SECURITY FINDING
Obfuscated JavaScript injected on the home page
What it is
The home page contains obfuscated JavaScript (encoded/decoded at runtime) — a technique legitimate code rarely needs, and a common way malware hides what it actually does from a casual look at the page source.
How to fix it
Review the page's source for a script you don't recognize. If you're not sure, install the WordPress Plugin and run AI Repair to clean it safely (with an automatic backup and rollback).
In depth
Your security scan found obfuscated JavaScript code on your home page, which means code that has been deliberately scrambled or hidden to avoid detection. Attackers use this technique to conceal malicious instructions that might steal visitor data, redirect people to harmful sites, or inject advertisements without your knowledge. This type of code should never be on your website and needs to be removed immediately. Start by checking whether this code came from a plugin or theme you installed, as legitimate tools sometimes use obfuscation for protection. If you cannot identify a trusted source, use a WordPress security plugin like Wordfence or Sucuri to scan and remove the malicious code automatically, or contact your hosting provider's support team to manually review and clean your home page files. After removal, update all your plugins and themes to their latest versions and change your WordPress admin password to prevent re-infection.
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.