Hacked site checker:Does Google see a different site than you do?
We fetch your page as a visitor, as Googlebot and as a visitor arriving from Google, and show any injected text, spam links or redirects with the evidence.
- Free, no account
- Results in under a minute
- Any public URL
example-shop.hr
WordPress 6.8Sample shop · homepage · mobile Chrome · the same check you get for your own site
6 passed · 1 failed · 0 warnings. Biggest issue: Sensitive files are readable by anyone.
The page, fetched three ways
differences are evidence, not a verdict| Signal | Normal visitor | Googlebot | Visitor from Google |
|---|---|---|---|
| Response | 200 | 200 | 200 |
| Final URL | example-shop.hr/ | example-shop.hr/ | example-shop.hr/ |
| Visible words | 354 | 354 | 354 |
| Words not on the visitor page | — | 0% | 0% |
| Links | 23 | 23 | 23 |
| Hidden links | 0 | 0 | 0 |
| Spam vocabulary | none | none | none |
| Text in another script | none | none | none |
| Referrer redirect script | none | none | none |
What we found
Show 6 passed checks
Fix these first
From the example above. Check your own site to get the fixes that apply to it.
Problem: Sensitive files are readable by anyone
/.env holds database passwords and API keys; /.git exposes your source code and every secret ever committed.
How to fix it: Block dotfiles at the web server (nginx: location ~ /\. { deny all; }; Apache: RedirectMatch 404 /\..*$).
What this tool checks
Three copies of the same page, compared. Differences come with evidence, never a verdict: you decide what belongs there.
Cloaked content
Compares the page as visitors and Googlebot see it, since hidden differences can signal a hack.
Spam links
Looks for spam links or links shown only to Google, a common sign that someone injected them.
Redirects only for Google
Checks that visitors arriving from Google are not sent to another site that direct visitors never see.
Hidden outbound links
Finds links hidden from visitors but visible to search engines, a pattern injections use.
Google unsafe site flag
Checks whether Google lists the site as malware or phishing, which puts a red warning in browsers.
CMS version
Compares the CMS version your page reveals with the latest release, since old versions have known holes.
Plugins closed on wordpress.org
Flags detected plugins that wordpress.org has closed, often because of a security issue.
Abandoned plugins
Flags detected plugins with no update in over 2 years, which no longer get security fixes.
Exposed .env and .git files
Checks that files holding passwords, keys or source code can't be downloaded by anyone.
Directory listings
Checks folders don't show an automatic list of every file, including backups and settings.
Show 6 more checks
Google unsafe site flag
Checks whether Google lists the site as malware or phishing, which puts a red warning in browsers.
CMS version
Compares the CMS version your page reveals with the latest release, since old versions have known holes.
Plugins closed on wordpress.org
Flags detected plugins that wordpress.org has closed, often because of a security issue.
Abandoned plugins
Flags detected plugins with no update in over 2 years, which no longer get security fixes.
Exposed .env and .git files
Checks that files holding passwords, keys or source code can't be downloaded by anyone.
Directory listings
Checks folders don't show an automatic list of every file, including backups and settings.
How it works
Fetch the page three ways
The page is fetched with our normal user agent, with Googlebot's user agent, and with a browser user agent plus a Referer from google.com.
Compare the copies
The visible text, the outbound links and the inline scripts of the three copies are compared with each other.
Show the evidence
Text only Googlebot receives, spam or bot-only links, links in hidden containers, text in an unexpected script and redirects that fire only for Google visitors are listed.
One page per run. Some injections fire only on certain pages or at certain times, so a clean result here does not clear the whole site.
Questions
Is this really free?
Yes. getReport is funded by donations, not plans. This tool runs the full report and shows you the part it is about; the complete report with all seven modules is one click away, also free.
It found differences. Am I hacked?
Read the evidence. Pharma, casino or loan links you did not add, text in a language you do not publish in, or a redirect to a site you do not own are injections. A different menu for mobile user agents is not. The learn page walks through the cleanup.
It found nothing but Google shows spam for my site.
Some injections only fire on certain pages (old posts, category pages) or at certain times. Check the pages Google lists with spam in Search Console, one by one, and look the site up on Google's Safe Browsing site status page.
Why does a hacked site look fine to its owner?
Modern injections hide from the person most likely to notice. They show spam only to Googlebot, or only to visitors who arrive from a Google result, and a clean page to everyone who types the address. The owner sees nothing; Google sees a pharmacy; visitors from Google land on a casino. Comparing the three fetches is what Search Console's URL Inspection does, without the login and the wait. The result says "differences found" with evidence, never "hacked": some sites legitimately vary content by user agent.
Do you store my results?
The report is kept for 12 months at its shareable link so you can come back to it. Reports are not listed publicly and carry a noindex tag; nothing about your visitors is collected.
Related free tools
All 41 tools →Free, funded by the people who use it
€0 of €75 this month. At €75, site crawl up to 500 pages + weekly re-check switches on for everyone.