Skip to content

Audit record 8 min read Updated September 23, 2026

Dozens of pages were quietly carrying hidden spam text that visitors never saw

In short

An online continuing-education academy for licensed healthcare providers, based in the Portland, Oregon metro area, had a large share of its pages secretly carrying injected spam text for an unrelated gambling site, hidden with styling that pushed it far off screen. Visitors saw nothing unusual. Search engines saw it on every one of those pages.

Key facts

  • More than a quarter of the pages we checked contained hidden text promoting an unrelated gambling site, none of which was visible to a normal visitor scrolling the page.
  • The hidden text was pushed off screen using page styling, positioned far outside the visible area rather than being deleted or blocked by any security tool.
  • The affected pages included the business's own main checkout and enrollment funnels, meaning the injected content sat directly on pages tied to real financial transactions.
  • This kind of injection typically happens through a compromised plugin or an outdated piece of website software, not through any action the business itself took.
  • Search engines read a page's underlying code, not just what a visitor sees, so this content was fully visible to them even while invisible to every human who viewed the same page.

The finding

A meaningful share of this site's pages had been quietly compromised. Hidden inside otherwise normal page content was a block of text promoting an unrelated offshore gambling site, positioned using styling that pushed it thousands of pixels off screen, far outside anything a visitor would ever scroll to.

No visitor would ever notice, because there was nothing visible to notice. The text lived only in the page's underlying code, exactly where a search engine looks when it reads and ranks a page.

What we looked at

We saved and read the underlying code of every page on the site, not just what rendered visibly in a browser, specifically searching for content that did not match the business's own language, topic, or branding. The gambling-related text stood out immediately once we looked at the raw code rather than the visible page.

We mapped exactly which pages were affected and found the injected content sitting on a large share of the site, including some of its most important, highest-traffic pages, the ones tied directly to enrollment and payment.

Why it mattered for leads

This is not a cosmetic problem. Search engines actively watch for exactly this pattern, hidden text unrelated to a site's real content, because it is a well-known signature of a hacked website being used to promote something else. A site flagged this way can be demoted in search results or blocked outright with a visible warning to anyone who tries to visit it.

For a business whose enrollment and payment pages carry real financial transactions, that risk sits directly on top of the pages that matter most. A warning label or a ranking penalty on those specific pages does not just cost visibility, it can interrupt paying customers mid-purchase.

False positive checks we ran

We confirmed the hidden text was not simply an unusual but legitimate design choice, an off-screen element used for accessibility purposes, by checking its actual content. Legitimate off-screen text serves a specific technical purpose and never links out to an unrelated gambling domain, which this content did, repeatedly, across every affected page.

We also confirmed the pattern was consistent with a known type of website compromise, rather than a one-off scripting error, based on how uniformly the hidden text and its positioning styling appeared across dozens of otherwise unrelated pages.

The fix

None of the hidden or injected content was carried into the rebuilt site in any form. The new site was built fresh, on a different technical foundation, specifically so that no compromised code, plugin, or leftover file from the old platform could travel forward into the new one.

We also flagged the finding as urgent and separate from the rest of the marketing work, since a live compromise is a security matter first, deserving immediate attention on its own, well ahead of any conversation about design or content.

How to check your own site for this

Right click on any page of your own site in a browser and choose the option to view the page's source code, then search that code for words that have nothing to do with your business, gambling, unrelated pharmaceutical terms, or foreign-language spam links are common patterns. If anything unexpected turns up, do not assume it is harmless just because you cannot see it on the page itself.

If you find anything, treat it as urgent. Get the affected software or plugins updated and cleaned immediately, and check whether your search console account is showing any security warnings, since this kind of issue tends to spread across more pages the longer it goes unaddressed.

Related questions

Real findings from SearchPod proposal reviews, anonymized; platforms change, records are dated.

Want your site audited the same way?

Get a free, no-obligation proposal within one business day. We look at your site and your market and tell you plainly what we would do, and what we would not.

Get your free proposal

Keep reading

More in Audit library

All 40 in Audit library