Available for projects & agency overflow · Quick reply, from the person who does the work

How to check if your site is compromised, without paid tools

Before paying for an audit, four free checks already give a fairly clear picture, provided you know what each one actually confirms and what it can't see.

Describe my issue Send a message

Four free checks

  1. Check the Google Safe Browsing transparency report

    At transparencyreport.google.com/safe-browsing/search, no account needed, this confirms whether Chrome, Firefox or Edge are currently warning your visitors. It only reflects what Google has already detected: a very recent infection might not show up yet.

  2. Open the Security Issues section of Search Console

    This free, official Google tool explicitly flags any hacked or deceptive content it has detected, along with the type of issue found. It's also where you submit a review request once the cleanup is complete.

  3. Run a Sucuri SiteCheck scan

    The free Sucuri SiteCheck scanner, no account required for a basic scan, checks for known malware, blacklist status across several databases including Google Safe Browsing, and indicators of suspicious modification visible from the outside.

  4. Submit the address to VirusTotal

    The free VirusTotal service analyses the URL with dozens of antivirus engines and reputation databases at once. Useful as a cross-check if the previous three don't agree.

What these tools can't see

These four checks share one thing: they look at the site from the outside, the way a visitor's browser would. An infection that only triggers under specific conditions, say a certain referrer or once per visitor, may show nothing at all at the exact moment of the scan.

On PrestaShop, none of these external scanners can see inside the override/ folder either, the mechanism that legitimately lets a class or controller be extended without touching the original file. Malicious code placed there blends in with what's expected to be custom code: no public scanner can tell the difference from outside.

A clean result across all four checks lowers the risk that a visitor currently sees a redirect or a warning, but it doesn't confirm the absence of an admin account added by a third party, nor the absence of code injected directly into the database.

If the doubt remains

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

constat
plateforme
depuis-quand (facultatif)
sauvegarde
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

Is a Sucuri SiteCheck scan enough to confirm my site is clean?
No. It confirms the absence of known malware signatures and visible blacklisting from the outside, but it doesn't replace inspecting the server files and database for a recent or well-hidden infection.
What if Search Console flags a security issue?
Read exactly what type of issue is listed, fix the underlying cause, then submit a review request through Search Console once the cleanup is complete and verified.
My site isn't on any blacklist, does that mean it's clean?
Not necessarily. A recent infection, or a backdoor that hasn't yet been used to inject visible content, can trigger none of these external checks while still being present.
Should I create a Google Search Console account if I don't have one?
Yes, it's free, and it's the only way to get the exact detail of a security issue Google has detected, as well as to submit a review request after cleanup.
Can VirusTotal scan a file rather than a URL?
Yes, VirusTotal also accepts file submissions, which can be useful for checking a suspicious downloaded file alongside the analysis of the site's URL.