SECURITY FINDING
Malicious document.write() injection
What it is
The home page writes encoded content into itself via document.write — often used to smuggle a malicious script or redirect past a casual look at the page source.
How to fix it
Review the page's source for a script you don't recognize. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.