How to Check If My Website Is Hacked
Suspect something is wrong with your site? Here are the warning signs, the quick checks you can do yourself in two minutes, and a free external scan for malware and suspicious changes.
Get an answer in minutes. Our free scan checks your public pages for injected scripts and malware indicators, and checks whether your domain is on security blocklists.
No signup · Read-only checks · Nothing is changed on your site
The 8 warning signs your site may be hacked
Hackers usually want your traffic, your server, or your reputation — not to announce themselves. Watch for these signs:
- 1. Visitors get redirected to spam sites. Your pages look normal to you but send mobile visitors (or Google's crawler) to gambling, pharma or scam pages. This "cloaking" is a classic hack signature.
- 2. Browsers show "Deceptive site ahead." Chrome warns visitors when Google has flagged your site for phishing or malware.
- 3. Unknown admin users. New administrator accounts you didn't create — check your CMS user list.
- 4. Spam pages appear in Google. Search site:yourdomain.com and look for pages selling things you never sold, often in another language.
- 5. A sudden traffic drop. Google may demote hacked pages, which shows up as a sharp fall in Search Console.
- 6. Your host warns about spam email. Compromised sites are routinely used to send spam — your host is often the first to notice.
- 7. Unfamiliar files or code. Strange files in your uploads folder, or scripts in your page source you didn't add.
- 8. Customers report strange behavior. Popups, unexpected downloads, or antivirus warnings when visiting your site.
One sign alone can have an innocent explanation. Two or more together deserve a proper investigation.
The 2-minute checks you can do yourself
Before anything else, run these three free checks:
- Google search: type site:yourdomain.com into Google and scan the results for pages or text you don't recognize.
- Google Search Console: open the Security Issues report. Google tells you directly if it has detected hacking, malware or social engineering on your site.
- Google Safe Browsing: check your domain's current safety status — this is what powers the "Deceptive site ahead" warnings.
Run the free external scan
Our free scan approaches your site the way the outside world sees it. Three sections matter most when you suspect a hack:
- Malware — looks for injected scripts and suspicious code on your public pages, and gives a clear verdict.
- Security headers — missing protections that made the attack easier.
- Technology — flags risky disclosures like version numbers in public files that help attackers.
The scan is read-only: it examines, never changes, anything on your site.
What to do if the scan finds something
Don't panic — and don't start deleting things yet. Follow this order:
- 1. Back up first — files and database, including the suspicious parts. You need evidence of how the attacker got in.
- 2. Take the site offline or enable maintenance mode if visitors are being harmed (redirects, malware downloads).
- 3. Remove the malicious code — restore clean copies from backups or remove injected scripts and unknown admin users.
- 4. Close the entry point. Update everything, reset all passwords (hosting, CMS, database, FTP), and add the missing security headers. Skipping this step is why most cleaned sites get hacked again within days.
- 5. Request a Google review in Search Console once you're confident the site is clean.
When you need professional cleanup vs. DIY fixes
Handle it yourself when the infection is limited to a few injected scripts, you have clean backups, and you can identify and close the entry point. Call a professional when the database is modified, the same infection keeps returning, or the site handles payments or sensitive customer data. Reinfection is the signal that DIY has reached its limit.
How to prevent reinfection
Cleaning without hardening is a temporary fix. The habits that keep sites clean are unglamorous but effective:
- Keep your CMS, plugins, themes and server software updated — and remove what you don't use.
- Use strong, unique passwords everywhere, plus two-factor authentication on admin accounts.
- Add the missing security headers flagged by your scan report.
- Keep automated off-site backups you have actually tested restoring.
- Rescan regularly — monthly at minimum, and after every update round.
Stop guessing — check. Run the free external scan now and see what the outside world (and attackers) can see on your site.
Frequently asked questions
Can a free scan miss a hack?
Yes. An external scan only sees what the public internet sees — sophisticated backdoors can hide server-side without touching public pages. If you strongly suspect a compromise, get an internal file-level scan too.
Will Google remove the warning after I clean my site?
Yes, once the malicious content is gone and the entry point is closed. Request a review in Google Search Console under Security Issues — reviews typically complete within a few days.
How do I know my site is fully clean?
You can't be certain from the outside alone. Clean the infection, close the entry point (updates, passwords, headers), then verify with both an external scan and an internal file-level scan — and watch for reinfection over the following weeks.
Should I just delete the suspicious files?
Back up first — including the suspicious files. Deleting evidence before you understand the entry point often leads to reinfection within days, because the attacker simply walks back in the same way.
Will my hosting company suspend a hacked site?
Some hosts suspend sites that send spam or host phishing pages, to protect their network. If that happens, contact their support: most will restore access once you show a cleanup plan is underway.
How long does cleaning a hacked site take?
A straightforward cleanup can take a few hours; a deep infection with database changes can take days. The entry-point fix (updates, password resets, header hardening) matters more than speed.