Skip to content
Free WordPress security check

Is your WordPress site hacked?

Scan your website for suspicious redirects, casino and pharma spam, hidden links and other visible signs of compromise.

Free passive scan. No login required. Checks public website content only.

This check never logs into your website, changes files or tries to exploit anything. It reads the same public pages any visitor can see.

The checks

What does the WordPress hacked checker look for?

Six passive checks, run against the public HTML your website already serves to any visitor.

Malicious redirects

The scanner follows the redirect chain and reports where requests actually end up. A WordPress redirect hack is a compromise that sends visitors or search engines to a URL the site owner did not configure.

Casino and gambling spam

Injected gambling vocabulary and links are how many hacked sites are monetised. The check compares that vocabulary against what the site says it is about, so a genuine casino is not flagged for its own content.

Pharma and adult spam

Pharmacy product names and adult terms appearing on an unrelated business site are a common sign of an SEO spam injection.

Hidden links and hidden content

Links placed in the page source but hidden from visitors with CSS. Search engines still read them, which is the entire point of the attack.

Meta refresh redirects

A redirect written into the HTML itself, which works even when JavaScript is switched off.

Suspicious JavaScript

Redirect calls and encoded or obfuscated code in inline scripts. These have legitimate uses, so they are reported as indicators rather than proof.

Signs your WordPress site may be hacked

These are the symptoms owners actually report. The table shows which of them this external scan can see for itself, and which need access to the server.

Symptoms of a hacked WordPress site and whether this external scanner can detect them
SymptomCan this scan see it?
Visitors are redirected to another websiteYes, if it is in the HTML
Casino, pharmacy or adult pages appear on your domainYes, if it is in the HTML
Japanese or other unexpected keywords appear in GoogleYes, if it is in the HTML
Hidden spam links have been added to your pagesYes, if it is in the HTML
Your browser shows a deceptive or hacked site warningNo, needs server access
Your host has suspended the account for malwareNo, needs server access
Admin accounts you did not createNo, needs server access
PHP files changed or added on the serverNo, needs server access

What this scanner can see

The scanner requests your pages the way a visitor or a search engine would, then reads what comes back. That means the HTTP response headers, the full redirect chain, and the HTML source of the page it finally lands on. Everything it reports is drawn from that public response, which is why each finding comes with the evidence behind it.

It is deliberately passive. It does not log in, submit forms, guess passwords, request admin paths or attempt to exploit any vulnerability.

What this scanner cannot see

Most WordPress malware never appears in the HTML a visitor receives. No external scanner, including this one, can inspect:

  • PHP files that are executed but never served publicly
  • Anything on the server filesystem, including uploaded backdoors
  • The WordPress database, where injected content and options often hide
  • Malicious scheduled tasks in wp-cron
  • Administrator accounts an attacker has created
  • Code that runs only for certain visitors, such as mobile users or search engine crawlers
  • Malware that stays dormant for anyone who is logged in

What should I do if the scanner finds something?

  1. Take a full backup of the files and database before changing anything, even though it will contain the malware. You may need it.
  2. Change the WordPress administrator passwords, the hosting control panel password and the database password.
  3. Check the users list in WordPress and remove any administrator you did not create.
  4. Update WordPress core, every plugin and every theme, and delete anything you no longer use.
  5. Find the entry point. Removing the visible spam without closing the hole means it returns within days.

If that sounds like more than you want to take on, that is the job I do: WordPress malware removal for £59, with no fix, no fee. There are also step-by-step guides for the redirect virus and the Japanese keyword hack.

What if the scan finds nothing?

A clean result means this scan did not find suspicious redirects, spam links or other visible compromise indicators. It does not mean the installation is clean. If you are still seeing symptoms, the likeliest explanations are that the malware only triggers for certain visitors, that it lives entirely in files or the database, or that it has been removed from the front end while a backdoor remains.

Manual investigation is worth it when your host has flagged malware, Google Search Console reports pages you did not create, visitors describe redirects you cannot reproduce, or the problem keeps coming back after a cleanup. Reading the main types of WordPress malware may help you recognise which one you are dealing with, and hardening is what stops it happening again.

FAQ

Questions about hacked WordPress sites

Is my WordPress site hacked?

If visitors are redirected somewhere you did not configure, unfamiliar pages appear in Google for your domain, or your host has flagged malware, your site is very likely compromised. This checker looks for the signs that are visible from outside. It cannot rule out malware that only exists in your files or database.

How can I check WordPress for malware?

Start with what is visible publicly: the redirect chain, the page source, and what search engines show for your domain. That is what this tool automates. A complete answer needs file and database access, because most WordPress malware never appears in the HTML a visitor receives.

Can a website scanner detect all WordPress malware?

No. Any remote scanner, including this one, only sees what a website chooses to serve. Backdoors in PHP files, malicious database entries, scheduled tasks and code that only runs for certain visitors are all invisible from outside.

Why is my WordPress site redirecting to casino websites?

Almost always because injected code is redirecting your traffic to a site the attacker earns from. It commonly lives in a theme file, a plugin, the .htaccess file or the wp_options table, and it is often written to skip logged-in administrators so the owner does not notice.

Why are casino pages appearing on my WordPress site?

An attacker has generated pages on your domain to rank in search for gambling terms, borrowing your site's reputation. They are often hidden from ordinary visitors and served only to search engine crawlers.

What is WordPress SEO spam?

SEO spam is a compromise where an attacker adds content or links to your site to rank their own pages in search results. It targets your search visibility rather than your visitors, which is why it can run for months unnoticed.

Why are Japanese keywords appearing in Google for my website?

This is the Japanese keyword hack, an SEO spam compromise that creates Japanese-language pages on your domain, usually selling counterfeit goods. You will normally see them in Google before you see anything wrong on the site itself.

Can WordPress malware be hidden from visitors?

Yes, and it usually is. Malware routinely checks who is asking before deciding what to serve: it may show spam only to search engine crawlers, redirect only mobile visitors, or stay dormant for anyone logged in as an administrator.

Is this WordPress malware scan free?

Yes. The scan is free, needs no account and has no usage cost. If it finds something and you want it removed, standard WordPress malware removal is £59.

Does the scanner modify my website?

No. It sends normal GET requests for pages that are already public, exactly as any visitor or search engine would. It does not log in, change files or attempt to exploit anything.

Can Sudominus remove the malware if it is found?

Yes. I remove malware, backdoors, injected redirects and SEO spam, then close the entry point that allowed it. £59 for a standard WordPress site, with no fix, no fee. Complex sites and multisite installations are quoted upfront.

This tool performs a passive external check of publicly accessible website content. It does not exploit vulnerabilities, log into your website or inspect private server files. Results are indicators, not a guarantee that a site is clean or compromised. It is built and run by Rem, who operates Sudominus, a UK-based WordPress security service.

Found something you cannot explain?

I remove WordPress malware, backdoors and SEO spam for a fixed £59. No fix, no fee.

Clean my site, £59