SECURITY FINDING

Sign of a compromised WordPress site on the home page

What it is

Our scan found a pattern on the home page that's a common sign of a compromised site (injected/obfuscated code, a hidden redirect, spam content, or similar — see the detail above).

How to fix it

Review the page's source for content you don't recognize. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).

In depth

Our security scan detected suspicious code on your website's home page that appears to have been injected by an attacker. This hidden code can redirect your visitors to malicious websites, inject spam content, or steal their information, which harms both your visitors and your site's reputation. Google and other search engines may delist or penalize your site if they detect this malicious content. To fix this, you should immediately back up your website files, then either use a WordPress security plugin with malware removal features to scan and clean the infected files, or hire a WordPress professional to manually remove the malicious code from your home page template. After removal, change all your WordPress admin passwords and check your user accounts for any unauthorized access.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.