Website Security7 min read3 October 2026

How to Check If Your Website Has Malware: A Guide for UK Business Owners

Your website can be infected with malware without you seeing any visible changes. Here's how to check, what the warning signs are, and what to do if you find something.

By Yrzo AI — UK cybersecurity specialists

You Probably Won't Notice It Yourself

The uncomfortable reality about website malware is that it is usually designed to be invisible to the site owner. Attackers do not want you to know your site is compromised — a site you clean and secure is no longer useful to them. So the malware operates quietly: injecting hidden links into your page source that you cannot see in a browser, redirecting mobile visitors to spam sites while showing desktop visitors your normal content, harvesting data from contact forms and sending it somewhere else, or running cryptocurrency mining scripts in the background.

You might never see any of this. The first sign is often external: Google adds a malware warning to your search listing, your web host suspends your account for suspicious activity, or a customer tells you their antivirus fired when they visited your site. By then the infection has often been present for weeks or months.

This guide covers how to check your site proactively, before that happens.

Step 1: Google Safe Browsing Transparency Report

Start here — it is free, takes 30 seconds, and covers the most common detection:

Go to **transparencyreport.google.com/safe-browsing/search** and enter your domain.

Google's Safe Browsing database is updated continuously with sites detected as serving malware, phishing content, or unwanted software. If your site appears in the database, Google Search will show a warning to users attempting to visit it, and Chrome, Firefox, and Safari will display interstitial warning pages.

If the report shows no issues, that is a good sign but not a clean bill of health — Safe Browsing detects what Google has crawled and analysed, not everything that might be on your site.

Step 2: Google Search Console Security Issues Report

If you have Google Search Console set up for your site (and you should — it is free and provides valuable SEO data as well), check the Security Issues report:

In Search Console: **Security & Manual Actions → Security Issues**

Search Console will report malware, hacked content, social engineering (phishing), and harmful downloads detected on your site. It is more detailed than the Safe Browsing transparency report and will identify specific affected URLs rather than just flagging the domain.

If you do not have Search Console set up, the setup process involves adding a DNS record or uploading a verification file — your web developer or host can do this, or Google's documentation walks through it step by step.

Step 3: Free External Scanners

Several free tools scan the public-facing content of your site for malware signatures, malicious JavaScript, and known attack patterns:

**Sucuri SiteCheck (sitecheck.sucuri.net)** — checks your site against Sucuri's malware databases, scans for injected scripts, checks for known PHP backdoor signatures in visible page content, and verifies your status in Google Safe Browsing and other blacklists. Free to use.

**VirusTotal (virustotal.com)** — enter your domain and VirusTotal checks it against over 70 antivirus and URL scanning engines simultaneously. If multiple engines flag your domain, that is a strong signal of active malware.

**URLVoid (urlvoid.com)** — similar to VirusTotal, aggregates blacklist and reputation database checks.

**Important limitation**: external scanners can only see what a web crawler sees — the HTML and JavaScript your server sends to visitors. Malware that is injected server-side, that targets only logged-in users, that activates only on mobile devices, or that requires specific conditions to trigger will not be detected by external scans. They are a useful first check, not a comprehensive assessment.

Step 4: Check Your Own Page Source

For WordPress sites specifically, some common malware types are detectable with a basic source code check:

In Chrome or Firefox, visit your homepage, right-click anywhere, and select "View Page Source." Use Ctrl+F (or Cmd+F on Mac) to search for:

- `eval(base64_decode` — a common pattern in PHP malware that obfuscates malicious code - `document.write` followed by a URL — often used to inject hidden iframes or redirects - Unfamiliar `<script src="...">` tags pointing to domains you do not recognise - Hidden links in `<div style="display:none">` or `<a style="visibility:hidden">` tags — used for SEO spam injection

You will not catch everything this way, and you need to know what your legitimate scripts look like to identify the unfamiliar ones. But it takes five minutes and sometimes finds obvious injections immediately.

Step 5: Check Your WordPress Admin for Unauthorised Changes

If your site runs on WordPress, log into wp-admin and check:

**Users** — are there admin accounts you do not recognise? Attackers often create backdoor admin accounts after gaining access.

**Plugins** — are there plugins installed that you did not install? Or familiar plugins with recent unexpected updates?

**Files via Theme/Plugin Editor** — look at your active theme's functions.php file (Appearance → Theme File Editor → functions.php). Malicious code is often appended to this file. Legitimate functions.php files should not contain base64-encoded strings or eval() calls.

**Recently Modified Files** — via your hosting file manager or FTP, sort files by modification date. Files modified recently that you did not intentionally change are a strong indicator of compromise.

What to Do If You Find Malware

**Do not just delete the obvious infected files.** Attackers plant multiple backdoors. If you remove the visible malware without finding and closing the entry point, the site will be reinfected within hours.

**Take a backup before cleaning** — even of the infected site. You may need to refer to it during the forensic process.

**Identify the entry point** — review server access logs for the period before the first signs of infection. Look for unusual POST requests to PHP files, access to wp-admin from unusual IP addresses, or requests to known vulnerable plugin paths.

**Clean methodically**: replace WordPress core files from a fresh download, replace plugins and themes from their original sources (not from the infected copies), manually review and clean functions.php and any modified files, remove unauthorised admin accounts, change all passwords (WordPress admin, hosting panel, FTP, database).

**Request Google reconsideration** — once your site is clean, use Search Console to request a review and removal of any Safe Browsing warnings. This can take a few days.

**Consider professional help** — Sucuri, Wordfence, and several UK-based security firms offer malware removal services for websites. For a site holding customer data or taking payments, professional removal and a post-clean audit is worth the cost.

Yrzo AI's automated security scan checks your site for the vulnerabilities most commonly exploited to plant malware — authentication weaknesses, file upload flaws, injection points, and exposed admin paths — before an infection happens. From £99 at yrzoai.dev.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →