Remove malware, restore access and recover a compromised WordPress website.
● FREE WORDPRESS HACK CHECKER
Check your WordPress site for signs of a hack.
Enter your website address. Dr Web will inspect the public signals for suspicious redirects, injected code, SEO spam and common WordPress security exposure.
- No login required
- No changes to your website
- Public signals only
- Results in about a minute
What is your website showing the outside world?
The checker makes a small number of controlled requests to public pages. It never logs in, executes downloaded scripts or changes the website.
Only scan a website you own or are authorised to check.
● WHAT THE CHECKER LOOKS FOR
Five groups of public signals
01
Availability and redirects
HTTP status, HTTPS availability, response time and redirects to unexpected destinations.
02
Suspicious page code
Hidden frames, unusual scripts, obfuscation patterns and deceptive browser-update wording.
03
SEO spam signals
Public wording commonly associated with casino, pharmaceutical and crypto spam injections.
04
External domains
Third-party script and frame hosts that match a limited set of unusual-domain indicators.
05
WordPress exposure
WordPress detection, public REST and XML-RPC responses, and an exposed WordPress readme.
06
Reputation check
Google Safe Browsing threat matches when the external reputation service is configured.
How to read your result
01
No obvious compromise
No strong external warning signs were detected. This never guarantees the website is clean.
02
Security issues
The scan found exposure worth reviewing without strong evidence of an active compromise.
03
Suspicious activity
One or more behaviours associated with compromised websites need investigation.
04
High likelihood
Strong public compromise indicators warrant prompt specialist investigation.
A quiet scan is not a clean bill of health
Some compromises stay hidden from ordinary visitors or only appear under particular conditions. The free checker cannot inspect:
- WordPress files and core integrity
- database content and injected records
- administrator users and access history
- server logs, scheduled tasks or hosting configuration
- backdoors and other persistence mechanisms
If the scan finds suspicious activity—or the site behaves strangely despite a quiet result—a deeper WordPress investigation is the safest next step.
What happens when a scan is not enough
01
A specialist first look
Dr Web focuses on WordPress recovery and care, not generic website troubleshooting.
02
Investigation beyond the homepage
Files, database records, users, scheduled tasks and the hosting environment can all need review.
03
Controlled access
Credentials are never submitted through the scanner or ordinary email. Secure access is arranged later.
04
Written findings
Important findings and actions are recorded, including anything that remains uncertain or with a third party.
Frequently asked questions
No. The checker only reviews publicly visible signals. Malware can remain hidden in files, database records, user accounts or server configuration.
No. It requests a small number of public URLs and does not log in, execute downloaded scripts or modify the scanned website.
Yes. The general external checks still run, but WordPress-specific observations may not apply.
Some malicious code only appears to certain devices, search engines or logged-in visitors. Other malware is not visible from public pages.
Avoid deleting random files or installing multiple security tools. Preserve a known-good backup if available, document the symptoms and arrange a controlled WordPress investigation.
Still worried about the website?
Tell us what you have noticed. Dr Web will review the request and explain the safest next step.