Website Malware and SEO spam Scanner

Free website malware and SEO spam scanner.

86%
Health

php-login.com

149.28.66.11  ·  Scanned 2026-06-04 21:48:24
0 critical 4 warning 5 good 2 of 3 free scans left
StatusOnline
HTTP status code200
Response time9 ms (Fast)
ProtocolHTTP/1.1
HTTPS availableYes
Forces HTTPS (redirects http→https)Yes visiting http:// forwards to https://
DNS & reachability
Resolves to1 IPv4 · 0 IPv6 (single A record — no DNS failover)
IPv6 (AAAA record)No
www vs non-wwwBoth work, same canonical
Routing
RedirectsNone (direct)
Content checks
Fake URL handlingCorrect fake URLs return 404
Parked / for-sale pageNot parked
Connection timing breakdown
DNS lookup1 ms
TCP connect0 ms
TLS handshake7 ms
Server processing1 ms
Content transfer0 ms
SSL / TLS Certificate
Certificate presentYes
Trusted & validYes
IssuerLet's Encrypt
Issued tophp-login.com
Also covers (SAN)my.php-login.com, php-login.com, www.php-login.com
Expires2026-08-12 (68 days)
TLS versionTLSv1.3
CipherTLS_AES_256_GCM_SHA384 Strong
Security Headers (1 ok · 5 weak · 1 missing)
HeaderStateDetail
strict-transport-securityMissingHSTS not set — site is vulnerable to SSL stripping and protocol downgrade attacks
content-security-policyMissingNo Content Security Policy — no structural protection against XSS injection
x-frame-optionsMissingX-Frame-Options not set — site may be vulnerable to clickjacking
x-content-type-optionsMissingX-Content-Type-Options not set — browsers may MIME-sniff and execute malicious content
referrer-policyMissingReferrer-Policy not set — full URLs may leak to third parties via the Referer header
permissions-policyMissingPermissions-Policy not set — no restrictions on browser feature access
x-xss-protectionOptionalNot set — fine, this header is deprecated (CSP is the modern replacement)
cross-origin-opener-policyOptionalNot set — recommended for cross-origin isolation, but optional
cross-origin-resource-policyOptionalNot set — recommended to prevent your resources being embedded cross-origin
cross-origin-embedder-policyOptionalNot set — optional; needed only for full cross-origin isolation
set-cookieGoodAll cookies set HttpOnly, Secure and SameSite
serverInfoConsider hiding or genericizing this header

No malware signatures matched. The scanned HTML, scripts and links are clean.

No SEO spam, cloaking, hidden links or pharma injection detected.

DNS Blacklists (0 of 5 blocking)
Domain Age & Registration
Domain age0.9 years (328 days)
Registered2025-07-11
Expires2026-07-10 (35 days)
RegistrarGoDaddy.com, LLC
WHOIS privacyYes
  • Domain is less than 1 year old — moderate risk
  • Domain expires in 35 days — renewal recommended soon
GDPR riskMedium
Analytics presentYes
Advertising trackersNo
Session-recording / fingerprintingNo
Privacy policy linkNo
Cookie consent bannerNo
Analytics (1)
Plausible
  • Analytics tracking detected but no privacy policy link found
Page HTML size9 KB
Server response time9 ms
Compression (gzip/br)Yes
Minified HTMLNo
Browser caching headersNo (max-age 0s)
Total scripts5
External scripts1
Render-blocking scripts1
Stylesheets5
Images11
  • 1 render-blocking script(s) in <head> — consider async/defer
  • No browser caching headers detected — repeat visitors re-download all assets

No fingerprintable technologies were detected.

External scripts referenced5
Stylesheets referenced7
IP address(es)149.28.66.11
CountryUnknown
Site categoryUncategorized
Neighbour domains on the same host
WebsiteIP address
lgoshpee.com.149.28.66.11

How this tool works?

This tool will scan your website URLs and look for the presence of malware injected on it. It will also look for SPAM seo and other signs of a compromise. We will check multiple blacklists to verify if any of them has the site listed as malicious.

What do we look for?

Spam SEO
Spam Links
Adult content
Gambling and Pharma injection
Iframe injections
Javascript injections
Malicious ads
Fake-AV redirections