Guide

Your website is redirecting visitors to spam. Here's where the redirect is hiding.

by Ken Armitt, Founder · updated 30 July 2026

A hacked-site redirect is usually injected in one of four places: your .htaccess or server config, a JavaScript injection in theme files or the database, a rogue plugin/extension, or a modified index file. It commonly targets only mobile users or search-engine visitors — which is why the site looks fine to you while your customers get scam pages.

Do this now

  1. Test like a victim: phone, 4G, tap a Google result for your site — not a typed URL
  2. Check .htaccess and index files first; then database and theme JS
  3. Cleaning without closing the entry point = redirect returns in days

Why you can't reproduce it

Modern redirect malware is conditional: it fires for visitors arriving from Google, on mobile user agents, once per IP per day — and never for logged-in admins or direct visits. Your customers and your rankings suffer while everything looks normal from your chair. To reproduce it, open an incognito browser on your phone over mobile data and tap your site's Google listing.

The four hiding places

  1. .htaccess / server config. Rewrite rules matching search-engine referrers or mobile agents, redirecting to the attacker's domain. Check every .htaccess in the tree, not just the root.
  2. Injected JavaScript. Obfuscated JS in theme headers/footers or bundled files — often eval/atob chains loading a remote script that decides who to redirect.
  3. The database. On WordPress: rogue code in widgets, options rows or plugin settings that print into every page.
  4. Rogue or trojaned plugins. Installed by the attacker or "nulled" premium plugins that shipped with the backdoor included.

Removing it properly

Finding a redirect is easy; the reinfection cycle happens because the backdoor that installed it survives the cleanup. A proper job is: forensic copy → find every injection and the access method → close the entry point → verify from real search traffic on mobile. That last step matters: "it works from my desktop" has fooled a lot of site owners into declaring victory early.

When you want it handled

A senior engineer responds within the hour, 24×7, at a fixed published price — and you get the evidence pack at the end.

Start my rescue Free scan first
Call now — 24/7+1 469 489 7950