SecWeb

Malware Scanner

Check any website for malware indicators — blacklist hits, obfuscated JavaScript, hidden iframes, suspicious redirects, and spam injections. Free, passive, and instant.

Try:

What Is a Malware Scanner?

A malware scanner examines a website for signs of malicious code — scripts that have been injected without the owner's knowledge, redirects to unknown destinations, and hidden elements designed to manipulate search engines or steal visitor data.

Most website compromises aren't visible from the outside. A hacked WordPress site often looks and behaves perfectly for the owner, while visitors see injected spam or get silently redirected to a malicious page. The only way to catch it is to look at what the server is actually returning — which is what this scanner does.

Every check performed here is passive. We fetch your homepage the same way a browser would, then analyze the response for known malware patterns. We never download files, never execute code, and never modify anything on the target site.

What This Scanner Checks

Domain Reputation & Blacklists

We query four of the most widely used public blacklists via DNS:

  • Spamhaus DBL — the largest domain block list, used by most email providers
  • SURBL — tracks URIs in spam and phishing messages
  • URIBL — a collaborative URI reputation database
  • WPBL — a block list specifically for WordPress sites flagged as malicious

If a domain appears on any of these, it's a strong signal that the site has been compromised, is hosting malicious content, or has been used for phishing.

Obfuscated JavaScript Detection

Malware authors hide their code by encoding it — usually as base64 or via character-code obfuscation — and then executing it dynamically with eval(). We look for:

  • eval() combined with decoding functions like atob() or unescape()
  • Large base64-encoded string literals
  • document.write(unescape(...)) — the classic signature of injected PHP malware
  • Long String.fromCharCode() sequences

Hidden Elements

Injected content is often deliberately hidden from users. We check for iframes and links that are invisible to visitors — via display:none, zero dimensions, or off-screen positioning. These are used for spam, click fraud, and drive-by downloads.

Suspicious Redirects

We analyze your redirect chain. Long chains, redirects to unknown domains, and especially redirects to free TLDs like .tk, .ml, and .gq are strong indicators of compromise.

External Resources

Legitimate sites load scripts from domains they control or recognize. We flag scripts loaded from raw IP addresses, from high-risk TLDs, and excessive mixed content (HTTP resources on HTTPS pages).

Content & Spam Indicators

We check for the classic "pharma hack" — hundreds of injected pharmaceutical keywords — plus unusual volumes of external links that indicate SEO spam injection.

Server Response Anomalies

Visible PHP error messages with filesystem paths can leak sensitive information and often appear on compromised or poorly configured servers.

Common Signs Your Site Has Been Hacked

Most compromises go unnoticed by site owners. Here are the red flags:

  • Strange search results — searching for your brand shows unrelated pharmaceutical or adult content with your URL attached
  • Redirects on mobile only — attackers often target mobile user agents to avoid detection
  • Visitors report browser warnings — Chrome or Firefox showing "Deceptive site ahead" warnings
  • Rankings dropped suddenly — Google penalizes sites that host malicious content
  • Unknown files on your server — unfamiliar PHP files in wp-content/uploads/ or elsewhere
  • Emails marked as spam — if your domain appears on Spamhaus or SURBL

What to Do If Malware Is Found

  1. Take the site offline — or at minimum place it behind a maintenance page, to prevent further visitor exposure
  2. Change all credentials — FTP, database, admin panel, hosting control panel
  3. Scan for backdoors — use a professional tool like Wordfence, Sucuri, or MalCare to find hidden backdoors attackers leave behind
  4. Clean the files — either restore from a known-good backup or manually remove injected code
  5. Update everything — core, plugins, themes, and PHP version
  6. Request blacklist removal — after cleaning, submit delisting requests to Spamhaus, SURBL, and Google Safe Browsing
  7. Monitor — compromised sites are often re-compromised. Keep scanning regularly for at least a few months

How Often Should You Scan?

Weekly for active sites. Daily for e-commerce, membership sites, or anything handling payment data. Always after installing a new plugin or theme from an unverified source — those are the most common infection vectors.

Frequently Asked Questions

It performs three categories of checks: (1) DNS blacklist lookups against Spamhaus DBL, SURBL, URIBL, and WPBL; (2) HTML content analysis for obfuscated JavaScript, hidden iframes, and off-screen elements; and (3) redirect chain and external resource analysis. It does not download files, execute code, or submit forms.
No. As a passive scanner, we only see what the server returns in the HTML of your homepage. Malware that hides behind obfuscated JavaScript in files not served publicly, or that only triggers for specific user agents, won't be visible. For full coverage, combine this scanner with a professional server-side tool that has file-system access — like Wordfence, Sucuri, or MalCare.
First, investigate. Spamhaus listings usually appear because your site was sending spam emails (possibly through a compromised form), hosting injected content, or was itself compromised. Clean the underlying issue, then submit a delisting request at spamhaus.org/lookup. Delisting usually happens within a few hours of a confirmed clean.
The pharma hack is one of the oldest and most persistent WordPress compromise patterns. Attackers inject hundreds of hidden links to online pharmacy sites, which show up in Google's index but not to visitors. It damages search rankings severely and often appears for months before being noticed. The scanner flags it via pharmaceutical keyword detection.
Yes — the scan is passive, read-only, and uses the same techniques a browser would. You should still have a legitimate reason (evaluating a vendor, checking a potential domain purchase, etc.). Scanning sites you don't own with intent to harm is not permitted.
No. A clean result means the scanner found no malware indicators on the homepage. Sophisticated attacks target specific user agents, hide behind login walls, or inject on specific pages only. Use this scanner as one layer, and combine it with server-side tools that can inspect files directly.
Clean the malware first — delisting requests are usually rejected if the underlying issue isn't fixed. Then submit requests individually: Spamhaus at spamhaus.org/lookup, SURBL at surbl.org/surbl-analysis, URIBL at uribl.com, and Google Safe Browsing through Google Search Console. Each has a separate process and turnaround time.
Yes — completely free. Guests get 3 scans per hour; registered users get 20. No credit card, no trial expiration.
SecWeb Icon

Add SecWeb to your Home Screen

Get quick access to your security scans directly from your device.

Tap the Share icon below, then select "Add to Home Screen".