SECURITY FINDING
Sign of a compromised WordPress site on the home page
What it is
Our scan found a pattern on the home page that's a common sign of a compromised site (injected/obfuscated code, a hidden redirect, spam content, or similar — see the detail above).
How to fix it
Review the page's source for content you don't recognize. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).
In depth
Our security scan detected suspicious code on your website's home page that appears to have been injected by an attacker. This hidden code can redirect your visitors to malicious websites, inject spam content, or steal their information, which harms both your visitors and your site's reputation. Google and other search engines may delist or penalize your site if they detect this malicious content. To fix this, you should immediately back up your website files, then either use a WordPress security plugin with malware removal features to scan and clean the infected files, or hire a WordPress professional to manually remove the malicious code from your home page template. After removal, change all your WordPress admin passwords and check your user accounts for any unauthorized access.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.