How to tell if your site has been compromised

Most infections don't announce themselves — they show up as small, odd symptoms before anything looks obviously wrong.

Signs to watch for

1 Your browser or a visitor's shows a red "Deceptive site ahead" / "This site may be hacked" warning.
2 The site redirects unexpectedly to another page, or shows content you didn't add — pop-ups, adult content, spam links buried in the page.
3 You notice files or a WordPress admin user you don't recognise, or existing files with a very recent, unexplained modification date.
4 Outgoing e-mail bounces, or your domain lands on a spam blocklist, without you having sent anything unusual.
5 The site slows down or the hosting resource usage spikes for no reason you changed.

Check it directly

1 In cPanel, open Imunify Security — every account here is scanned automatically, and this page shows anything already detected or quarantined, no need to request a scan.
2 For a second opinion, paste your domain into sitecheck.sucuri.net (free, no account needed) or check Google's Safe Browsing report for your domain.
Running WordPress? A security plugin such as Wordfence adds ongoing monitoring on top of the server-level scanning, and will flag a compromised plugin or theme file specifically.

Found something? See how to clean up a compromised site.

Found a warning and not sure what it means? Send us the details.

Open a support ticket

SEE ALSO

How to redirect HTTP to HTTPS with .htaccess

How to clean up a compromised site

Why does my SSL certificate show fewer than 365 days?

Want a paid SSL certificate? See the options.

WEB HOSTING

Looking for hosting that stays out of your way?

cPanel, a free SSL certificate, backups every night before dawn kept for a year, and support that answers in your language.

See hosting plans

Free migration of your current site · no lock-in

  • 0 Users Found This Useful
Was this answer helpful?