Check any website for malware indicators — blacklist hits, obfuscated JavaScript, hidden iframes, suspicious redirects, and spam injections. Free, passive, and instant.
A malware scanner examines a website for signs of malicious code — scripts that have been injected without the owner's knowledge, redirects to unknown destinations, and hidden elements designed to manipulate search engines or steal visitor data.
Most website compromises aren't visible from the outside. A hacked WordPress site often looks and behaves perfectly for the owner, while visitors see injected spam or get silently redirected to a malicious page. The only way to catch it is to look at what the server is actually returning — which is what this scanner does.
Every check performed here is passive. We fetch your homepage the same way a browser would, then analyze the response for known malware patterns. We never download files, never execute code, and never modify anything on the target site.
We query four of the most widely used public blacklists via DNS:
If a domain appears on any of these, it's a strong signal that the site has been compromised, is hosting malicious content, or has been used for phishing.
Malware authors hide their code by encoding it — usually as base64 or via character-code obfuscation — and then executing it dynamically with eval(). We look for:
eval() combined with decoding functions like atob() or unescape()document.write(unescape(...)) — the classic signature of injected PHP malwareString.fromCharCode() sequences
Injected content is often deliberately hidden from users. We check for iframes and links that are invisible to visitors — via display:none, zero dimensions, or off-screen positioning. These are used for spam, click fraud, and drive-by downloads.
We analyze your redirect chain. Long chains, redirects to unknown domains, and especially redirects to free TLDs like .tk, .ml, and .gq are strong indicators of compromise.
Legitimate sites load scripts from domains they control or recognize. We flag scripts loaded from raw IP addresses, from high-risk TLDs, and excessive mixed content (HTTP resources on HTTPS pages).
We check for the classic "pharma hack" — hundreds of injected pharmaceutical keywords — plus unusual volumes of external links that indicate SEO spam injection.
Visible PHP error messages with filesystem paths can leak sensitive information and often appear on compromised or poorly configured servers.
Most compromises go unnoticed by site owners. Here are the red flags:
wp-content/uploads/ or elsewhereWeekly for active sites. Daily for e-commerce, membership sites, or anything handling payment data. Always after installing a new plugin or theme from an unverified source — those are the most common infection vectors.
Get quick access to your security scans directly from your device.
Tap the Share icon below, then select "Add to Home Screen".