# How to Check a Site for Public Compromise Signals

Canonical: https://vulnify.app/blog/how-to-check-site-compromise-signals

Check Safe Browsing, redirects, hidden frames, and miner hosts with Vulnify. A missing Safe Browsing key is a failed check, not a clean result.

A compromised site often looks normal to the person who owns it. Visitors get a warning page, a hidden frame, or a redirect to a host they did not type. Vulnify&rsquo;s Site Compromise Checker looks for those public signals. It does not clean malware, and it does not install a firewall. What to do after you already know an account or a repository was exposed is a different article: the post-incident checklist . Start here when you are not sure the public site is still yours. Run the free check Enter the public URL. Quick does not need an account. The check covers Safe Browsing, the host a redirect lands on, the page title, hidden frames, a meta refresh, and known miner hosts. Safe Browsing fails closed. If the Safe Browsing key is missing, that check fails. It is not a clean result. Do not tell a customer the site is fine because the rest of the card looked quiet while Safe Browsing did not run. A hit means a public signal matched. It does not name the file to delete, and it does not prove how the change got there. Take the signal to someone who can inspect the host. Then run the check again after the change is gone. Watch the same signals daily The monitor is $9 a month, or $90 a year, at the compromise watch page . It repeats the external check and emails on change. A text-hash comparison is a toggle, and it ships off. Turn it on only if you want an alert when the visible text changes. Homepages that rotate banners will be noisy. Read each signal as itself A Safe Browsing hit means Google&rsquo;s list flagged the URL or a resource on it. A redirect hit means the final host was not the host you typed. A hidden frame or a meta refresh is a page that sends the browser somewhere else without a normal link. A miner host is a script name the check already knows. The title check is there because defacements change the title and leave the layout. None of these tell you which plugin was outdated. They tell you the public page is not what you published. Run Quick on the public homepage first. If the application has a second host, such as a checkout subdomain, run that URL too. One clean homepage does not clear the other name. Comprehensive, after sign-in, is the same checker in the signed-in mode. It is still not a malware removal tool. If Safe Browsing failed because the key was missing, say that out loud in the ticket. &ldquo;Safe Browsing did not run&rdquo; is a different sentence from &ldquo;Safe Browsing says the site is fine.&rdquo; The product treats a missing key as a failed check on purpose. The $79 snapshot A snapshot is a one-time $79 order. While the status is paid, the page shows Start snapshot and Refund. After you start it, the signals come from the same external check plus a Standard website scan. That combination is not a cleanup report. It will not remove code, rotate passwords, or certify the incident. Refund is for the paid order you have not started. After start, read the signals and the Standard scan, then use the post-incident checklist for credentials and code. What to do with a hit, and what not to do Write down the signal, the URL, and the time. Take a copy of the HTML if you can still load it. Do not &ldquo;fix&rdquo; it by deleting random plugins before you know which signal fired. A miner host and a Safe Browsing hit suggest script you did not place. A title change suggests a defacement. A redirect to a new host suggests the page or the DNS was changed. Those are different afternoons. The $9 monitor is for the next week, so a cleaned site that gets the same injection again does not wait for a customer complaint. Leave the text-hash toggle off unless the page text is stable. The $79 snapshot is for a moment when you want the external signals and a Standard scan in one paid order. Start snapshot only when you are ready to spend that order. Refund is on the screen while the status is paid and you have not started. After start, the result is signals plus a Standard scan. It is not a cleanup report, and it is not the post-incident checklist. Use that checklist when credentials or code may already be exposed. Frequently asked questions Does this remove malware? No. The checker, the $9 monitor, and the $79 snapshot report public signals. None of them clean the site or install a firewall. What does a missing Safe Browsing key mean? That check failed. A missing key is not a clean result. Do not treat the rest of the card as a pass for Safe Browsing. What is the difference between the $9 monitor and the $79 snapshot? The monitor repeats the external check on a schedule. The snapshot is a one-time paid order. After you start it, you get those external signals plus a Standard scan, not a cleanup report.
