Sign up free

Hacked Website Checker

Look for spam redirects, hidden links and content shown only to search engines.

About Hacked Website Checker

Many hacked sites look normal to their owners. The spam appears only to search engines or to people arriving from a search result, so the first sign is often gambling or pharma titles in Baidu or Google results, or a sudden drop in rankings. This hacked website checker fetches the page five ways, as a normal visitor, Baiduspider, Googlebot, a phone and a visitor coming from a Baidu search, and compares the final host, title and text of each version.

It also looks for gambling, adult and pharma spam words in Chinese and English, links hidden with display:none, off-screen positioning or marquee, scripts that redirect by referrer or user agent, packed eval() code, document.write(unescape()), long fromCharCode strings, a meta refresh to another site, invisible iframes and titles written as &#x…; codes. External script hosts are listed so you can spot one you don't recognize. It's passive, reading only what visitors get, and doesn't scan for vulnerabilities.

How to use Hacked Website Checker

  1. 1
    Enter the URL

    Start with the home page, then pages that show odd titles in search results.

  2. 2
    Click Scan

    The page is fetched five ways from our server, which can take up to half a minute.

  3. 3
    Compare the versions

    The table shows each visitor type's status, final address, title, text similarity and spam words.

  4. 4
    Clean up and scan again

    Remove what's flagged, update your software, change passwords and run the check again.

Why use Cubfile for this

  • Five points of view

    Visitor, Baiduspider, Googlebot, phone and a visitor arriving from a Baidu search.

  • Cloaking caught

    Spam words or another site shown only to crawlers or search visitors are flagged.

  • Hidden links and scripts

    Hidden link blocks, referrer and user-agent redirects, packed and encoded code.

  • Spam words in two languages

    Chinese and English gambling, adult and pharma terms.

FAQ

Hacked Website Checker: questions and answers

How can my site be hacked without me noticing?
Injected code often checks who's visiting. Crawlers and people clicking from a search result get spam or a redirect, while you, typing the address directly, get the normal page. That's why this checker visits as crawlers and as a search visitor. To read the raw HTML a crawler receives, open View Page Source and choose a crawler under Visit as.
What should I do if the checker finds signs of hacking?
Look for injected code in .htaccess, the server config, index.php, templates and recently changed files, and remove it. Update your CMS and plugins, change every password, then ask Baidu and Google to recrawl the cleaned pages.
Does a clean result mean my site is safe?
Not necessarily. The checker reads one page from the outside and doesn't scan for vulnerabilities or look at files on your server. Some injections show only on certain pages, at certain times or to certain visitors, so check several pages.
Why is the phone version's text similarity low?
Many sites serve a separate mobile page with different text and layout, which is normal. Low similarity is a prompt to compare, not proof of hacking. Spam words or a redirect to another domain are the real warning signs. The Redirect Checker follows a redirect hop by hop, so you can see where it ends.
Is the hacked website checker free?
Yes, with no sign-up and no daily tasks used. A scan takes a bigger share of the hourly allowance than a simple lookup, and the results aren't stored.
Share Hacked Website Checker with a friendIt runs in any browser, and they can try it without signing up.

Related tools

WEB Website Speed TestTime DNS, connection, first byte and download for a page, and see what slows it down.
SSL SSL Certificate CheckerCheck a site’s certificate: issuer, expiry, domains covered and whether browsers trust it.
HTTP HTTP Status Code CheckerCheck the status code of one URL or a whole list at once.
HTTP Redirect CheckerFollow every redirect hop, with status codes and timing, and catch loops.
WEB Website Technology DetectorSee the CMS, frameworks, analytics, CDN and server a website uses.
WEB Is It Down?Find out whether a site is down for everyone, and which step fails.
WEB CDN CheckerFind out whether a domain is behind a CDN, and which one.
WEB GZIP and Brotli CheckerCheck whether a page is sent compressed and how much it saves.