Free website security check

Is your website already compromised?

Enter your domain. In about 20 seconds we check 25+ public signals: malware and spam injection, hidden redirects, SSL/TLS, security headers, exposed software versions and email spoofing protection.

What the free check covers

Everything is read from the outside, exactly as a visitor or search engine sees your site.

Malware and spam injection

Casino, pharma and Japanese SEO spam, injected links and obfuscated scripts that hacked sites typically carry.

Hidden redirects and cloaking

Whether visitors or search engines are silently sent somewhere else — the classic sign of a compromised CMS.

SSL / TLS

Certificate validity and expiry, and whether every visitor is moved to an encrypted connection.

Security headers

HSTS, Content Security Policy, clickjacking and MIME protection, referrer and permissions policies.

Software exposure

Server, PHP and CMS versions your site reveals publicly, including software that no longer receives security fixes.

Email spoofing protection

SPF and DMARC records that stop criminals sending email in your company's name.

Safe by design

The check only reads what any visitor can already see. No login attempts, no exploitation, no load on your server.

Already hacked?

Redirects to casino or pharma sites, Google warnings, strange pages in search results? We clean infected sites and close the hole they came through.

Request a cleanup