Free, no sign-up, in 10 seconds

Check your website for hacks, malware and hidden redirects

Enter your website address. I will check it from the outside, the way a search engine and a mobile visitor see it: defacement, mobile redirects, cloaking, the CMS version and open vulnerabilities. No site access needed.

Examples: hacked site · clean site

What I check: a "Hacked by..." message, redirects only from mobile devices, a different response served to search engines (cloaking), the Joomla version and whether it is outdated, the redirect chain, and security headers.

Checking the site from the outside...

This is an external instant check: what can be seen without access to the site. It does not replace a full audit that inspects files and the database, and it does not guarantee the site is 100% clean. For the Google Safe Browsing status, see the Google Transparency Report.

Current Joomla alerts

Running ZOO or YOOtheme Pro?

August 2026 security releases close critical ZOO upload and SQL-injection paths and two contributor-level YOOtheme Pro issues. Check ZOO 4.1.66 guidance, YOOtheme Pro 5.0.41 guidance, or the complete fixed-version table.

FAQ

Answers to common questions

If you cannot find your answer, message me on Telegram and I will help.

Is the check really free, and do I need to register?

Yes, it is free and there is no registration: no email, no phone, no account. You enter the site address and get a verdict plus a list of findings in about 10 seconds.

Do I have to install anything or share access?

No. The checker looks at your site from the outside, using only the address, so there is no need for hosting, FTP, admin panel or database access. You never enter any passwords.

What exactly does it check?

The usual external traces of a hack: defacement text such as "Hacked by", hidden redirects to casino and pharma pages, suspicious scripts in the page code, outdated vulnerable CMS and extension versions, signs of search engine warnings and security headers. All of that is visible from outside, without touching the site itself.

If the result says "clean", can I relax?

"Clean" means nothing suspicious is visible from the outside. That is a good sign, but not a full guarantee: a backdoor in the files or an injection in the database cannot be seen from outside. If you have other symptoms (visitor complaints, Search Console messages, spam sent from your addresses), you need a full audit with access to files and database.

What should I do if it finds something?

Do not delete things in a hurry: the traces show how they got in, and without that the hack usually comes back. You can work through the findings yourself, or write to me: I clean up hacked sites on Joomla, WordPress and PrestaShop, starting from 700 zł net depending on the scope.

Telegram