SECURITY FINDING
Cryptomining script injected on the home page
What it is
The home page loads a cryptomining script. Visitors' browsers get used to mine cryptocurrency for whoever injected it, without their consent — this is essentially always a sign of compromise, never a legitimate feature.
How to fix it
Install the WordPress Plugin and run AI Repair to remove this immediately (with an automatic backup and rollback) — this is not something to leave in place while you investigate.
In depth
Your website contains malicious code that uses your visitors' computers and phones to secretly mine cryptocurrency for attackers without their knowledge. This hidden script runs in the background when people visit your site, consuming their device's processing power, draining battery life, and slowing down their experience. Beyond harming your visitors, this seriously damages your site's reputation and can cause search engines to block your site from appearing in search results. To fix this, you need to remove the malicious code immediately by restoring your website from a clean backup if you have one, or by hiring a WordPress security specialist to manually identify and delete the infected files. After removal, change all your WordPress admin passwords, update WordPress and all plugins to their latest versions, and consider installing a security plugin like Wordfence or Sucuri to scan for remaining threats and prevent future infections.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.