WP Clinic
Log in Sign up

SECURITY FINDING

Malicious document.write() injection

What it is

The home page writes encoded content into itself via document.write — often used to smuggle a malicious script or redirect past a casual look at the page source.

How to fix it

Review the page's source for a script you don't recognize. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.