WPSecureOps

Glossary · Malware

A blocklisted URL was found in site content

Wordfence type
blacklistedURL
Category
Malware
Severity
High

Content on the site links to a domain known for malware or fraud.

What Wordfence found

Wordfence found a URL in the site's content that appears on a blocklist of known-malicious destinations. It may be in a post, a widget, or a theme file.

Why it matters

Links to malicious domains are how injected SEO spam and malvertising monetise. Their presence usually means something wrote to your content, not that an author made a mistake — and search engines will act on it.

How to fix it

  1. 1Locate the URL and establish whether a human added it.
  2. 2If not, treat this as an injection and follow the database-injection steps.
  3. 3Remove the link and re-scan.
  4. 4Check whether the same URL appears across multiple sites you manage — injections are usually campaign-wide.

How WPSecureOps treats it

The connector reports this as blacklistedURL. WPSecureOps files it under Malware and bands it by the numeric severity Wordfence assigns, so findings of this kind from every site you manage arrive in one queue rather than one email per site. Titles and descriptions are stripped of HTML and the site's absolute path is replaced before anything leaves the server.

See this finding in context