NEW CASE
Antana

We create digital solutions that work for businesses


Give us a call +38 (066) 35-14-529

Let's take the first step towards your website — write to us

Close
Tools

Website Malware Scanner

Malicious code, exposed files and security holes.

We scan the homepage and common system paths: malicious code signatures, exposed files, directory listing, SSL, security headers and blacklists. Takes 15–25 seconds.

Signs your site has been hacked

Modern malware hides itself: the owner opens the site and everything looks normal. So you judge by indirect signs.

Strange links in the footer The most common case. Casino or pharmacy links are hidden in the footer, white on white — visible only in the page source.
Redirects only on mobile On a desktop the site loads fine; on a phone it sends visitors elsewhere. The code deliberately tells them apart.
A warning in search results Google flags the site as dangerous and the browser shows a red warning instead of your page. Traffic drops to near zero within a day.
Unfamiliar pages in search URLs you never created appear in Search Console, often in a language you do not use.
An email from your host The provider warns about suspicious activity or spam being sent from your account.
The site suddenly slowed down Injected code eats server resources. If speed dropped without any change on your side, it is worth checking.

What to do when malware is found

Order matters: clean up without changing passwords first and the code returns the same day.

1 Change every password Hosting, FTP, database, site admin — in that order. Otherwise the attacker simply returns through the door you left open.
2 Restore from a backup Use a copy made well before the infection. Faster and safer than hunting injected fragments by hand.
3 Close the hole Update the CMS and its extensions. Most break-ins come through an outdated plugin, and without updating it will happen again.
4 Check again Run the site through the check above and confirm it is clean. While you are at it, see whether the IP landed on a blacklist.
5 Request a review If Google already flagged the site, submit a reconsideration request in Search Console. The warning is usually lifted within days.

How to avoid being hacked again

Updates A vulnerability in a popular extension gets published, and within hours bots are testing every site online. Updating closes that window.
Backups Automatic, and stored separately. A copy sitting next to the site disappears along with it.
Admin access Strong passwords, two-factor authentication, and an IP restriction if you always log in from one place.
Unused extensions Every plugin you do not use is an open door. Delete them rather than just switching them off.

FAQ

What exactly do you check?
We analyse the homepage code for typical infection markers: encoded scripts executed via eval and atob, hidden zero-size iframes, cryptocurrency miners, heavily obfuscated JavaScript, redirects to third-party domains. Separately we check whether system files such as .env and .git/config are reachable, whether directory listing is on, the state of the SSL certificate, security headers and whether the IP appears in spam databases.
Does this replace a proper website antivirus?
No, and that matters. We only see what is served externally: the homepage code and the availability of a few paths. Malicious code can hide in server files, in the database, inside plugins, or be shown selectively — only to search bots or to mobile visitors. A full check requires file system access and a scan of the entire site. Our tool is a fast external diagnosis that catches the most common cases.
Why is an accessible .env or .git file dangerous?
A .env file usually holds database passwords, payment system keys and API tokens in plain text. If it is reachable by direct link, an attacker does not need to break anything: they simply open the URL and read your keys. A .git directory is no less dangerous: it lets someone reconstruct your entire source code along with its change history, which often contains passwords that were once committed and later removed. Both must be blocked at the web server level.
What should I do if malicious code is found?
Follow this order. First change every password: hosting, FTP, admin panel, database — infections usually start with stolen access. Then restore a clean backup made before the infection date. Update your CMS and all extensions: in most cases the entry point is an outdated plugin. Review the list of admin users — attackers routinely leave themselves an extra account. Once cleaned, submit the site for review in Google Search Console if it was flagged as dangerous.
Telegram Viber Call us