Free · No sign-up · Read-only

Is your website safe for the people who visit it?

Most small businesses find out their site has been tampered with when a customer tells them, or when Google puts a red warning screen in front of it. Type your address below and find out in about a minute.

Free, and no sign-up. We read the pages your site already shows every visitor — the same thing Google does. We never log in, never change anything, and don't ask for access to your website or your hosting.

What this check does

  • Read the pages your website already shows to everyone
  • Look for hidden or disguised code running on your visitors
  • Check you against public malware and blacklist databases
  • Compare what you show a browser with what you show Google
  • Tell you plainly what we found, and what it means

What it never does

  • Ask for a password, a login, or access to your hosting
  • Change, add, or delete anything on your website
  • Require an account, an email address, or a credit card
  • Try doors that are not already open to the public
  • Sell or share your details with anyone
What we actually look at

Five checks, explained in full.

No black box. Here is every check we run and why it matters.

Hidden code injected into your pages

The most common way a small-business site is abused: scrambled code added to every page, which runs in the browser of everyone who visits. We look for the patterns these loaders use, and check whether it appears site-wide.

Public malware and blacklist listings

We check your domain against Sucuri SiteCheck, a public reputation service. Being listed is what causes browsers to show a red warning screen to your customers before they ever reach you.

Content shown only to search engines

We fetch your homepage as a normal browser, as Googlebot, and as a phone, and compare them. Hacked sites routinely look fine to their owner while showing spam to Google.

Spam text and invisible frames

Pharmacy, gambling and counterfeit-goods text injected into your pages, and content loaded invisibly into them. Common analytics tools are excluded so you are not told off for having Google Analytics.

Browser protections and software on show

Which standard security settings your site sends to visitors, and which add-on versions your pages publish. Both are configuration, not break-ins — we say so rather than dressing them up.

This will not tell you whether a link is safe to click

It is worth being blunt about this one. This check finds real websites that have been broken into — someone else's code added to a site that is otherwise legitimate. That is the common case, and it is what it is good at.

A brand-new fake page, built from scratch to trick people, is a different thing. It has no injected code to find and has not been reported to anyone yet, so it will come back clean here. A clean result on a page you were sent out of the blue means very little.

For those, the rule does not change: never paste a command into Terminal, and never press Windows key + R, because a web page told you to. No legitimate website ever asks you to do that — it is the single most common way computers get taken over right now.

What else this check cannot see

This is an outside-only look. It sees what any visitor sees, and no more. A clean result here is genuinely good news, but it is not proof that nothing is wrong. It cannot see:

  • Backdoors or modified files sitting on the web server
  • Anything inside the database, including injected admin accounts
  • Server, hosting, and access-log activity
  • Anything behind a login, a firewall, or a paywall
  • Whether any data has actually been taken

A definitive answer needs access to the web server, its files and its logs — which is a different job, and one you should only ever hand to someone you have chosen deliberately.

Who is behind this

Staxly is a small US company that looks after cloud and website security for small businesses that don't have anyone in-house to do it. We built this checker because the sites that get hit are almost never the ones with a security budget — they are the ones whose web person moved on and never got replaced.

The check is free and there is nothing attached to it. If your result is worrying and you would rather talk to a person than read a report, you can — but nobody will chase you.