Is My Website Hacked? Free WordPress Site Checker

By DrGlenn — USA-based WordPress security specialist · 290+ cleanups across 34 countries · free, instant, no signup.

🛡 Worried about your email or domain reputation too?Run the free Blacklist Checker →

Is My Website Hacked? Free Instant Checker

Enter your web address and I’ll run a deep external scan — the same reconnaissance an attacker does. I check your homepage the way a visitor and Google see it (injected code, hidden iframes, spam, redirects, cloaking), then fingerprint your WordPress core, plugins, theme, admin accounts, and exposed files to show you exactly what your site is leaking. Free, instant, no signup.



Important: this is only a fast surface scan of your public homepage. Many hacked sites look completely normal on the front end — the malware hides in server files, the database, or backdoors this scan simply cannot see. A clean result here does NOT mean your site is safe. The only way to know for certain is a full professional inspection.

Not sure? Get a real inspection — just $19.95

An outside scan can only see so much. For $19.95 I’ll personally do a full, hands-on inspection of your site — the server files, the database, and the hidden places malware likes to hide that no external scan can ever reach — and tell you exactly what, if anything, is wrong.

And if I find a problem, that $19.95 goes straight toward the repair. So the inspection effectively costs you nothing when your site needs work — you never pay for it twice.

Get My $19.95 Inspection See how it works →

What this checker looks for

  • Obfuscated / injected codeeval, base64_decode, char-code strings and long encoded blobs that hide malware.
  • Hidden iframes — invisible frames used to deliver malware to your visitors.
  • SEO-spam injection — pharma, casino, replica and other spam keywords added to your pages.
  • Cloaking & redirect hacks — spam or redirects shown only to Google or only to certain visitors.
  • Exposed WordPress version and missing hardening headers that make you an easier target.
  • Outdated plugins & theme — enumerated from the outside and checked against the current releases.
  • Leaked admin usernames — leaked usernames are a serious security issue that leads to thousands of hacked sites every day.
  • Exposed files & backups — readme, debug logs, .git, .env, wp-config backups, and open directory listings.

My site is flagged — what now?

If the check finds problems — or Google, your host, or an antivirus has already flagged you — don’t panic, and don’t just delete the obvious file. Malware almost always leaves a hidden backdoor that rebuilds itself. I remove the infection completely, get the warnings lifted, and harden the site so it stays clean. You work directly with one USA-based expert — not an overseas queue.

Get My Site Cleaned See how it works →

Frequently asked questions

Is this checker really free? Yes — run it as many times as you like. It checks your live homepage and how it appears to Google.

It says my site is clean. Am I 100% safe? No. A scan that only reads your public homepage cannot see server files, the database, or backdoors — and that is exactly where most infections hide. Plenty of compromised sites look perfectly clean out front. Treat a clean result as “nothing obvious on the homepage,” not “your site is safe.”

It found something — can you fix it? Yes. I clean hacked WordPress sites every day — malware removal, blacklist/false-positive removal, and hardening. Start here.

Does it work on non-WordPress sites? The surface checks run on any site, but my specialty is WordPress.