Free tool, no signup
IS MY WEBSITE HACKED?
Paste your address below. We load your home page three ways, on a laptop, on a phone, and as someone arriving from a Google search, because most attacks hide from the owner and show themselves only to customers.
We only request your public home page. Nothing is changed, nothing is stored.
What this check actually looks for
Spam redirects
Your address ends up on a pharmacy, gambling or adult site.
Phone only hijacks
The site behaves for you on a laptop and hijacks your customers on mobile.
Search visitor cloaking
Anyone arriving from Google is bounced elsewhere while direct visits look normal.
Injected spam wording
Pill, casino and replica wording buried in your page code.
Rewritten page titles
Foreign characters in your title, the signature of the Japanese keyword hack.
Scrambled scripts
Deliberately unreadable code that hides a payload from security plugins.
Invisible frames
Zero sized frames used to serve something to your visitors quietly.
Hosting suspension
Your host has switched the account off and visitors see a notice, not your site.
Honest limit: this reads your public home page. It cannot see your files, your database, your scheduled tasks, or the admin accounts someone may have created. A clean result here is a good sign, not proof. If your host or Google has told you there is a problem, they can see more than this page can.
What to do in the first hour
- 1
Take a copy before you touch anything
The infected version is the evidence. Delete it and nobody can work out how they got in, which is how sites get reinfected.
- 2
Change every password
Hosting, site admin, database, and the email address those accounts recover to. Stolen logins are the most common way in, ahead of any plugin flaw.
- 3
Stop guessing at files
Deleting things that look odd usually breaks the site and leaves the actual backdoor untouched.
- 4
Get the payload removed and the entry route closed
Both, not one. Cleaning without closing the door buys you about two weeks.
- 5
Ask Google to review the site
Once it is genuinely clean, the warning has to be lifted by request. It does not clear itself.
Questions owners ask us
How do I know if my website has been hacked?
The five signs owners actually notice: your site sends visitors to a different website, Google shows a red warning next to your listing, your host switches the account off, pages appear that you never wrote (often selling pills or gambling), or your site loads fine for you but looks broken to everyone else. The checker on this page tests for all five in about fifteen seconds.
Why does my website look fine to me but broken to my customers?
Because most modern attacks are selective. The injected code checks who is asking. If it is you, typing the address directly on your laptop, it serves the real site. If the visitor came from a Google search, or is on a phone, it serves the spam instead. That is why we load your page three different ways rather than once.
Is this checker safe to run on my site?
Yes. It only requests your public home page, the same as any visitor or search engine. It does not log in, does not touch your files, does not change anything, and does not store your site details.
The check found nothing. Am I definitely clean?
No, and we will not pretend otherwise. This reads your home page from the outside. Most infections also leave things it cannot see: unknown admin users, scheduled tasks, backdoor files in the uploads folder, and spam pages that only exist deeper in the site. A clean result means the obvious public symptoms are absent. If your host or Google has warned you, believe them.
My site is hacked. What should I do first?
Do not delete files at random and do not just reinstall the theme. First take a full copy of the site as it is now, because that copy is the evidence of how they got in. Then change every password, hosting, admin, database and email. Then have someone remove the payload and close the entry route. Skipping the last step is why most sites get reinfected within a fortnight.
How much does it cost to fix a hacked website?
We charge a flat $249 to clean and reopen a hacked site, whatever the platform. That covers removing the payload, closing the way in, clearing the Google warning, and a written note on what happened. Typical agency quotes for the same work run from $500 to $1,500.
Does this work on Shopify, Wix or Squarespace sites?
Yes. The check is platform agnostic because it reads what your visitors receive, not what your admin panel says. Hosted platforms are compromised less often at the server level, but injected apps, stolen admin logins and hijacked DNS produce exactly the same symptoms.
The rest of the WebCare toolkit
Pull every URL from any XML sitemap, with lastmod, changefreq, and priority. Export to CSV.
Cross reference your core, plugin, or theme version against the CVE database.
Auto updating feed of the latest WordPress CVEs, sorted by severity and date.
Paste your active plugins, get a report on known conflicts and deprecated plugins.
See which PHP version your WordPress needs and when to upgrade.
Real 3 year TCO across hosting, plugins, backups, security, and your time.
Last updated · Reviewed by Ali Yasin Jatoi
