How to check if your site is compromised, without paid tools
Before paying for an audit, four free checks already give a fairly clear picture, provided you know what each one actually confirms and what it can't see.
Four free checks
-
Check the Google Safe Browsing transparency report
At transparencyreport.google.com/safe-browsing/search, no account needed, this confirms whether Chrome, Firefox or Edge are currently warning your visitors. It only reflects what Google has already detected: a very recent infection might not show up yet.
-
Open the Security Issues section of Search Console
This free, official Google tool explicitly flags any hacked or deceptive content it has detected, along with the type of issue found. It's also where you submit a review request once the cleanup is complete.
-
Run a Sucuri SiteCheck scan
The free Sucuri SiteCheck scanner, no account required for a basic scan, checks for known malware, blacklist status across several databases including Google Safe Browsing, and indicators of suspicious modification visible from the outside.
-
Submit the address to VirusTotal
The free VirusTotal service analyses the URL with dozens of antivirus engines and reputation databases at once. Useful as a cross-check if the previous three don't agree.
What these tools can't see
These four checks share one thing: they look at the site from the outside, the way a visitor's browser would. An infection that only triggers under specific conditions, say a certain referrer or once per visitor, may show nothing at all at the exact moment of the scan.
On PrestaShop, none of these external scanners can see inside the override/ folder either, the mechanism that legitimately lets a class or controller be extended without touching the original file. Malicious code placed there blends in with what's expected to be custom code: no public scanner can tell the difference from outside.
A clean result across all four checks lowers the risk that a visitor currently sees a redirect or a warning, but it doesn't confirm the absence of an admin account added by a third party, nor the absence of code injected directly into the database.
If the doubt remains
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.