# How to check if your site is compromised, without paid tools

> Before paying for an audit, four free checks already give a fairly clear picture, provided you know what each one actually confirms and what it can't see.

- Source canonique : [https://allaux.fr/en/securite/verifier-si-mon-site-est-compromis](https://allaux.fr/en/securite/verifier-si-mon-site-est-compromis)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> The Google Safe Browsing transparency report, the Security Issues section of Search Console, a Sucuri SiteCheck scan and a VirusTotal submission all give a free, no-account first diagnosis. None of the four replaces an inspection of the files and database for a well-hidden infection.

## Four free checks

1. **Check the Google Safe Browsing transparency report** — At transparencyreport.google.com/safe-browsing/search, no account needed, this confirms whether Chrome, Firefox or Edge are currently warning your visitors. It only reflects what Google has already detected: a very recent infection might not show up yet.
2. **Open the Security Issues section of Search Console** — This free, official Google tool explicitly flags any hacked or deceptive content it has detected, along with the type of issue found. It's also where you submit a review request once the cleanup is complete.
3. **Run a Sucuri SiteCheck scan** — The free Sucuri SiteCheck scanner, no account required for a basic scan, checks for known malware, blacklist status across several databases including Google Safe Browsing, and indicators of suspicious modification visible from the outside.
4. **Submit the address to VirusTotal** — The free VirusTotal service analyses the URL with dozens of antivirus engines and reputation databases at once. Useful as a cross-check if the previous three don't agree.

## What these tools can't see

These four checks share one thing: they look at the site from the outside, the way a visitor's browser would. An infection that only triggers under specific conditions, say a certain referrer or once per visitor, may show nothing at all at the exact moment of the scan.

On PrestaShop, none of these external scanners can see inside the override/ folder either, the mechanism that legitimately lets a class or controller be extended without touching the original file. Malicious code placed there blends in with what's expected to be custom code: no public scanner can tell the difference from outside.

A clean result across all four checks lowers the risk that a visitor currently sees a redirect or a warning, but it doesn't confirm the absence of an admin account added by a third party, nor the absence of code injected directly into the database.

## A clean result isn't a green light

> If the host has flagged suspicious activity, if an unfamiliar admin account exists, or if suspicious orders or emails are visible, an external scan coming back "clean" changes nothing: these are internal signs that need to be dealt with on their own, and they matter more than a public scanner's result.

## If the doubt remains

- **Compromise confirmed or strongly suspected** — The exact order of first actions for the following two hours. ([/securite/que-faire-dans-les-deux-heures](/securite/que-faire-dans-les-deux-heures))
- **Move on to cleanup** — The method, and why restoring a backup isn't always enough. ([/securite/nettoyer-un-site-infecte](/securite/nettoyer-un-site-infecte))
- **Track published vulnerabilities** — Where to watch for issues affecting your CMS, theme and extensions. ([/securite/surveiller-les-failles-qui-concernent-ma-boutique](/securite/surveiller-les-failles-qui-concernent-ma-boutique))

## FAQ

### Is a Sucuri SiteCheck scan enough to confirm my site is clean?

No. It confirms the absence of known malware signatures and visible blacklisting from the outside, but it doesn't replace inspecting the server files and database for a recent or well-hidden infection.

### What if Search Console flags a security issue?

Read exactly what type of issue is listed, fix the underlying cause, then submit a review request through Search Console once the cleanup is complete and verified.

### My site isn't on any blacklist, does that mean it's clean?

Not necessarily. A recent infection, or a backdoor that hasn't yet been used to inject visible content, can trigger none of these external checks while still being present.

### Should I create a Google Search Console account if I don't have one?

Yes, it's free, and it's the only way to get the exact detail of a security issue Google has detected, as well as to submit a review request after cleanup.

### Can VirusTotal scan a file rather than a URL?

Yes, VirusTotal also accepts file submissions, which can be useful for checking a suspicious downloaded file alongside the analysis of the site's URL.
