Hacked Website & SEO Spam Checker (casino/pharma injection) avatar

Hacked Website & SEO Spam Checker (casino/pharma injection)

Pricing

from $2.50 / 1,000 site checkeds

Go to Apify Store
Hacked Website & SEO Spam Checker (casino/pharma injection)

Hacked Website & SEO Spam Checker (casino/pharma injection)

Bulk check sites for public signs of an SEO spam hack, the most common WordPress website malware: casino/pharma spam, CSS-hidden links, Japanese keyword hack sitemap URLs, WordPress spam posts, the ndsw loader. Strong vs weak evidence, so casinos or pharmacies are not called hacked. Read-only.

Pricing

from $2.50 / 1,000 site checkeds

Rating

0.0

(0)

Developer

Weio, Inc.

Weio, Inc.

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a day ago

Last modified

Share

Hacked Website & SEO Spam Checker

Check a list of websites for the most common kind of hack: search spam injected into a legitimate site. Attackers add casino, slot, pharma (viagra/cialis) or essay-mill text and links to small-business sites, often hidden from visitors and shown only to Google. The owner rarely notices until rankings drop or Google flags the site.

This actor reads only public pages (homepage, robots.txt, sitemaps and, on WordPress, the public post search). No login, no vulnerability probing, nothing is changed on the site.

What it checks

  • Visible spam phrases on the homepage (online casino, slot gacor, situs slot, free spins, replica watches, "buy viagra online" and more, plus Thai, Chinese, Japanese, Korean and Vietnamese gambling terms)
  • Spam links to casino, slot, betting or pharma sites, and spam doorway subdomains such as slot88.yoursite.com
  • Hidden spam: text placed in display:none, zero-size or off-screen blocks
  • Sitemap injection: casino/pharma/slot or Japanese spam URLs listed in the site's sitemaps (up to 15 sitemap files per site)
  • Spam posts on WordPress: casino or pharma posts the attacker published, found through WordPress's public post search
  • Known malicious loader: the ndsw script injection used to redirect visitors

Two levels, so legitimate sites are not called hacked

Words like casino, poker or viagra are normal on many real businesses: a casino-night rental, a poker run, a pharmacy, a news story. So the actor separates:

  • likely_hacked: true — strong evidence: unmistakable spam vocabulary, spam hidden with CSS, links to several unrelated casino sites, many spam sitemap URLs or several spam posts. Each reason is in issues.
  • suspicious: true — anything worth a human look, with the reasons in warnings (for example "one spam-like phrase on the homepage" or "3 sitemap URLs mention gambling words; usually legitimate"). Every likely-hacked site is also suspicious.

Before release we ran it on real sites, reading them exactly as it does for you (as WeioBot, within robots.txt). Of 66 small-business sites our team had confirmed hacked by hand, 61 could be checked and it marked 59 of those 61 as likely hacked; the other 5 refused automated visitors or their robots.txt asked crawlers to stay away, so they came back as free "not checked" rows. Of 434 random small-business websites it could check, it marked 6 as likely hacked, and on review all 6 really were serving gambling spam. Treat a result as a lead to confirm, not a verdict.

Who uses it

  • Web and SEO agencies screening prospects or monitoring client sites
  • Security and hosting teams triaging lists of customer domains
  • Anyone auditing a portfolio of sites for compromise

Input

{ "websites": ["example.com", "https://www.example.org"], "checkSitemaps": true, "checkWordPress": true, "onlyLikelyHacked": false }

Duplicates (example.com and https://example.com/) are checked and charged once.

Output (one row per site)

fieldmeaning
domain, final_url, status, tls, platformwhere the homepage ended up, whether its certificate is valid, and the site builder (WordPress, Wix, Shopify, Squarespace...) when recognisable
likely_hackedtrue when there is strong evidence; the reasons are in issues
suspicioustrue when anything is worth a look; weaker reasons are in warnings
spam_scorerough count of spam signals (0 = clean)
visible_spam_terms, spam_links, hidden_spam_text, weak_links, comment_spam_linksthe matched evidence (capped)
sitemap_urls_checked, sitemap_spam_count, sitemap_spam_examples, sitemap_weak_examplessitemap evidence
wordpress_spam_posts, wordpress_weak_poststitle and link of matching public posts
parked, redirects_to, checks_skippedparked or for-sale domains, sites that send every visitor elsewhere, and checks a bot wall prevented

Example (a real small-business site): likely_hacked: true, issues: ["spam phrases visible on the homepage: online casinos, free spins", "7 spam link(s) on the homepage"].

Pricing

Pay per checked site. Invalid, unreachable and duplicate sites, sites that answer with an error page or a bot check, and sites whose robots.txt does not allow WeioBot are not charged; with onlyLikelyHacked clean and suspicious-only sites are skipped and not charged.

Limits

A pattern scanner, not a malware scanner: it finds search-spam injection, the most common small-business hack, and will not see server-side backdoors that leave no public trace. A clean result means no public spam signal was found. It identifies itself as WeioBot and follows each site's robots.txt and crawl delay, so a site that blocks crawlers comes back as a free "not checked" row, and some optional checks may be skipped (listed in checks_skipped). Built by Weio, Inc.