Free website malware and SEO spam scanner.
| Header | State | Detail |
|---|---|---|
strict-transport-security | Warning | HSTS max-age is very short (0s). Recommend at least 31536000 (1 year) |
content-security-policy | Missing | No Content Security Policy — no structural protection against XSS injection |
x-frame-options | Missing | X-Frame-Options not set — site may be vulnerable to clickjacking |
x-content-type-options | Missing | X-Content-Type-Options not set — browsers may MIME-sniff and execute malicious content |
referrer-policy | Missing | Referrer-Policy not set — full URLs may leak to third parties via the Referer header |
permissions-policy | Missing | Permissions-Policy not set — no restrictions on browser feature access |
x-xss-protection | Optional | Not set — fine, this header is deprecated (CSP is the modern replacement) |
cross-origin-opener-policy | Optional | Not set — recommended for cross-origin isolation, but optional |
cross-origin-resource-policy | Optional | Not set — recommended to prevent your resources being embedded cross-origin |
cross-origin-embedder-policy | Optional | Not set — optional; needed only for full cross-origin isolation |
set-cookie | Optional | No cookies set in the response (nothing to harden) |
server | Info | Consider hiding or genericizing this header |
No malware signatures matched. The scanned HTML, scripts and links are clean.
No SEO spam, cloaking, hidden links or pharma injection detected.
| Service | Status | Resolved |
|---|---|---|
| Clean | NOERROR | |
| Clean | NOERROR | |
| Clean | NOERROR | |
| Clean | NOERROR | |
| Clean | NOERROR |
No fingerprintable technologies were detected.
This tool will scan your website URLs and look for the presence of malware injected on it. It will also look for SPAM seo and other signs of a compromise. We will check multiple blacklists to verify if any of them has the site listed as malicious.
What do we look for?
Spam SEO
Spam Links
Adult content
Gambling and Pharma injection
Iframe injections
Javascript injections
Malicious ads
Fake-AV redirections