Security · Live check

Is my site hacked?

Enter your address — we fetch the homepage and look for typical hack signs: foreign redirects, obfuscated malware, hidden iframes, spam content and defacement markers. In seconds, right in your browser.

In short

Signs your WordPress site is hacked include unknown admin users, foreign redirects, spam content, a warning in Google or the browser, and unexpected files. Check with a malware scan, via Google Safe Browsing, and by reviewing file changes. Forge12 offers a free initial check and manual cleanup at a fixed price from €490.

FAQ

Frequently asked questions

01How reliable is this check?

It's a surface scan of the publicly reachable homepage — fast and helpful, but no guarantee. It finds the most common visible symptoms. Many hacks hide, though: they only show to search engines (cloaking), only to visitors arriving via Google, or sit deep in files and database where an online check can't look.

02It says “clean” — can I relax?

Not with certainty. A clean result doesn't rule out a hack, because this test only checks the visible homepage. If you have concrete signs (Google warning, host suspension, ranking drop), have it checked more deeply.

03Anomalies were found — what now?

Don't panic, but act soon: back up the site (files + database), change all passwords and limit the damage. For cleanup we offer WordPress hack recovery — by hand, at a fixed price.

04How else can I tell my site is hacked?

Typical signs: a Google warning “This site may be hacked”, a host suspension, sudden redirects to spam pages, foreign sub-pages in the Google index, or a sudden drop in rankings.

05Do you also check files and database?

This online check doesn't — it only sees the served homepage. In our recovery service we deep-scan core, themes, plugins, uploads and the database, and also find hidden backdoors.

06Are my data stored?

No. We fetch the entered URL once server-side and show the result. Nothing is logged or stored.

Suspicion confirmed? We get your site back.