Malware & injected code
Scan public HTML for obfuscated scripts, miners, suspicious iframes, and high-risk paths.
Enter a URL. We’ll look for malware signals, outdated software, known CVEs, and common misconfigurations — correlating Wordfence, WPVulnerability, CISA KEV, Retire.js, OSV, and more.
Remote scanners have limited access and results are not guaranteed. Only scan sites you own or are authorized to test.
How it works
Four remote checks run against every public URL you submit.
Scan public HTML for obfuscated scripts, miners, suspicious iframes, and high-risk paths.
Fingerprint WordPress core, plugins, themes, and common JS libraries from the public site.
Match detected versions against Wordfence, WPVulnerability, Retire.js, OSV.dev, and CIRCL.
Flag CISA KEV exploited-in-the-wild CVEs, exposed xmlrpc, and other publicly reachable issues.
Built on trust
Regular remote checks help you catch malware indicators, vulnerable plugins, and configuration mistakes before they hurt SEO, visitors, or brand trust.
Honest limits
We only see what a browser can fetch — HTML, headers, and a few public paths. Server-side backdoors and private files need host-level scanning.