Is my WordPress site hacked? A check from outside
Give your site's address and see the signs of a break-in that show from outside: visitors from search sent somewhere else, links hidden in the page, code written to hide what it does.
What it looks for
Our server asks for the one page at the address you give, twice. The first request is a plain one. The second says it arrived from a search result, because a site that has been broken into is often set to treat those visitors differently. It then reads what came back.
- Where a visitor ends up. Whether the address sends everyone to another site, and whether a visitor from a search result is sent somewhere a direct visitor is not.
- Links a reader cannot see. Links to other sites placed in a part of the page that is hidden, which is how injected spam is usually tucked in.
- Scripts that hide what they do. Code in the page that unpacks itself before it runs, and frames too small to see that load another site.
- Someone else's words. Spam wording in the title, the description or the links, and a title in another language than the page's own.
It works on any site, and the advice it links to is written for WordPress.
What a result means
Each line is a sign, with what else could explain it. A theme can hide a block for a sound reason. A site can move to a new domain on purpose. So a sign is a reason to look closer, and never proof. A result with no signs is not proof either: it means this one page, asked for twice from outside, showed none of them.
What it cannot see
- The site's files and database. It does not sign in and reads no file, so it is not a malware scan.
- What only a search engine is shown. Some break-ins show their pages only to a search engine's own crawler, which they recognize by its network address. Nobody outside can imitate that. Google Search Console shows you the page as Google received it, and lists what Google has flagged under Security issues.
- Other pages. It reads the page at the address you give. Spam pages added elsewhere on the site do not show here. Searching Google for
site:example.com, with your own domain, lists the pages it knows. - Rules that pick their visitors another way. By the kind of phone, the country, or the time of day, for instance.
How to check whether a WordPress site has been hacked covers the checks from inside. If you already know, the runbook for the first hour says what to do, in order.
What happens to the address
The address goes to our server, which makes the two requests and sends back the report. Neither the address nor the pages are kept or logged. Both requests name themselves as WPMinistry-SiteCheck, so they can be told apart in the site's own logs. Only public web addresses are asked.
Common questions
It found nothing. Is my site clean?
It found a sign. Have I been hacked?
Why does it ask for the page twice?
Can I check a site that is not mine?
Would you rather someone looked inside?
Tell us what you are seeing. We look at the site itself and reply with the cause and a fixed quote. The diagnosis is free.
Get a free diagnosis
