WP Clinic
Log in Sign up

SECURITY FINDING

Hidden iframe injected on the home page

What it is

The home page loads an invisible (zero-size or hidden) iframe from a domain we don't recognize as a common embed/ad/analytics provider. This is a textbook sign of an injected drive-by-download or redirect on a compromised site.

How to fix it

If you didn't add this embed on purpose, remove it. If you're not sure or the page was edited by someone else, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.