CLEAR SCOPE. FIXED PRICE. WRITTEN HANDOFF.
TidewellShopify systems repair

STORE SECURITY

Spam pages are showing up on your store

Seeing casino, pharmacy, loan or other pages you did not create is a reason to stop and check the store. Do not assume every strange URL means the same thing. Google says hacked content can include new pages, code injected into existing pages, hidden links, or redirects. The first job is to find out what Google and visitors are actually seeing.

1. Save what you found

Copy a few of the strange URLs into a document. Take screenshots of the Google results and note the date. Open one result in a separate browser profile if you can. If it redirects, record where it goes. Do not enter customer or admin information on a suspicious page.

Run a Google search for site:yourdomain.com casino, then repeat with another word that appears in the results. Google recommends the site: operator as a simple way to see pages it has found on your site. Search Console can show more detail than a normal search, so keep the examples you find.

2. Check Search Console

Open Search Console for the property and look at the Security Issues report. Google says this report can show hacked pages it has identified and provide instructions for fixing the problem. Also check the Pages report for a sudden group of URLs you do not recognize.

Look at the Search Console message panel too. Google says it can notify site owners when it detects malware. Check whether the strange URLs are real pages in your store admin or only URLs Google discovered. That distinction changes the next step.

3. Protect access before editing

Change the passwords for the accounts that control the store, hosting, domain and Search Console. Use separate passwords. Review the user list and remove accounts you do not recognize. If the store runs on WordPress and WooCommerce, review WordPress, plugin and theme versions. WordPress recommends keeping WordPress current and getting plugins and themes from WordPress.org or known companies. WooCommerce notes that its security depends on the WordPress installation and recommends keeping WordPress and plugins up to date.

Ask the host or platform for help if you see a warning, redirect or unknown admin. Google also recommends contacting the hosting company or publishing platform when you need support. Save a backup before making large changes. For a WordPress site, include the database and files. Do not overwrite the only copy with a cleanup that you cannot undo.

4. Remove the cause, not just the URLs

Deleting a few spam pages is not enough if the account still has an unwanted user, an old plugin, injected code or a redirect. For WordPress, compare the installation and extensions with clean copies from trusted sources, then update or remove anything you no longer need. Review scheduled tasks, administrator accounts and files that changed around the time the spam began. If you do not have server experience, stop before editing PHP or the database.

For Shopify, check the products, pages, blog posts, navigation and apps in the admin. If the URLs do not exist there, keep your evidence and ask Shopify Support to investigate the storefront behavior. Do not install an app or paste code offered by a page claiming to remove the hack.

5. Recheck Google after the store is clean

Search the sample URLs again. Check the Security Issues report and any warning in Search Console. Google says that after deceptive content is removed, a site owner can request a security review in the Security Issues report. A review can take several days. Request it after the underlying problem is fixed, not after deleting only the visible results.

Keep watching the site: search and Search Console after the review. Unknown pages returning may mean the entry point is still open. Keep WordPress, plugins, themes and the computers used to manage the site updated. Use secure transfer methods such as SSH or SFTP when you have server access.

When to get help

Get help when visitors are being redirected, a browser warning appears, you cannot tell whether the URLs are real pages, or the spam returns after cleanup. A store that takes orders needs a careful backup, access review and written record of what changed. A review request cannot fix code that is still injecting pages.

Pricing

A one-bug Tidewell fix is $299, and larger work gets a written quote ($400 to $1,500). If the cause is unclear, a written diagnosis is $99 and is credited toward the fix within 30 days if you proceed. The scope is agreed before access is needed. No one can promise a Google review outcome, but the work can leave you with a cleaned store, documented changes and the evidence needed for your review.

Describe the issue

COMMON PROBLEMS

Start with the symptom.

Search cleanup

Spam pages are showing up

Unknown casino or spam pages need evidence, access review and careful cleanup.

Read the checklist →

Email delivery

Shopify emails go to spam

Check sender authentication, DNS and notification headers before changing records.

Read the checklist →

Merchant Center

Misrepresentation suspension

Audit store details, policies and product data before requesting another review.

Read the checklist →