🔍 Overview
If you've noticed a suspicious script, unexpected redirect, or unfamiliar code appearing on your WordPress site — particularly in the footer, header, or theme files — this article will help you understand what's happening and how to respond. Search Atlas and the OTTO SEO plugin do not inject unauthorized scripts or malicious code of any kind. If suspicious code has appeared on your site, the cause is almost certainly a compromised WordPress installation, theme, plugin, or hosting account.
⚠️ Is the Suspicious Script Related to Search Atlas or OTTO?
No. The OTTO SEO plugin communicates exclusively with Search Atlas servers to manage SEO tasks such as schema markup, internal linking, and on-page optimizations. It does not modify your site's footer with third-party scripts, inject advertising code, or communicate with any domain outside of Search Atlas infrastructure.
If you see an unfamiliar script in your footer or elsewhere, the most likely causes are:
- A compromised WordPress plugin or theme (including nulled or outdated software)
- Unauthorized access to your WordPress admin account or hosting control panel
- A vulnerability in your WordPress core installation
- Malicious code injected through your hosting server or database
🛠️ Immediate Steps to Take
- Take your site offline or enable maintenance mode to prevent visitors from being exposed to malicious content while you investigate.
- Change all passwords immediately: WordPress admin accounts, FTP/SFTP credentials, hosting control panel, and your database password.
- Revoke and regenerate API keys for any third-party services connected to your site, including your Search Atlas API key if it was stored in plain text anywhere.
- Notify your hosting provider. Most hosts have a security team that can scan your server environment and isolate the infection at the server level.
🔬 How to Identify the Malicious Code
Use the following steps to locate and remove the suspicious code:
- Scan with a WordPress security plugin. Install and run a reputable scanner such as Wordfence, Sucuri Security, or MalCare. These tools compare your core files against known-clean versions and flag anomalies.
- Check recently modified files. Via FTP or your host's file manager, sort files by last-modified date. Malware often modifies wp-config.php, functions.php, index.php, or .htaccess.
- Inspect your database. Use phpMyAdmin to search for suspicious strings such as eval(base64_decode, <script src= pointing to unknown domains, or document.write in your wp_options or wp_posts tables.
- Review installed plugins and themes. Deactivate and delete any plugins or themes you do not recognize, any that have not been updated in over a year, or any obtained from unofficial sources.
🧹 Cleaning and Restoring Your Site
- Restore from a clean backup if you have one dated before the infection. This is the fastest and most reliable remediation method. Confirm the backup is clean before restoring.
- Reinstall WordPress core files. From your WordPress dashboard, go to Dashboard → Updates and click Re-install version X.X.X. This overwrites core files without affecting your content.
- Replace theme and plugin files with fresh downloads from wordpress.org or the original developer. Do not reuse existing files that may be infected.
- Clean your database manually by removing any injected scripts found during your inspection.
- Implement a Web Application Firewall (WAF) such as Cloudflare or Sucuri to block future intrusion attempts.
✅ After Cleanup: Hardening Your WordPress Site
Once your site is clean, take these steps to reduce the risk of reinfection:
- Keep WordPress core, all themes, and all plugins updated at all times.
- Use strong, unique passwords and enable two-factor authentication (2FA) on your WordPress admin account.
- Limit login attempts using a plugin or your WAF rules.
- Remove unused themes and plugins entirely — deactivated plugins can still be exploited.
- Set correct file permissions: 644 for files and 755 for directories.
- Move wp-config.php one directory above your WordPress root if your host supports it.
- Schedule regular automated backups stored off-server (e.g., Amazon S3, Google Drive).
🔗 Verifying OTTO Is Working Correctly After Remediation
After cleaning your site, verify the OTTO SEO plugin is functioning as expected by navigating to OTTO SEO → All Sites (SEO Automation Projects) in the left sidebar of your Search Atlas dashboard. Confirm that your site is connected, tasks are running normally, and no error messages appear. If OTTO was deactivated during cleanup, simply reactivate it from your WordPress plugin manager — no reconfiguration is needed as long as your API key is intact.
💬 Need More Help?
If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.