Spam Comments and Gambling/Casino Posts in WordPress: How to Clean Them Up for Good
How to handle spam comments and gambling or casino spam posts in WordPress, from moderation and user audits to database cleanup and prevention so they do not return.
Spam comments are annoying, but many times they are still just a cleanup job. Gambling or casino spam posts are much more serious. If your WordPress dashboard suddenly shows posts, pages, drafts, or scheduled content you never created, especially if some of it is already indexed by Google, treat it as a security incident, not ordinary spam.
The problem is that these two cases are often mixed together. A website owner sees lots of strange comments and installs an anti-spam plugin, while the real issue is actually a compromised administrator account. On the other hand, some owners panic and assume the whole website has been hacked when in reality the comment form is simply open without moderation.
The short answer is this: spam comments and gambling/casino spam posts in WordPress must first be separated into ordinary spam versus a real security compromise. If the issue lives only in comments, the focus is moderation, CAPTCHA or Turnstile, anti-spam filtering, and discussion settings. If the issue has reached posts or pages you did not create, the focus must shift to user audits, plugin audits, the database, scheduled tasks, and possible backdoors.
This guide covers both situations in a problem-solution format so you can tell which steps actually solve the problem instead of only tidying up the symptoms.
First, separate ordinary spam from a hacked site
Before you clean anything, answer this question: is the problem only comment spam, or has it already reached the post, page, or user level?
It is usually still “ordinary spam” if:
- the spam only appears as comments, and all of it is in moderation or the spam folder;
- there are no suspicious new user accounts;
- there are no unknown posts, pages, or custom post types;
- the website does not redirect to another domain;
- Search Console shows no unusual URL spike.
It is strongly suspicious of compromise if:
- there are gambling or casino posts, pages, drafts, or scheduled posts;
- there is an author, editor, or admin account you do not recognise;
- spam comments appear even though comments were already closed;
- the permalink settings, homepage, widgets, or sitemap changed on their own;
- Google search results begin showing spam URLs from your domain.
If you are in the second category, do not stop at anti-spam plugins. You need to approach it the same way as a website hacked case.
Problem 1: spam comments arrive every day
What does it look like?
Every day there are dozens, hundreds, or even thousands of comments waiting. They promote casinos, gambling, betting, loans, pills, or random links. Sometimes they use normal-looking names, sometimes strange letter-number combinations. Left alone, they make the dashboard noisy, overload email notifications, and create the risk that some spam slips through to the public page.
Why does this happen?
The most common causes are simple:
- the comment form is open on every old and new post;
- comments publish immediately with no moderation;
- there is no bot protection on the comment form;
- pingbacks and trackbacks are still enabled;
- there is no automatic spam filtering.
Google discusses user-generated spam directly and recommends moderation, blocklists, automated abuse prevention, and regular monitoring for comments and other public inputs.
How to fix it properly:
- Turn on comment moderation. At minimum, new comments should require manual approval before publishing.
- Close comments on content that does not need them. Many company profile websites do not need comments at all.
- Disable pingbacks and trackbacks if you do not use them.
- Add bot protection to comment forms, login forms, and registrations.
- Use an anti-spam plugin so high-risk comments do not fill the manual queue.
- Delete old spam comments so the database does not keep getting heavier.
WordPress plugins worth considering:
- Akismet to filter comments and form submissions that look like spam.
- Antispam Bee if you want an alternative focused on native WordPress comments with a privacy-friendly approach.
- Simple CAPTCHA with Cloudflare Turnstile to add human verification to comments, login, registration, and multiple WordPress forms.
- Disable Comments if the website does not need comment functionality at all.
The mistake people keep making: deleting spam comments one by one without closing the form or adding a filter. The next morning, the queue is full again.
Prevention: if comments are not an important part of your content strategy, it is safer to disable them. If they are important, combine moderation, anti-spam, and bot protection. Do not rely on only one of those.
Problem 2: spam comments go live and carry gambling or casino links
What does it look like?
The comments are not only arriving; they are appearing on public pages. That is worse than a full moderation queue, because spammers are now borrowing your domain’s reputation. They often use anchor text such as gambling phrases or casino terms that can damage page quality and reduce visitor trust.
Why does this happen?
- comments publish automatically without moderation;
- the whitelist rules are too relaxed;
- anyone whose comment was approved once can post freely afterward;
- the comment form has no protection;
- old pages are rarely checked.
How to fix it:
- Turn on moderation for all new comments.
- Disable overly permissive auto-approval rules, at least until the situation is stable.
- Review older pages that still allow comments.
- Edit or remove the comments that already went live.
- Make sure links in user comments are treated as untrusted user-generated content.
On websites that are attacked heavily, consider stricter rules: comments only on selected articles, limited comment windows, and mandatory anti-spam checks for everything submitted.
Prevention: include old content in a daily or weekly review. High-traffic articles often become spam targets because they carry more SEO value for spammers.
Problem 3: gambling/casino spam posts, pages, drafts, or scheduled posts appear
What does it look like?
This is the point where the issue stops being “just spam” and becomes a security incident. You open Posts or Pages in WordPress and find content you never made. Sometimes it is still a draft, sometimes it is scheduled, sometimes it is already published. The titles can be obvious, or disguised with random-looking slugs so they are harder to notice quickly.
Why can this happen?
Some of the most common reasons are:
- an admin username and password leaked;
- user registration was left open and the default role was too permissive;
- a plugin or theme vulnerability allows content creation;
- the website uses nulled plugins or themes;
- there is a backdoor in the files that can write into the database at any time.
How to check it properly:
- Audit all WordPress users and see when they were created.
- Check the default role for new registrations.
- Review Posts, Pages, Media, and any custom post types.
- Check scheduled posts and revision history.
- Inspect
wp_posts,wp_users,wp_usermeta, andwp_optionsin the database. - Check
uploads,mu-plugins, the active theme,.htaccess, andwp-config.php.
If you are comfortable with SQL, a simple search like this helps surface suspicious content faster:
SELECT ID, post_type, post_status, post_title
FROM wp_posts
WHERE post_title LIKE '%casino%'
OR post_title LIKE '%slot%'
OR post_content LIKE '%bet%';
Change the table prefix if your website does not use wp_.
How to fix it in a way that really closes the issue:
- Back up the database and files as they are now.
- Remove the spam posts or pages, including their revisions and trash entries.
- Audit and remove suspicious users.
- Rotate all passwords and turn on 2FA.
- Reinstall WordPress core from the official source.
- Reinstall every plugin and theme from official sources, especially the least-maintained ones.
- Clean backdoors from the files and database.
- Check scheduled actions, cron tasks, and injected code inside theme or plugin options.
- Make sure removed spam URLs now return
404or410.
The mistake that keeps the problem alive: deleting spam posts from the dashboard and assuming it is over. If the root cause is an unknown user or a backdoor, new posts will appear again later.
Prevention: turn off public registration if the website does not need it, use 2FA, and review users regularly. For the security foundation itself, see our guide on securing a small business WordPress site.
Problem 4: the spam posts are deleted, but the URLs still appear in Google
What does it look like?
The dashboard looks clean, but Google still shows the spam URLs. Sometimes clicking them now leads to a 404, sometimes the snippet still contains gambling terms, and sometimes Search Console still reports the URLs as discovered.
Why does this happen?
Google keeps old crawl data for a while. If spam URLs were indexed, they do not vanish the moment you delete them from WordPress. At the same time, if the source of the spam is not fully removed, Google can simply find new variations again.
How to fix it:
- Make sure the real source of the spam is gone from the database, files, sitemap, and internal links.
- Make sure the old URLs return
404or410. - Refresh the sitemap and submit it again through Search Console.
- Use the removal tool only to speed up the visible cleanup of search results, not as the core solution.
- Monitor index coverage for several weeks.
If the spam-post issue has already damaged the search index, read our article on a website not appearing in Google, because once the spam is removed you need to make sure the real business pages regain their place in the index.
Prevention: do not wait for Google to tell you. Run a regular site:yourdomain.com search and monitor Search Console.
Problem 5: the comment spam is really coming from weak user registration or login protection
What does it look like?
Spam comments keep coming even after filters are added. Then you discover a large number of fake subscriber accounts, or repeated brute-force attempts on the login page. In a case like this, the spam comments are only the front symptom; the weak point is actually the login or registration flow.
The most common causes:
- “Anyone can register” is turned on even though the website does not need it;
- the default role for new users is set incorrectly to Author, Editor, or something stronger;
- the login form has no protection;
- passwords are weak or reused;
- there is no login rate limiting.
How to fix it:
- Turn off user registration if the website does not need it.
- Make sure the default role for new users is Subscriber.
- Clean up fake accounts that have already been created.
- Add bot protection and login security.
- Force password resets for all important accounts.
Relevant WordPress plugins:
- Simple CAPTCHA with Cloudflare Turnstile for comments, login, registration, and password reset.
- Wordfence Security for login protection, failed-login limits, 2FA, and firewall.
Prevention: do not leave registration open if your website model does not need it. Many company profile websites get flooded with spam simply because this one default setting was forgotten.
Problem 6: after cleanup, the spam posts come back a few days later
What does it look like?
You already deleted the spam comments, removed the gambling posts, and even changed passwords. Then a week later the problem returns. That almost always means one source was never found.
The most common things left behind are:
- a backdoor in
wp-content/uploads/ormu-plugins; - a vulnerable plugin or theme that was never updated;
- a rogue admin account that still exists;
- a scheduled task recreating the spam posts;
.htaccessorwp-config.phpstill containing malicious code.
How to fix it:
- do a deeper file audit, not only a dashboard review;
- reinstall WordPress core, plugins, and themes from official sources;
- inspect the uploads directory for
.phpfiles that should not be there; - inspect cron and scheduled actions;
- review login and user activity logs;
- scan again after cleanup.
This is why cleaning spam posts often looks more like website recovery work than simple moderation. Ongoing care like a website maintenance service matters because it adds monitoring after the first cleanup, not just one day of deletion.
A safe handling order for WordPress
If you want a practical sequence, use this:
- Decide which kind of problem you actually have: comments only, or comments plus posts, pages, or users.
- Back up the website before cleaning, especially the database. You can use UpdraftPlus or your hosting backup system.
- Shut off the fastest spam source first: close comments, disable registration, and enable maintenance mode if necessary.
- Audit users and roles. Remove fake or unknown accounts.
- Clean the comments, posts, pages, and media spam. Do not forget trash and revisions.
- Review plugins and themes. Remove what is unused, update what is behind, and reinstall from official sources when something looks suspicious.
- Inspect core files and high-risk folders. Especially
uploads,mu-plugins, the active theme,.htaccess, andwp-config.php. - Rotate all important credentials and turn on 2FA.
- Add anti-spam and login protection after the website is clean.
- Monitor Search Console, comments, and new users for several weeks.
The order matters. If you start by deleting spam while the source is still open, the problem will feel endless.
The most sensible WordPress plugin combination
Many website owners install too many security plugins at once. The result is not better security but heavier dashboards and more conflicts. For spam comments and spam posts, a sensible combination is usually enough:
- For comment spam: Akismet or Antispam Bee.
- For human verification: Simple CAPTCHA with Cloudflare Turnstile.
- To disable comments entirely if you do not use them: Disable Comments.
- For login security and firewall: Wordfence Security.
- For backup and recovery: UpdraftPlus.
What matters more than plugin count is maintenance discipline. An anti-spam plugin that is never configured, a backup that is never tested, and a firewall whose alerts are ignored will not help much.
Realistic prevention so the spam does not come back
1. Close features you do not use
If the website does not need comments, disable them. If it does not need user registration, disable that too. Every public feature is another point of entry.
2. Moderation is cheaper than cleanup later
Spam held in moderation is much easier to manage than spam that is already published, indexed, and harming your domain reputation.
3. Avoid plugins and themes from unofficial sources
Many spam-post cases actually begin with compromised files. That is why you should use official sources and update WordPress plugins safely.
4. Audit users every month
Check who still has login access, which role each person has, and whether the account is still needed. This tiny routine prevents larger problems surprisingly often.
5. Watch Search Console and run site: searches
Google recommends monitoring user-generated spam and abuse signals. For WordPress owners, a weekly site: check and Search Console email notices are a simple but effective habit.
6. Keep backups ready to use
If a spam problem becomes a true hack, a clean backup can dramatically reduce recovery time. Our article on why website backups matter explains why backups need to be tested, not merely assumed to exist.
Frequently asked questions
Does comment spam always mean my website was hacked? Not always. Comment spam often only means the comment form is open without enough filtering or moderation. But if it appears alongside unknown users, spam posts, redirects, or changed settings, you should suspect a real compromise.
Is installing Akismet enough to stop gambling or casino spam posts? No. Akismet is very useful for comments and some form submissions, but it does not solve the problem if the real source is a leaked admin account, a vulnerable plugin, bad user-registration settings, or a backdoor that can write directly to the database.
How do I safely delete thousands of spam comments? Back up the database first, then delete them in bulk from the dashboard or use a plugin tool built for comment management. Most importantly, shut off the spam source before deleting them, otherwise the queue fills again immediately.
Why do spam posts return after I delete them? Usually because the source was never removed: an unknown user account, a scheduled task, a file backdoor, or a vulnerable plugin or theme is still active. Deleting the posts only removes the symptom, not the root cause.
Final thought: once it reaches posts, users, or Google indexation, treat it as urgent
Comment spam is frustrating, but it can often be solved through the right settings. The moment the problem reaches the level of posts, pages, users, or Google indexing, you are no longer dealing with ordinary spam alone. You are dealing with abused access or a security compromise.
If you want to verify the condition first, start with our free audit. If your website is already full of gambling or casino posts, if unknown users have appeared, or if search results are starting to show spam URLs, it is safer to move straight to our website emergency service or contact us on WhatsApp. The sooner the site is cleaned and the gap is closed, the smaller the impact on domain reputation, lead generation, and sales.
Does any of this look like your website?
Tell us on WhatsApp. We look first, explain what needs fixing, then you decide. For a fuller picture, request the free audit.
Related articles.
WordPress Website Care: Why WordPress Needs Specialist Maintenance
Why WordPress needs specialist care compared with other platforms, its typical risks, and what a competent WordPress care service actually does.
Signs Your Website Has Gambling Malware: From Code Injection to Google Index Spam
Learn the real signs of gambling malware on a WordPress site, from injected code and hidden redirects to spam pages indexed by Google, plus the right cleanup steps.
Website Maintenance Services: What Should You Actually Get?
What website maintenance is, which work should be included, what it costs, and how to judge whether your business needs it now.