Did Trulia Get Hacked?
I wrote a post on my other blog last summer about Trulia cloaking in order to improve their search results. This morning, I was pinged by Brad Carroll’s blog on the post because Trulia’s SERP position seemed to have disappeared. Brad referenced the post, among others, to show that Trulia’s SEO team has never played it clean, and that it wouldn’t be surprising to see them incur a penalty from big G.
I was pretty intrigued (as I am with all things SEO,) so I read a few more posts, twittered some friends, and then had a thought. WordPress has some notorious security holes, and there are hackers that like to break into sites and insert nefarious links (mainly to pills/porn/casino sites.) The links they insert are definitely bad neighborhoods, and I have many friends whose sites have been temporarily penalized b/c they were hacked.
But Trulia’s not on WordPress, right? And their security MUST be tighter than that, right? Wrong…
I ran a site: check to see if any PPC links had been inserted on the domain. Yep.
Viagra = 59 pages w/ links
Levitra = 6 pages with links
I could have gone on and on checking for pill keywords, but that was enough. The hackers inserted the links into the footer, and hid them so as not to alert anyone. Here’s a link to a copy of one of the pages Google currently has indexed. Look at the code, scroll to the bottom, and you can see a TON of inserted, hidden links.
Apparently, the hindsight.trulia.com subdomain is built on a WordPress install, and some hackers found it. Fortunately for Trulia, it appears they’ve already identified the problem and removed the links. It will take a reinclusion request (which I’m sure they’ve submitted,) and they should be reindexed within the week.
If you want to see Trulia’s hacked pages until/unless it’s corrected, run this search and click on the “cached” link to the bottom right of the page description.
******Update*******
Brad Carroll pointed out that hacked WP installs on subdomains are typically only penalized on that specific subdomain. Another friend of mine is on the SEO team at a large scale ecommerce site whose WP install was hacked on a subdomain, and confirmed that it was isolated to the blog’s subdomain.
There could well be more to the disappearing Trulia rankings!!!


32 Responses
Conversation