← All articles

How to Tell If Your Website Has Malware

April 1, 2026 · 3 min read · by the upkept/dev team

You can usually tell if your website has malware from a mix of warning signs and a free scan. The signs include unexpected redirects, spam pop-ups, a browser or search warning that your site may be harmful, unfamiliar new files or admin users, and a sudden drop in traffic. The fastest confirmation is a free online malware scanner. Here is how to check properly, what the results actually mean, and what to do if something turns up.

The warning signs

Malware often gives itself away before any scan. Watch for:

  1. Redirects. Visitors, or you, get sent to a different site, often spammy, especially from search results or on mobile.
  2. Content you did not add. Strange pop-ups, ads, or pages selling things you do not sell.
  3. A browser or Google warning. A red "this site may be harmful" screen is the clearest sign, and the most damaging, because visitors see it too.
  4. Unfamiliar users or files. New admin accounts you did not create, or recently modified files you cannot explain.
  5. A traffic collapse. Search engines drop flagged sites, so a sudden fall in visitors can mean an infection they spotted before you did.

Any one of these is worth investigating. Several together is close to a confirmation.

How do I actually scan for it?

Use more than one method, because no single check catches everything.

  • A free online scanner. Enter your address and it checks your public pages for known malware and blacklisting. Fast, and a good first pass, though it only sees what is public.
  • Google Search Console. If your site is verified there, its security section reports detected issues directly from Google. This is authoritative, because it is what Google shows searchers.
  • A server-side scan. Online scanners only see the surface. A scan that runs on the actual files finds injected code the public pages hide. This is where a maintenance provider or a security plugin earns its keep.

A clean result from a surface scanner is reassuring but not final. A server-side scan is what confirms the files themselves are clean.

What the results mean, and what to do

If scans come back clean and you have no symptoms, you are probably fine. Keep your software updated so it stays that way, since outdated plugins are how most infections get in.

If something is found, do not start deleting files at random. That can break the site and destroy the evidence of how they got in. Instead, work the problem in order: contain the site, reset access, identify the damage, then clean and patch. The first hour after a hack walks through exactly that sequence. If the scan keeps finding reinfections after you clean, there is a backdoor you have missed, and that is the point to get help.

Prevent the next one

Most infections are preventable with the basics: current software, strong unique passwords, removed unused plugins, and tested backups. Building those into a regular routine is far cheaper than a cleanup.

What to do next

Run your site through a free scanner now, and if it is verified in Search Console, check the security section there too. If either flags something, or you have the symptoms above, treat it as active and follow the hack response steps. A clean scan is a good moment to shore up backups and updates so you stay that way.

Part of our guide to website problems.

Not sure what is actually wrong with your site?

Our $250 site health audit checks performance, security, broken forms, and outdated dependencies. You get a written report and a prioritised fix list, credited toward your first month if you start maintenance within 30 days.

Book the $250 site health audit