Blog
How to Check If Your Website Has Been Hacked (Free Tools Inside)

Key Takeaways
- Use free external scanners like Sucuri SiteCheck and VirusTotal for a quick first pass.
- Check Google Safe Browsing status and Google Search Console for security alerts.
- Manually inspect your .htaccess file, JavaScript files, and FTP directories for injected code.
- Search Google for pharma or casino spam pages indexed under your domain.
- If you find signs of compromise, act immediately — every hour counts.
Why Speed Matters When Detecting a Website Hack
A hacked website isn’t just an inconvenience. According to Google, over 10,000 websites are blocklisted every day for malware and phishing. Once your site lands on that list, you lose organic traffic, customer trust, and potentially revenue. The longer malware sits on your site, the deeper it embeds. Attackers install backdoors, inject SEO spam, and harvest visitor data. Early website hack detection is the difference between a quick cleanup and a full site rebuild. If you’ve already noticed warning signs that your WordPress site is hacked, these checks will help you confirm and locate the problem.Step 1: Check Google Safe Browsing Status
Google maintains a massive database of unsafe websites. Here’s how to check if your site is flagged:- Go to Google’s Transparency Report
- Enter your full domain URL
- Review the site status
Step 2: Run a Sucuri SiteCheck Scan
Sucuri SiteCheck is one of the most reliable free website hack detection tools available. Here’s how to use it:- Visit sitecheck.sucuri.net
- Enter your website URL
- Click Scan Website
- Malware — malicious code embedded in your pages
- Blocklist status — whether security vendors have flagged your site
- Injected spam — hidden links or content added by attackers
- Outdated software — CMS or plugin versions with known vulnerabilities
- Website errors — server-side issues that could indicate tampering
Step 3: Scan with VirusTotal
VirusTotal aggregates results from over 70 antivirus engines and URL scanners. It gives you the broadest possible perspective on whether your site is flagged.- Go to virustotal.com
- Click the URL tab
- Paste your website address and hit Enter
Step 4: Review Google Search Console Security Issues
If you have Google Search Console set up (and you should), it’s one of the most authoritative sources for website hack detection.- Log in to Google Search Console
- Select your property
- Navigate to Security & Manual Actions → Security Issues
- Hacked content — pages that were added or modified without your consent
- Malware or unwanted software — code that harms visitors
- Social engineering — phishing pages or deceptive content
- Deceptive pages — pages impersonating trusted entities
Step 5: Check for Unfamiliar Files via FTP or File Manager
External scanners catch a lot, but some hacks hide on the server side where scanners can’t reach. It’s time to look under the hood. Connect to your site via FTP (using FileZilla, Cyberduck, or your hosting file manager) and check for:- Files you don’t recognize — especially PHP files in your root directory, wp-includes, or wp-content/uploads Hackers often upload files with names like wp-config-backup.php, db-cache.php, or random strings like x7hd9.php.
- Recently modified files — sort by modification date. If core files were changed on a date you didn’t deploy updates, that’s a red flag.
- Files in upload directories — the wp-content/uploads/ folder should contain images and media files, not .php Any PHP file here is suspicious.
What to Look For
/assets/wp-content/uploads/2025/malicious-file.php ← Suspicious /assets/wp-includes/class-wp-backdoor.php ← Suspicious /index-old.php ← Suspicious If you find files you didn’t create, do not delete them yet. Document everything first. You’ll need this information during the malware removal process.Step 6: Inspect Your .htaccess File for Injections
The .htaccess file is a favorite target for hackers because it controls how your server handles requests. A compromised .htaccess can redirect your visitors to malicious sites — often without you ever noticing because the redirects only trigger for search engine visitors, not direct traffic. Open your .htaccess file (located in your site’s root directory) and look for:- Unfamiliar RewriteRule directives — especially ones redirecting to external domains
- Base64 encoded strings — long blocks of random characters are almost always malicious
- Conditional redirects — rules that check HTTP_REFERER for Google, Bing, or Yahoo and redirect only search traffic
- eval() or base64_decode() calls — these should never appear in .htaccess
Step 7: Scan for Malicious JavaScript
Hackers frequently inject malicious JavaScript into your site’s theme files, plugin files, or directly into the database. This code can steal visitor information, redirect traffic, or mine cryptocurrency using your visitors’ browsers. If sensitive personal details are stolen through these scripts, utilizing identity theft protection helps affected users monitor their personal accounts and prevent unauthorized activity. Here’s how to check:- View page source — Right-click on your site and select “View Page Source.” Search (Ctrl+F) for <script tags you don’t recognize, especially ones loading external scripts from unfamiliar domains.
- Check your theme’s php and footer.php — These are common injection points. Look for obfuscated code or scripts loading from third-party domains.
- Search for obfuscated code — Look for eval(, fromCharCode(, atob(, or document.write( combined with long encoded strings. Legitimate plugins rarely use heavy obfuscation.
Red Flags in JavaScript
- Scripts loading from domains you didn’t add
- Obfuscated code blocks with random variable names
- Hidden iframes (<iframe style="display:none")
- Code injected before the closing </body> tag that you didn’t place
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Step 8: Check Google Search Results for Spam Pages
This is one of the most revealing checks you can perform, and it takes 30 seconds. Open Google and search: site:yourdomain.com viagra OR casino OR payday OR cheap If you see results with spammy titles about pharmaceuticals, gambling, payday loans, or counterfeit goods — your site has been hit with a Japanese keyword hack or similar SEO spam attack. These pages are invisible to you when browsing normally but fully indexed by Google. Also try: site:yourdomain.com inurl:/wp-content/ filetype:php This surfaces PHP files in locations where they normally shouldn’t exist, potentially revealing uploaded backdoors or spam page generators.What to Do If You Confirm Your Website Is Hacked
If any of these checks come back positive, here’s your immediate action plan:- Don’t panic, but act fast. Every hour matters.
- Document everything — screenshot scan results, note suspicious files, save copies of injected code.
- Change all passwords — WordPress admin, FTP, database, hosting control panel. Do this from a clean device.
- Contact your hosting provider — they may be able to provide server logs and additional support.
- Begin the cleanup process — follow our step-by-step guide on how to remove malware from your website.
- Get professional help if needed — a thorough cleanup includes checking for backdoors, hardening security, and requesting Google review.
Free Website Hack Detection Tools — Quick Reference
| Tool | What It Checks | Best For |
| Google Safe Browsing | Blocklist status | Confirming Google has flagged your site |
| Sucuri SiteCheck | Malware, blocklists, outdated CMS | Comprehensive front-end scan |
| VirusTotal | 70+ antivirus engine results | Cross-referencing multiple security vendors |
| Google Search Console | Security issues, hacked content | Authoritative alerts with specific details |
| FTP / File Manager | Server-side files | Finding uploaded backdoors and shells |
| Google site: search | Indexed spam pages | Detecting SEO spam injection |
Frequently Asked Questions
How do I know if my website has been hacked?
Can a hacked website affect my SEO rankings?
Are free website security scanners accurate?
How often should I scan my website for malware?
Put this into action with eSEOspace
We help businesses grow with maintenance & support that actually performs. Explore the services behind this guide:
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!
On this page
- Key Takeaways
- Why Speed Matters When Detecting a Website Hack
- Step 1: Check Google Safe Browsing Status
- Step 2: Run a Sucuri SiteCheck Scan
- Step 3: Scan with VirusTotal
- Step 4: Review Google Search Console Security Issues
- Step 5: Check for Unfamiliar Files via FTP or File Manager
- Step 6: Inspect Your .htaccess File for Injections
- Step 7: Scan for Malicious JavaScript
- Step 8: Check Google Search Results for Spam Pages
- What to Do If You Confirm Your Website Is Hacked
- Free Website Hack Detection Tools — Quick Reference
- Frequently Asked Questions






