SECURITY FINDING

Unauthorized redirect via a meta refresh tag

What it is

The home page automatically redirects visitors to another URL via a meta refresh tag. If you didn't set this up, it's a common symptom of a hacked site sending your traffic to spam, ads or phishing pages.

How to fix it

If you didn't add this redirect on purpose, remove it. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).

In depth

Your security scan found a meta refresh tag in your site's code that automatically redirects visitors to a different website. If you did not intentionally add this, it usually means your site has been compromised and a hacker is using it to send your visitors to spam or malicious sites. To fix this, you need to remove the meta refresh code from your homepage. You can do this by logging into WordPress, going to your page editor, switching to the HTML view, and deleting the line that starts with "<meta http-equiv='refresh'" or similar. If you are not comfortable editing code, contact your web hosting company's support team and tell them you need to remove unauthorized redirect code from a specific page, or hire a WordPress specialist to clean it for you.

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.