{"id":7283,"date":"2026-08-02T10:50:04","date_gmt":"2026-08-02T10:50:04","guid":{"rendered":"https:\/\/checksitestatus.com\/?p=7283"},"modified":"2026-08-02T10:52:16","modified_gmt":"2026-08-02T10:52:16","slug":"website-security-checker-virus-malware-scanner","status":"publish","type":"post","link":"https:\/\/checksitestatus.com\/fr\/website-security-checker-virus-malware-scanner\/","title":{"rendered":"Website Security Checker \/ Virus \/ Malware Scanner"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"7283\" class=\"elementor elementor-7283\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-44fe255 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"44fe255\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-97707da\" data-id=\"97707da\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f03ad7d elementor-widget elementor-widget-text-editor\" data-id=\"f03ad7d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"3:1-3:266;67-332\">Nobody hacks a site to make it look hacked. That was true twenty years ago, when defacements were the point. It isn&#8217;t true now. A compromised site in 2026 usually looks exactly like it did the day before, because the whole business model depends on nobody noticing.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"5:1-5:306;334-639\">The malware is there to redirect mobile visitors to a scam page while desktop users see nothing wrong. Or to inject spam links that only appear to Googlebot. Or to sit quietly in a checkout page skimming card numbers. In every one of those cases, the owner&#8217;s homepage loads fine and the owner has no idea.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"7:1-7:157;641-797\">That&#8217;s the reason to scan rather than assume. A security checker looks at what your site actually serves to the outside world, not what you think it serves.<br \/><br \/><\/p><h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\" dir=\"ltr\" data-sourcepos=\"9:1-9:58;799-856\"><strong>The gap between &#8220;my site works&#8221; and &#8220;my site is clean&#8221;<\/strong><\/h2><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"11:1-11:85;858-942\">Uptime tells you the server responded. It says nothing about what&#8217;s in the response.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"13:1-13:401;944-1344\">You can watch this in your own logs if you have a compromised site. Traffic looks normal. Response times look normal. Status codes are 200 across the board. Meanwhile, a script in your footer is fingerprinting each visitor and only firing the malicious payload for people arriving from Google on an Android phone. You, the owner, arrive by typing the domain directly on a desktop, so you never see it.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"15:1-15:350;1346-1695\">Modern website malware is built specifically to hide from the person most likely to remove it. Conditional loading based on user agent, referrer, or IP. Payloads that skip anyone who has ever logged into wp-admin. Obfuscated code buried in a legitimate-looking file. Backdoors scattered across a dozen locations so cleaning one accomplishes nothing.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"17:1-17:291;1697-1987\">Sucuri&#8217;s remediation data has consistently found backdoors on around half of the compromised sites their team cleans, and their reports have repeatedly shown that a majority of infected sites carry more than one. Which explains why &#8220;I deleted the weird file&#8221; is rarely the end of the story.<br \/><br \/><\/p><h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\" dir=\"ltr\" data-sourcepos=\"19:1-19:39;1989-2027\"><strong>What a scan is actually looking for<\/strong><\/h2><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"21:1-21:115;2029-2143\">An external scanner requests your pages the way a visitor would and examines what comes back. The common findings:<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"23:1-23:242;2145-2386\"><strong>Malicious JavaScript injections.<\/strong> Usually appended to a legitimate file or dropped into the header and footer of your theme. Often base64 encoded or otherwise obfuscated, which is itself a signal, because normal code doesn&#8217;t need to hide.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"25:1-25:211;2388-2598\"><strong>Hidden redirects.<\/strong> Traffic sent to a different domain based on device, referrer, or geography. Mobile-only redirects are the most common variant because mobile users are less likely to notice or report them.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"27:1-27:363;2600-2962\"><strong>SEO spam.<\/strong> Injected links and pages selling pharmaceuticals, counterfeit goods, gambling, or replica products. Frequently served only to search engine crawlers, so it&#8217;s invisible in your browser and highly visible in your search results. If you&#8217;ve ever seen unfamiliar Japanese or pharmaceutical text in your own site&#8217;s Google listings, this is what happened.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"29:1-29:113;2964-3076\"><strong>Defacement.<\/strong> Rare now, but it still happens, usually from hacktivist groups rather than commercial operators.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"31:1-31:289;3078-3366\"><strong>Blacklist status.<\/strong> Whether Google Safe Browsing or the major anti-virus and domain reputation lists have already flagged your domain. This is the one with immediate business consequences, since a flagged domain triggers a full-page browser warning and shreds your click-through rate.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"33:1-33:186;3368-3553\"><strong>Certificate and header problems.<\/strong> An expired or misconfigured SSL certificate, or missing security headers. Not malware, but both are visible signals of a site nobody is maintaining.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"35:1-35:341;3555-3895\">Reputation checks are also useful in the opposite direction, when you&#8217;re the one deciding whether to trust an unfamiliar shop or download page. That use case is covered in more depth in our guide to <em><strong><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/checksitestatus.com\/website-safety-checker-check-if-the-website-is-secure\/\">checking whether a website is secure before you use it<\/a><\/strong><\/em>.<br \/><br \/><\/p><h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\" dir=\"ltr\" data-sourcepos=\"37:1-37:33;3897-3929\"><strong>What a remote scan cannot see<\/strong><\/h2><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"39:1-39:77;3931-4007\">This part gets glossed over in most articles on the subject, and it matters.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"41:1-41:452;4009-4460\">An external scanner sees what&#8217;s publicly served. It can&#8217;t read your server&#8217;s file system, so a backdoor sitting in a PHP file that never renders to a visitor stays invisible. It can&#8217;t inspect your database, where malicious admin users and injected content often live. It can&#8217;t see anything behind a login. And it can&#8217;t detect malware that&#8217;s currently dormant, or that&#8217;s cloaked well enough to serve clean content to anything that looks like a scanner.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"43:1-43:355;4462-4816\">There&#8217;s also a broader limitation with reputation-based detection: it&#8217;s reactive by design. Norn Labs tested 254 confirmed phishing sites in February 2026 and found Google Safe Browsing had flagged only 41 of them, roughly 16%. Blocklists depend on a URL being reported and confirmed first, so anything new gets a free window before detection catches up.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"45:1-45:376;4818-5193\">None of this makes scanning useless. It makes it the first step rather than the only one. A clean external scan means the obvious stuff isn&#8217;t happening in public. It doesn&#8217;t mean nobody is in your server. If you have real reason to suspect a compromise, a remote scan needs backing up with file integrity monitoring, log review, and a look at your database and user accounts.<br \/><br \/><\/p><h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\" dir=\"ltr\" data-sourcepos=\"47:1-47:47;5195-5241\"><strong>How sites get in trouble in the first place<\/strong><\/h2><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"49:1-49:71;5243-5313\"><strong>Seldom through a dramatic zero-day. The mundane causes dominate:<\/strong><br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"51:1-51:266;5315-5580\">An outdated plugin or theme with a publicly disclosed vulnerability. This is the single largest category on WordPress, and the exploit code is usually published within days of the patch. The window between &#8220;patch released&#8221; and &#8220;you applied it&#8221; is the attack window.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"53:1-53:142;5582-5723\">A weak or reused admin password, found in a credential dump and tried against your login page by a bot that tries thousands of sites an hour.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"55:1-55:96;5725-5820\">An abandoned plugin nobody has updated in three years, still active because it&#8217;s still working.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"57:1-57:109;5822-5930\">A shared hosting account where a neighbouring site got compromised and permissions allowed lateral movement.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"59:1-59:125;5932-6056\">A stolen FTP or hosting credential, often taken by malware on the developer&#8217;s own laptop rather than from the server at all.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"61:1-61:170;6058-6227\">The pattern is unglamorous. Most compromised sites are compromised by automated scanning that found a known hole, not by anyone who had a specific interest in that site.<br \/><br \/><\/p><h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\" dir=\"ltr\" data-sourcepos=\"63:1-63:25;6229-6253\"><strong>The practical routine<\/strong><\/h2><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"65:1-65:20;6255-6274\"><strong>For a site you own:<\/strong><\/p><ol class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-decimal flex flex-col gap-1 pl-8 mb-3 print:block print:space-y-1\" dir=\"ltr\" data-sourcepos=\"67:1-72:94;6276-7012\"><li class=\"font-claude-response-body whitespace-normal break-words pl-2\" data-sourcepos=\"67:1-67:83;6276-6358\">Scan the public pages. Do this monthly at minimum, weekly if you take payments.<\/li><li class=\"font-claude-response-body whitespace-normal break-words pl-2\" data-sourcepos=\"68:1-68:167;6359-6525\">Check your blacklist status specifically. Being flagged is a separate emergency from being infected, and it needs a separate remediation request once you&#8217;re clean.<\/li><li class=\"font-claude-response-body whitespace-normal break-words pl-2\" data-sourcepos=\"69:1-69:173;6526-6698\">Search your own domain on Google with <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">site:yourdomain.com<\/code> and read the results. Injected spam pages show up here long before they show up anywhere you&#8217;d normally look.<\/li><li class=\"font-claude-response-body whitespace-normal break-words pl-2\" data-sourcepos=\"70:1-70:120;6699-6818\">Look at your admin user list. An unfamiliar administrator account is one of the clearest signs of a real compromise.<\/li><li class=\"font-claude-response-body whitespace-normal break-words pl-2\" data-sourcepos=\"71:1-71:100;6819-6918\">Keep everything updated. Boring, and it prevents more incidents than anything else on this list.<\/li><li class=\"font-claude-response-body whitespace-normal break-words pl-2\" data-sourcepos=\"72:1-72:94;6919-7012\">Take backups you have actually tested restoring. An untested backup is a hope, not a plan.<br \/><br \/><\/li><\/ol><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"74:1-74:488;7014-7501\">For a site you&#8217;re just visiting: check the domain&#8217;s reputation before you enter a card number or download anything. HTTPS proves the connection is encrypted, nothing more. Phishing operations run valid certificates as a matter of routine, and the padlock has been useless as a trust signal for years. Running an unfamiliar URL through a <em><strong><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/checksitestatus.com\/free-online-virus-scanner-for-your-website\/\">free online virus scanner<\/a><\/strong><\/em> takes a few seconds and covers the obvious cases.<br \/><br \/><\/p><h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\" dir=\"ltr\" data-sourcepos=\"76:1-76:30;7503-7532\"><strong>If a scan comes back dirty<\/strong><\/h2><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"78:1-78:226;7534-7759\">Don&#8217;t start deleting files immediately. You&#8217;ll lose evidence of how they got in, and if you don&#8217;t close the entry point the malware comes back within days. That reinfection loop is the most common outcome of a rushed cleanup.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"80:1-80:16;7761-7776\"><strong>A better order:<\/strong><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"82:1-82:461;7778-8238\">Take the site offline or into maintenance mode if it&#8217;s actively serving malware to visitors. Then take a full backup of the compromised state, so you can investigate it later. Change every password: hosting, database, FTP, all CMS admin accounts. Look for the entry point in your access logs around the time of the earliest suspicious file. Then clean, restore from a known-good backup if you have one from before the compromise, update everything, and rescan.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"84:1-84:433;8240-8672\">If any of that is beyond what you want to take on, hiring a remediation service is a reasonable call. A botched cleanup that leaves one backdoor in place costs more than doing it properly. The <strong><a class=\"underline underline underline-offset-2 decoration-1 decoration-current\/40 hover:decoration-current focus:decoration-current\" href=\"https:\/\/checksitestatus.com\/top-benefits-of-using-a-website-safety-checker\/\">wider case for running these checks routinely<\/a><\/strong> is mostly that finding an infection in week one is a maintenance task, and finding it in month six is an incident.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fb84eb3 elementor-widget elementor-widget-accordion\" data-id=\"fb84eb3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-2631\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-2631\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How can I tell if a website has a virus?<\/a>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<div id=\"elementor-tab-content-2631\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-2631\"><p>Run it through an external security scanner, which requests the pages and inspects the returned code for malicious scripts, hidden redirects, injected spam, and blacklist flags. Warning signs you can spot yourself include unexpected redirects on mobile, browser security warnings, unfamiliar pages appearing in <code class=\"bg-text-200\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\">site:<\/code> search results, and a sudden drop in search traffic.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-2632\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-2632\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Does HTTPS mean a website is safe?<\/a>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<div id=\"elementor-tab-content-2632\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-2632\"><p>No. HTTPS encrypts the connection between your browser and the server so nobody in between can read it. It says nothing about who runs the server or what they intend. Certificates are free and instant, and phishing sites use them as standard. A padlock is necessary but proves very little on its own.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-2633\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-2633\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Can my website be hacked without me noticing?<\/a>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<div id=\"elementor-tab-content-2633\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-2633\"><p>Yes, and that&#8217;s the normal case. Modern website malware is designed to stay hidden from the site owner, often by not firing for logged-in users or desktop visitors. Sites regularly run infected for weeks. Usually the first real signal is external: a customer complaint, a browser warning, or Google flagging the domain.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-2634\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-2634\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Why did Google flag my site as dangerous?<\/a>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<div id=\"elementor-tab-content-2634\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-2634\"><p>Google Safe Browsing detected malware, deceptive content, or unwanted software on at least one of your pages. It doesn&#8217;t have to be the homepage, and it doesn&#8217;t have to be content you added. Clean the infection first, then request a review through Search Console. Requesting review before the site is clean just resets the clock.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<div id=\"elementor-tab-title-2635\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-2635\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How often should I scan my website for malware?<\/a>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<div id=\"elementor-tab-content-2635\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-2635\"><p>Monthly is a reasonable floor for a small brochure site. Weekly or continuous is more appropriate for anything handling payments or logins, where the cost of a slow discovery is much higher. Always scan immediately after installing new plugins, changing hosts, or noticing anything unusual in traffic or search results.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"How can I tell if a website has a virus?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Run it through an external security scanner, which requests the pages and inspects the returned code for malicious scripts, hidden redirects, injected spam, and blacklist flags. Warning signs you can spot yourself include unexpected redirects on mobile, browser security warnings, unfamiliar pages appearing in <code class=\\\"bg-text-200\\\/5 border border-0.5 border-border-300 text-danger-000 whitespace-pre-wrap rounded-[0.4rem] px-1 py-px text-[0.9rem]\\\">site:<\\\/code> search results, and a sudden drop in search traffic.<\\\/p>\"}},{\"@type\":\"Question\",\"name\":\"Does HTTPS mean a website is safe?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>No. HTTPS encrypts the connection between your browser and the server so nobody in between can read it. It says nothing about who runs the server or what they intend. Certificates are free and instant, and phishing sites use them as standard. A padlock is necessary but proves very little on its own.<\\\/p>\"}},{\"@type\":\"Question\",\"name\":\"Can my website be hacked without me noticing?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Yes, and that&#8217;s the normal case. Modern website malware is designed to stay hidden from the site owner, often by not firing for logged-in users or desktop visitors. Sites regularly run infected for weeks. Usually the first real signal is external: a customer complaint, a browser warning, or Google flagging the domain.<\\\/p>\"}},{\"@type\":\"Question\",\"name\":\"Why did Google flag my site as dangerous?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Google Safe Browsing detected malware, deceptive content, or unwanted software on at least one of your pages. It doesn&#8217;t have to be the homepage, and it doesn&#8217;t have to be content you added. Clean the infection first, then request a review through Search Console. Requesting review before the site is clean just resets the clock.<\\\/p>\"}},{\"@type\":\"Question\",\"name\":\"How often should I scan my website for malware?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Monthly is a reasonable floor for a small brochure site. Weekly or continuous is more appropriate for anything handling payments or logins, where the cost of a slow discovery is much higher. Always scan immediately after installing new plugins, changing hosts, or noticing anything unusual in traffic or search results.<\\\/p>\"}}]}<\/script>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dfbee82 elementor-widget elementor-widget-text-editor\" data-id=\"dfbee82\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h2 class=\"text-text-100 mt-3 -mb-1 text-[1.125rem] font-bold\" dir=\"ltr\" data-sourcepos=\"103:1-103:21;10585-10605\"><strong>The short version<\/strong><\/h2><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"105:1-105:151;10607-10757\">Scanning takes seconds. Cleaning up after a compromise that ran for two months takes days, and the search rankings take longer than that to come back.<br \/><br \/><\/p><p class=\"font-claude-response-body break-words whitespace-normal\" dir=\"ltr\" data-sourcepos=\"107:1-107:134;10759-10892\">Check the site, check the blacklist status, keep things updated, and don&#8217;t rely on your homepage looking fine as evidence that it is.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Nobody hacks a site to make it look hacked. That was true twenty years ago, when defacements were the point. It isn&#8217;t true now. A compromised site in 2026 usually looks exactly like it did the day before, because the whole business model depends on nobody noticing. The malware is there to redirect mobile visitors [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":7284,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[442,441,445,444,443,243,274,250,364,446],"class_list":["post-7283","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-website","tag-check-if-website-is-safe","tag-free-virus-scanner-online","tag-google-safe-browsing-warning","tag-hacked-website-signs","tag-seo-spam-injection","tag-site-safety-check","tag-website-blacklist-check","tag-website-malware-scanner","tag-website-security-checker","tag-wordpress-malware-removal"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/posts\/7283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/comments?post=7283"}],"version-history":[{"count":10,"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/posts\/7283\/revisions"}],"predecessor-version":[{"id":7294,"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/posts\/7283\/revisions\/7294"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/media\/7284"}],"wp:attachment":[{"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/media?parent=7283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/categories?post=7283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checksitestatus.com\/fr\/wp-json\/wp\/v2\/tags?post=7283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}