WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Negative SEO vs WordPress malware

Junk backlinks often look like negative SEO when the real problem is malware on WordPress. Clean the site first. Disavow in Search Console only after the install is clean.

Topics Hardening & checklists

Updated Published

Negative SEO vs WordPress malware Open larger image: Negative SEO vs WordPress malware

“Negative SEO” usually means someone pointing junk links at your domain to hurt rankings. On WordPress it is less common than people claim, and less effective than a compromise that injects spam on your host.

If Search Console, Ahrefs, or another crawler suddenly shows toxic backlinks, start by splitting two problems. Do not open with a disavow file.

ProblemWhat it looks likeFirst move
On-site spam or malwareInjected pages, hidden links, redirects, cloaked junk for GooglebotIncident response. Not a disavow file.
External junk backlinksWeird domains linking to you with spam anchorsOften ignore. Disavow only clear networks after the site is clean.

A hacked site that manufactures its own spam pages will keep looking like negative SEO until you clean the install.

If the damage is on your WordPress site

Stop the disavow project.

Signs that this is malware, not a link attack:

  • Search Console Hacked content or Security Issues
  • site:yourdomain.com shows pharma, gambling, or foreign-language titles you did not publish
  • Redirects for Googlebot or mobile visitors only
  • Unknown posts, plugins, or admins

Start with signs your WordPress site is hacked, then WordPress malware removal. After the install is actually clean, recover indexing with SEO recovery after a hack.

Run a malware scanner and a vulnerability scan. If cleanup keeps looping, hire help.

Google already discounts a lot of obvious spam. A handful of random directory links with no ranking loss is not an emergency.

Useful signals (combined, not one tool score):

  • Sudden spikes of low-quality referring domains with matching spam anchors
  • Foreign-language gibberish sites linking with money keywords
  • Link graphs that look automated (thousands of near-identical domains in days)
  • Ranking drops that line up with on-site spam in Search Console, not only new backlinks

Less useful:

  • A single “toxic” score with a healthy site and no ranking loss
  • Random directory links that have been there for years
  • Competitor paranoia without evidence

Disavow only after cleanup (Search Console, not the crawler)

Backlink tools help you find candidate domains. Google Search Console is where you submit the file. There is no button in Ahrefs (or similar) that sends a disavow list to Google.

  1. Confirm the site is clean.
  2. Export suspicious linking domains from Search Console or a backlink crawler. Focus on networks you can explain, not every low-DR mention.
  3. Build a UTF-8 plain-text list. Prefer domain:spam-network.example when the whole site is junk. Use a single URL line only when one page is spam and the rest of the site is fine.
  4. Upload it in Google’s disavow tool for the correct property (domain vs URL-prefix). Wrong property is a common silent miss.
  5. Keep a copy. Revisit when new evidence appears. Do not rebuild the file weekly out of anxiety.

Example shape:

# Toxic networks reviewed after malware cleanup
domain:obvious-spam-network.example
domain:another-pbn-dump.example

Chase malware and indexing issues harder than a vanity toxic score. Background: why website security matters for SEO.

Hardening so the next mess is smaller

  1. Keep core, plugins, and themes updated (checklist)
  2. Harden logins with 2FA and login protection
  3. Run scheduled malware and vulnerability checks
  4. Watch Search Console security messages
  5. Keep restore-tested backups

Security Ninja Free covers tests and vulnerability checks. Pro adds firewall and malware scanning when you want active blocking. Free on WordPress.org or pricing.

Bottom line

Most “negative SEO” panic on WordPress is either ignored junk or an on-site infection wearing a backlink costume. Clean first. Disavow in Search Console only when leftover external networks are still worth a scalpel.

Found this useful? Share it.

Frequently asked questions

Is a spike of toxic backlinks usually negative SEO? +

Often no. On WordPress, injected spam pages, hidden links, and crawler-only redirects are more common than a rival pointing junk links at you. Check the site itself before you build a disavow file.

Should I disavow links before cleaning WordPress? +

No. If malware is still manufacturing spam URLs, a disavow file is busywork. Clean and confirm the install, then decide whether leftover external junk is worth a Search Console disavow.

Does Ahrefs submit a disavow file to Google? +

No. Ahrefs (or Search Console’s link reports) can help you find candidate domains. You still upload a plain-text list in Google’s disavow tool for the correct property.

When should I actually disavow? +

After the site is clean, and only for clear, persistent spam networks you can explain. Google already discounts a lot of obvious junk. Overusing disavow can throw away links you later wish you had kept.

Larger screenshot

Enlarged image