Free Tool
WordPress Malware Risk Checker
Scan publicly visible page source for common signs of injected code, spam hacks, and malicious redirects.
What this checks
- Obfuscated/suspicious injected code patterns
- Hidden iframes and hidden links
- Spam SEO injection signals
- Unexpected cross-domain redirects
- Unusual breadth of external script sources
This is not a full malware scanner — it can't see inside your files, database, or server. It only catches patterns visible in the public page source. A clean result is a good sign, not a guarantee, and a flagged result isn't proof of infection — some patterns have legitimate explanations too.