SECURITY FINDING

Hidden iframe injected on the home page

What it is

The home page loads an invisible (zero-size or hidden) iframe from a domain we don't recognize as a common embed/ad/analytics provider. This is a textbook sign of an injected drive-by-download or redirect on a compromised site.

How to fix it

If you didn't add this embed on purpose, remove it. If you're not sure or the page was edited by someone else, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).

In depth

A hidden iframe is invisible code that loads content from another website into your home page without visitors realizing it. Attackers use these to redirect your visitors to malicious sites, steal their information, or infect their computers with malware. Your site's visitors could be harmed and your site's reputation damaged, even though nothing looks wrong on the surface. To fix this, log into your WordPress dashboard, go to Appearance and then Theme File Editor, then search your theme's files for suspicious iframe code and delete it. If you cannot find or remove the code yourself, use a reputable WordPress security plugin like Wordfence or Sucuri to automatically scan and remove the hidden iframe, then change all your WordPress passwords immediately.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.