Skip to content

Hacked site checker:Does Google see a different site than you do?

We fetch your page as a visitor, as Googlebot and as a visitor arriving from Google, and show any injected text, spam links or redirects with the evidence.

  • Free, no account
  • Results in under a minute
  • Any public URL
Example result

example-shop.hr

WordPress 6.8

Sample shop · homepage · mobile Chrome · the same check you get for your own site

Run it on your site
Security

6 passed · 1 failed · 0 warnings. Biggest issue: Sensitive files are readable by anyone.

The page, fetched three ways

differences are evidence, not a verdict
The same page fetched as a visitor, as Googlebot and as a visitor from Google
SignalNormal visitorGooglebotVisitor from Google
Response200200200
Final URLexample-shop.hr/example-shop.hr/example-shop.hr/
Visible words354354354
Words not on the visitor page—0%0%
Links232323
Hidden links000
Spam vocabularynonenonenone
Text in another scriptnonenonenone
Referrer redirect scriptnonenonenone

What we found

1 failed0 warnings6 passed
Show 6 passed checks

Fix these first

From the example above. Check your own site to get the fixes that apply to it.

  1. Problem: Sensitive files are readable by anyone

    /.env holds database passwords and API keys; /.git exposes your source code and every secret ever committed.

    How to fix it: Block dotfiles at the web server (nginx: location ~ /\. { deny all; }; Apache: RedirectMatch 404 /\..*$).

What this tool checks

Three copies of the same page, compared. Differences come with evidence, never a verdict: you decide what belongs there.

  • Cloaked content

    Compares the page as visitors and Googlebot see it, since hidden differences can signal a hack.

  • Spam links

    Looks for spam links or links shown only to Google, a common sign that someone injected them.

  • Redirects only for Google

    Checks that visitors arriving from Google are not sent to another site that direct visitors never see.

  • Hidden outbound links

    Finds links hidden from visitors but visible to search engines, a pattern injections use.

  • Google unsafe site flag

    Checks whether Google lists the site as malware or phishing, which puts a red warning in browsers.

  • CMS version

    Compares the CMS version your page reveals with the latest release, since old versions have known holes.

  • Plugins closed on wordpress.org

    Flags detected plugins that wordpress.org has closed, often because of a security issue.

  • Abandoned plugins

    Flags detected plugins with no update in over 2 years, which no longer get security fixes.

  • Exposed .env and .git files

    Checks that files holding passwords, keys or source code can't be downloaded by anyone.

  • Directory listings

    Checks folders don't show an automatic list of every file, including backups and settings.

Show 6 more checks
  • Google unsafe site flag

    Checks whether Google lists the site as malware or phishing, which puts a red warning in browsers.

  • CMS version

    Compares the CMS version your page reveals with the latest release, since old versions have known holes.

  • Plugins closed on wordpress.org

    Flags detected plugins that wordpress.org has closed, often because of a security issue.

  • Abandoned plugins

    Flags detected plugins with no update in over 2 years, which no longer get security fixes.

  • Exposed .env and .git files

    Checks that files holding passwords, keys or source code can't be downloaded by anyone.

  • Directory listings

    Checks folders don't show an automatic list of every file, including backups and settings.

How it works

  1. Fetch the page three ways

    The page is fetched with our normal user agent, with Googlebot's user agent, and with a browser user agent plus a Referer from google.com.

  2. Compare the copies

    The visible text, the outbound links and the inline scripts of the three copies are compared with each other.

  3. Show the evidence

    Text only Googlebot receives, spam or bot-only links, links in hidden containers, text in an unexpected script and redirects that fire only for Google visitors are listed.

One page per run. Some injections fire only on certain pages or at certain times, so a clean result here does not clear the whole site.

Questions

Is this really free?

Yes. getReport is funded by donations, not plans. This tool runs the full report and shows you the part it is about; the complete report with all seven modules is one click away, also free.

It found differences. Am I hacked?

Read the evidence. Pharma, casino or loan links you did not add, text in a language you do not publish in, or a redirect to a site you do not own are injections. A different menu for mobile user agents is not. The learn page walks through the cleanup.

It found nothing but Google shows spam for my site.

Some injections only fire on certain pages (old posts, category pages) or at certain times. Check the pages Google lists with spam in Search Console, one by one, and look the site up on Google's Safe Browsing site status page.

Why does a hacked site look fine to its owner?

Modern injections hide from the person most likely to notice. They show spam only to Googlebot, or only to visitors who arrive from a Google result, and a clean page to everyone who types the address. The owner sees nothing; Google sees a pharmacy; visitors from Google land on a casino. Comparing the three fetches is what Search Console's URL Inspection does, without the login and the wait. The result says "differences found" with evidence, never "hacked": some sites legitimately vary content by user agent.

Do you store my results?

The report is kept for 12 months at its shareable link so you can come back to it. Reports are not listed publicly and carry a noindex tag; nothing about your visitors is collected.

All 41 tools →

Free, funded by the people who use it

€0 of €75 this month. At €75, site crawl up to 500 pages + weekly re-check switches on for everyone.

Chip in