Free Website Malware Scanner: Is My Site Hacked?
Enter your website and the scanner loads it three ways – as a normal visitor, as Googlebot and as a mobile visitor coming from Google – to catch the tricks hackers use to hide: spam injected only for Google, redirects only for mobile visitors, hidden links, obfuscated JavaScript, crypto miners, exposed backups and blacklist listings.
What the malware scanner checks
Cloaking (Googlebot vs visitors)
Hacked sites often show clean pages to you and spam to Google. We compare what a visitor, Googlebot and a mobile user see.
Malicious redirects
Redirects to scam, adult or pharmacy sites that only fire for mobile visitors or people coming from Google search.
SEO spam
Viagra, casino, “slot gacor”, replica and Japanese keyword hack content injected into your pages.
Hidden links & iframes
Invisible links to spam sites and 1×1 iframes that load malware in the background.
Malicious JavaScript
eval(atob…), long encoded strings, fake jQuery/Google CDN domains, crypto miners and script-based redirects.
Blacklists & exposed files
Spamhaus DBL, SURBL and URIBL listings, plus exposed .git, .env, wp-config backups, debug.log and open upload folders.
Quick answer
To check if a website is hacked, load it as a normal visitor, as Googlebot and as a mobile visitor from Google, then compare: different redirects or spam that only Google sees (cloaking) are the clearest signs. Also look for spam keywords, hidden links, obfuscated JavaScript, crypto miners and blacklist listings. This free scanner does all of that in about 20 seconds.
How to use it
- Type your website address (for example
example.com) and press Scan for malware. - Wait about 20 seconds while the page is fetched as a visitor, as Googlebot and as a mobile visitor coming from Google.
- Read the verdict: Clean, Suspicious or Signs of hacking. Each finding shows the evidence and what to do next.
Signs your website is hacked
- Google shows Japanese, pharmacy or casino titles for your pages (search
site:yourdomain.com). - Visitors on mobile are redirected to another website, but you don’t see it on your computer.
- Your host suspended the account or sent a malware warning.
- Chrome shows “Deceptive site ahead” or Google Search Console reports “Security issues”.
- New admin users, unknown files in
wp-content/uploadsor a sudden drop in traffic.
How to read the results
| Result | What it means | What to do |
|---|---|---|
| Clean | No public sign of infection was found. | Keep WordPress, plugins and the theme updated and turn on uptime monitoring. |
| Suspicious | Something looks unusual (encoded scripts, external redirects, exposed files). | Check each finding. Many are harmless, but exposed files must be removed today. |
| Signs of hacking | Spam, cloaking, malicious redirects, miners or blacklist listings were detected. | Change all passwords, take a backup and clean the site fully – or ask for help. |
Important: an online scanner only sees what the website sends to the public. Backdoors hidden in PHP files or the database are invisible from outside. A “clean” result is good news, not a guarantee. If you have real symptoms, follow the hacked WordPress recovery guide or request a professional malware removal.
What to do if malware is found
- Do not delete things at random – take a full backup of files and database first (it is evidence and a safety net).
- Change every password: hosting, FTP/SFTP, database, WordPress admins and e-mail.
- Replace WordPress core, plugins and themes with clean copies from the official sources and remove anything you don’t use.
- Search for backdoors (PHP files in uploads, unknown admin users, modified
.htaccess, cron jobs). - Request a review in Google Search Console and from any blacklist that lists your domain.
- Harden the site: firewall, 2FA, limited login attempts, file editing disabled, daily off-site backups – see the WordPress security guide.
Why we check as Googlebot and as a mobile visitor
Modern malware is built to hide from the site owner. A typical “SEO spam” hack shows thousands of spam pages only to search engines, and a “conditional redirect” only sends visitors to scam sites when they arrive on a phone from Google – the owner, who types the address directly on a laptop, never sees it. Comparing the three views is the fastest way to expose both tricks.
Frequently asked questions
How can I check if my website is hacked for free?
Enter your domain in this free malware scanner. It compares what visitors, Googlebot and mobile users see, and checks for spam, hidden links, malicious JavaScript, crypto miners, blacklists and exposed files. Also search site:yourdomain.com on Google and check Google Search Console for security issues.
Can an online scanner find all malware?
No. An online scanner only sees the public output of the website. Backdoors inside PHP files or the database need a server-side scan. Use this tool as a quick first check and get a full server-side clean-up if you have symptoms.
What is the Japanese keyword hack?
It is an SEO spam hack that creates thousands of auto-generated pages in Japanese (often selling fake brands) on your domain, usually visible only to Google. Your search results suddenly show Japanese titles. The scanner flags pages with large amounts of Japanese or Chinese text on a non-Japanese site.
Why does my site redirect only on mobile?
That is a conditional redirect, a common hack that only fires for mobile visitors or visitors coming from Google so the owner does not notice. The scanner fetches the site as a mobile visitor with a Google referrer to catch it.
Is it safe to scan my website?
Yes. The scanner makes a few normal page requests like a browser. It does not log in, attack or change anything, and the address you scan is not stored.
Want an expert to handle it?
I’m Eslam Abdullah – WordPress developer and web security specialist with 8+ years and 450+ projects. Send me your result on WhatsApp for a free consultation.