SECURITY FINDING

Cryptomining script injected on the home page

What it is

The home page loads a cryptomining script. Visitors' browsers get used to mine cryptocurrency for whoever injected it, without their consent — this is essentially always a sign of compromise, never a legitimate feature.

How to fix it

Install the WordPress Plugin and run AI Repair to remove this immediately (with an automatic backup and rollback) — this is not something to leave in place while you investigate.

In depth

Your website contains malicious code that uses your visitors' computers and phones to secretly mine cryptocurrency for attackers without their knowledge. This hidden script runs in the background when people visit your site, consuming their device's processing power, draining battery life, and slowing down their experience. Beyond harming your visitors, this seriously damages your site's reputation and can cause search engines to block your site from appearing in search results. To fix this, you need to remove the malicious code immediately by restoring your website from a clean backup if you have one, or by hiring a WordPress security specialist to manually identify and delete the infected files. After removal, change all your WordPress admin passwords, update WordPress and all plugins to their latest versions, and consider installing a security plugin like Wordfence or Sucuri to scan for remaining threats and prevent future infections.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.