. A recent timestamp is a lead, not proof; editing, imports, updates, and revisions also change rows.
Search indicators without trusting one keyword
SELECT ID, post_type, post_status,
LEFT(post_title, 100) AS title_preview,
LEFT(post_content, 240) AS content_preview
FROM wp_posts
WHERE post_content LIKE '%bad-domain.example%'
OR post_excerpt LIKE '%bad-domain.example%'
OR post_title LIKE '%unexpected spam phrase%'
ORDER BY post_modified_gmt DESC;Search observed indicators such as a destination domain, script fragment, or exact phrase. Broad words create false positives. Review parents and revisions before deletion because a clean revision may preserve the page.
WordPress SEO spam in wp_postmeta requires context, not bulk deletion
wp_postmeta holds builder layouts, custom fields, SEO settings, product data, and serialized values. An unfamiliar value may be legitimate, while a familiar key may contain injected code.
Join metadata to its parent post, compare repeated keys with clean records from the same plugin, and confirm how each value is rendered before changing it.
SELECT pm.meta_id, pm.post_id, p.post_type, p.post_status,
LEFT(p.post_title, 80) AS post_title,
pm.meta_key, LEFT(pm.meta_value, 240) AS value_preview
FROM wp_postmeta AS pm
LEFT JOIN wp_posts AS p ON p.ID = pm.post_id
WHERE pm.meta_value LIKE '%bad-domain.example%'
OR pm.meta_value LIKE '%unexpected script fragment%'
ORDER BY pm.post_id, pm.meta_key;Never delete every row matching a common string. Export matches first. Repair contaminated builder or SEO fields through their plugin when possible so serialized data remains valid.
For broader file-and-database context, review WordPress malware cleanup across files, database records, and backdoors.
WordPress SEO spam will return unless the code or account writing it is removed
Repair is temporary if the writer survives. Compare row changes with access logs, admin activity, plugin updates, scheduled jobs, file timestamps, and outbound requests.
- Infected plugins, themes, mu-plugins, or snippets
- Stolen WordPress, database, or hosting access
- Scheduled actions, cron jobs, or external automation
- Backdoors in writable folders or neighboring sites
Quarantine confirmed malicious code, replace compromised software from trusted packages, remove unknown privileged users, revoke sessions, rotate affected access, and patch the entry point. The manual WordPress malware cleanup guide explains the wider order of operations.
WordPress SEO spam cleanup should repair only confirmed records
After disabling the writer, export again and create a cleanup list. Record each table, primary key, evidence copy, clean value, reason, operator, and time.
Use WordPress or the responsible plugin when practical. Trash a confirmed spam post before permanent deletion. Restore an infected legitimate page from a verified revision or replace only the bad fragment.
# Recheck and trash a confirmed spam post.
wp post get 456 --fields=ID,post_type,post_status,post_modified,post_title --format=json
wp post delete 456
# Delete only a confirmed malicious key.
wp post meta delete 123 confirmed_malicious_key
wp post delete normally uses trash; avoid --force on the first pass. Repair builder or SEO keys through their plugin instead of deleting them blindly.
WordPress SEO spam recovery is complete only after cache and search verification
Repeat the indicator queries, compare exports, and inspect affected URLs while logged out. Check source, REST output, sitemaps, canonical tags, structured data, and mobile rendering.
After preserving evidence, purge WordPress, object, server, CDN, and browser caches. Check Search Console, and request removal or reindexing only after clean responses are stable.
Monitor through the original recurrence window. Compare row times, file hashes, users, jobs, logs, and outbound traffic. Then follow the post-malware WordPress hardening guide.
WordPress SEO spam database cleanup FAQ
WordPress SEO spam in wp_posts and wp_postmeta needs evidence-first repair
Confirm the rendered symptom, export the database, identify records with read-only queries, disable the writer, repair confirmed values, and verify every output layer.
If customer data, revenue pages, many records, or multiple sites are affected, stop experimental edits. Structured recovery is safer than rebuilding after uncontrolled cleanup.
If You Can’t Secure or Recover Your WordPress Site Yourself

If your website shows malware warnings, redirects to strange pages, or you are not sure whether it is secure,
SiteFixNow can help clean, repair, and recover your WordPress site.
- Your WordPress site may be infected with malware.
- Security warnings appear in Google or browser results.
- You found unknown admin users or suspicious files.
- The site redirects to spam or unknown websites.
- You need urgent WordPress hacked site repair.
- Reduce visitor risk and SEO damage.
- Find hidden malware and backdoors, not only visible symptoms.
- Recover the site safely without unnecessary data loss.
