Free · No signup required

Is your WordPress site hacked? Check in 30 seconds.

Paste your URL for an instant check against common signs of a hack — hidden redirects, injected content, exposed backdoor locations — plus a Google Safe Browsing blacklist lookup. Free, no signup, no plugin install.

Results

What this tool checks

Enter a URL and this tool fetches the site's public homepage — the same page a browser or search engine already loads — and checks it for common, publicly visible signs of a hack: a hidden redirect to another domain, a near-invisible iframe, obfuscated inline scripts, hidden spam text, and an executable .php file sitting in /wp-content/uploads/ (a common backdoor-shell location, checked only against paths the page itself already links to — never guessed). Where a Google Safe Browsing lookup is configured, it also checks whether Google itself currently lists the page as unsafe.

How to read the result

The verdict is plain-English, not a raw data dump: Clean means none of these signs were found. Flagged — action needed means at least one strong signal was found — something a legitimate site essentially never has a good reason for. Inconclusive means a weaker signal turned up that has a plausible innocent explanation but is still worth a manual look.

What this can't do

This only reads what's already publicly visible on the homepage — the same way a visitor's browser does. It can't see inside wp-admin, the database, or files that aren't linked from the page, so a clean result here is a genuinely good sign, not a guarantee. A backdoor that isn't doing anything visible yet won't show up in a public scan; if you were hacked once already, or a previous clean-up didn't fully stick, a proper look under the hood catches what a public check structurally can't.

If it comes back flagged

Treat it as urgent, not as something to get to later. A site that's actively hacked keeps losing search ranking, visitor trust and often real revenue for every day it stays live, and Google's own blacklist status doesn't clear itself once the underlying problem is fixed — it has to be requested. See WordPress Malware Removal for the full process, or read what to do when your WordPress site gets hacked for the complete step-by-step.

FAQ

Questions about this checker

Is this WordPress malware checker actually free?

Yes. No signup, no email gate, and no limit on how many times you use it. Enter a URL and get a result in a few seconds.

Do you store the URL I check?

No. The scan runs, the report is shown to you, and nothing about the URL or the result is kept afterward.

What if it says my site is flagged?

Treat it as urgent. A flagged result means something publicly visible on the homepage matches a known sign of compromise — a hidden redirect, injected content, or a Google Safe Browsing listing. The longer a hacked site stays live, the more of its traffic, trust and search ranking it loses.

Can you fix it for me?

Yes — see WordPress Malware Removal for the full clean-up process: the infection removed, the actual entry point closed, blacklist status cleared, and hardening applied afterward so it doesn't happen the same way twice.

Available for new projects

NEXT STEP

Found something worth fixing?

Based in Bangladesh, working with clients worldwide. Send over what this turned up, or just describe the problem — every serious enquiry gets a reply within one working day.

  • Reply within one working day
  • Fixed quote before work starts
  • UK, EU and US hours covered