Is your website hacked?

Most hacked websites look completely normal. The malware is not there to be seen — it hides from you and shows itself to your visitors, or to Google. Spam links get injected into pages only search engines read. A script quietly redirects mobile visitors somewhere else. Your rankings slip, your emails start landing in spam, and one morning Chrome shows a red warning to everyone who tries to visit.

By the time it is obvious, the damage is done. Enter your website below. In about thirty seconds, you will get a score out of 100, every problem found in plain English, and what to do about each one.

What the scan checks

Six areas, scored and weighted, on whatever the site serves publicly.

Malware and spam

The scanner reads your pages the way a visitor's browser does and matches them against known infection signatures: obfuscated scripts that hide their real code, crypto-miners that steal your visitors' processors, invisible iframes loading malware from another server, injected pharma and casino spam, and the markers left by common WordPress infections like WP-VCD. The signatures are deliberately conservative, so a clean result means something.

Exposed files

Configuration backups, .git folders, .env files, debug logs and downloadable archives left where anyone can read them. These are how an attacker gets your database password without needing to break anything — they just download it. The scan checks the paths a real auditor checks by hand.

Security headers and SSL

The certificate, whether HTTP is forced to HTTPS, and the headers that defend against script injection and clickjacking — HSTS, CSP and the rest. Also whether a firewall or CDN is protecting the site at all.

Blacklist and reputation

Whether your site appears on Google Safe Browsing — the list that drives the full-page red warning in Chrome, Firefox and Safari — and on URLhaus, which tracks sites distributing malware. A blacklisted site loses most of its traffic overnight, and getting removed takes longer than getting listed.

Outdated software

Whether the site advertises its WordPress version, whether the default readme file is exposed, and whether the version it shows is behind the current release. Old versions accumulate publicly documented security holes, and automated attack tools read exactly this to decide what to try.

WordPress hardening

Whether your usernames leak through the REST API, whether XML-RPC is left open to brute-force amplification, and whether the login page sits at its guessable default. None of these are disasters alone; together they are the difference between a site that shrugs off automated attacks and one that eventually gives in.

What this scan can and cannot see

Be clear on this, because it matters. A remote scan reads only what your site shows the public. That is exactly what Google, attackers and your visitors see, so it catches the infections that hurt you — blacklisting, injected spam, malicious redirects, exposed files.

What it cannot see is your server: the files on disk, the database, the admin area. Some malware hides there and never appears in a public page. So a clean scan here is genuine good news, not a guarantee. For a site you own and are worried about, the sure answer is a server-side scan — which is part of what we do when we clean a site.

about us

If the scan finds something

Do not panic, and do not immediately delete things. A hacked site is recoverable, but the wrong first move — restoring an old backup over a live infection, deleting files at random — often makes the cleanup harder.

Take a backup now, even of the infected site. It is evidence of how the attacker got in, and losing it means the same hole gets used again.

Change your passwords from a different device. If your computer is what leaked the credentials, changing them on it just hands over the new ones.

Then get it cleaned properly. Removing visible malware is not the same as removing the backdoor that let it in. A site that gets re-infected within a week was cleaned, not secured.

FAQs

Common questions

How do I know if my website is hacked?

The common signs are: browser or Google warnings when visiting, a sudden drop in search rankings, unexpected pop-ups or redirects, spam content or pharma links appearing in pages, your host suspending the account, or emails from your domain landing in spam. Many hacks show none of these to you while showing all of them to visitors and search engines. Running your site through the scanner above checks for the signatures of an active infection in about thirty seconds.

Yes. The full scan and score are free, with nothing to install. We ask for an email address to unlock the complete list of fixes, and that is all we ask for.

Yes, and this is the most common case. Modern malware is built to stay hidden from the site owner — it targets your visitors, or cloaks itself to show spam only to Google while showing you a normal page. That is exactly why a scan is worth running even when nothing looks wrong.

It is genuinely good news, but not a guarantee. A remote scan sees only what your site serves publicly — which is what attackers and Google see, so it catches the infections that hurt you. It cannot see server files or the database, where some malware hides. If you own the site and are seriously worried, a server-side scan is the sure answer.

Do not delete things at random or restore an old backup over the live site — both often make cleanup harder. Take a backup of the site as it is now (it is evidence of how they got in), change your passwords from a different device, and get it cleaned properly. Removing the visible malware without closing the entry point just means it comes back.

Google Safe Browsing flags sites serving malware, hosting phishing pages, or redirecting visitors to harmful sites — usually the result of a compromise you may not have noticed. The warning clears only after the site is cleaned and you request a review in Search Console under Security Issues.

Google Safe Browsing flags sites serving malware, hosting phishing pages, or redirecting visitors to harmful sites — usually the result of a compromise you may not have noticed. The warning clears only after the site is cleaned and you request a review in Search Console under Security Issues.

We keep the site address and its score so we can serve the report quickly if it is checked again. We store nothing from inside the site, because the scanner only reads what is already public.

We clean hacked WordPress sites

Malware removal and recovery is a core part of what we do — finding the entry point, removing every trace of the infection, getting the site off blacklists, and hardening it so it does not happen again. If this scan turned something up, or if you already know something is wrong, send us the site and we will tell you what it will take to put right.