Site Health · Security Watch

Website security check: are there pages on your site that you never published?

An attacker who takes over a site rarely makes a mess of it. Your home page looks the same, your admin panel opens, nothing seems wrong. Meanwhile hundreds of pages go live in the background and Google takes them for yours. Our crawler was already walking your entire site. We made the crawl a few minutes longer, and now it looks for those pages too.

61
checks
10,000
pages per run
4
independent traces
3
possible verdicts

Security Watch

example.com · crawl version 12

Pages crawled

2.940 / 10.000

  • clean/services/consulting
  • clean/blog/customer-experience
  • flagged/wp-content/uploads/2019/x9k2
  • clean/references
  • clean/products/campaign
  • clean/contact

Verdict for this crawl

One page carries several traces, and the same traces show up in your search data. The verdict is Alarm, and the evidence is waiting in your panel.

It starts as a security problem, but SEO pays the bill

Injected pages go live under your own domain. Google crawls them, indexes them and lists them as yours. From that day on, what shapes your visibility in search is no longer the content you wrote but the pages the attacker left behind.

01

Your rankings slide

Google works out what your site is about by reading your pages. Drop hundreds of unrelated pages into that mix and the picture blurs. Service pages you never touched start losing positions.

02

Your crawl budget burns

Google gives every site a limited crawl allowance, and the fake pages eat into it. An article you just published waits days for its turn, and a page you updated keeps showing its old version.

03

A manual action becomes possible

If Google finds the spam first, a security issue or manual action lands in Search Console. In the worst case the site drops out of results entirely. Getting back in means a reconsideration request, and that takes weeks.

04

Visitors turn back at the door

Once the browser starts showing its “this site may harm your computer” warning, visitors never open the page at all. Ad platforms read the same signal, and your campaigns can be suspended.

Timing

Catch it early and your rankings survive

Most companies whose site gets taken over find out months later. The news arrives one of two ways: Google sends a warning, or a customer calls to say there is a strange page on your site. Both arrive too late, because by then the pages are indexed and the rankings have already dropped.

The difference is measured in days. A site that deletes the injected pages before Google takes them seriously carries on as if nothing happened. Leave the same pages up for months and cleanup alone will not fix it: you wait for Google's records to fall away, file removal requests for the deleted URLs, and win back the positions you lost.

How an attack caught early plays out

daily spam impressions

peakcut off

Sample curve, the numbers are illustrative. In your panel the same curve is drawn from your own Search Console data, and it compares the last two weeks to tell you whether the trace is still running.

There is no separate scan to start

The security check runs inside the Website Crawler. As our Chrome and Edge extension walks your pages one by one, it also puts each page through the signature core. That adds a few minutes to the crawl, and in return your whole site gets checked.

  1. 01

    The crawl starts

    The extension begins at the home page, follows internal links and walks your entire site. It goes up to 10,000 pages in a single run.

  2. 02

    Every page goes through the same gate

    The URL, title, text and link anchors of each page pass through the signature core, and the server-side crawl reads the raw HTML on top of that. Because the check runs on our server, you never have to update the extension when a new wave of attacks is defined.

  3. 03

    Four separate traces come together

    One signal is never treated as enough. Traces found on pages, content in a language your site does not use, suspicious outbound links and spam queries leaking into your Search Console data are brought together as the crawl finishes.

  4. 04

    One verdict comes out

    Your panel shows one of three results: Clean, Watch or Alarm. If the result is not clean, a warning banner appears on the site's landing screen and an email goes out to you.

Traces found on pagesA language your site never usesSuspicious outbound linksSpam queries in searchOne verdictClean · Watch · Alarm

Three verdicts, one sentence of criteria

The verdict follows from how many independent kinds of trace point the same way. A single signal never raises an alarm.

Clean
None of the traces we look for matched anything on your site. The scorecard is still drawn, so you can see which groups ran and what each one found.
Watch
There is one kind of trace and its volume is low. It may well be a false alarm. The evidence stays in your panel, and if the trace grows on the next crawl the verdict rises.
Alarm
At least two independent traces point the same way, or a single trace has reached a volume you cannot ignore. The evidence and the steps to take are in your panel.

A warning that cries wolf is not a warning

A security warning has one job, and that is to be right. Nobody takes a warning seriously once it has gone off for nothing, and nobody looks on the day it goes off for real. That is why the core was built to hold back.

  • A weak signal never flags a page on its own, it asks for a second one. That is why a model name in a car article or a time expression in a scheduling article does not count as a finding.
  • If your industry overlaps with the subject of a trace, that group is not treated as evidence. Whatever a client does for a living, the words for it will sit in their page titles. What is standing there is the site itself, not an attack.
  • Foreign-language pages you really did publish are told apart. If a page declares which language it is in, or carries a language prefix in its URL, that is a legitimate translation and not evidence.
  • We measured it: in the calibration round of August 2026 roughly 20,000 pages were crawled and not a single false alarm came out.

The technical part

What the crawl looks at

The table below lists the checks the crawl runs and how many parameters each one carries. The numbers come from the signature core rather than being typed in by hand, so the table grows on its own whenever a new wave of attacks is defined.

CheckHow it worksParameters
Page text signature scanThe URL, title, description, H1, body text and link anchors are matched against signature patterns.27
Writing system analysisThe alphabet mix in the title and body is measured, and writing systems your site never uses are separated out.3
Obfuscated code scanThe raw HTML is searched for base64 decoding calls, packed scripts, character-code arrays and meta redirects that throw the page to another domain.4
Outbound link scanThe domains your pages link out to are weighed together with their authority and with the page the link came from.3
Search query scanThe daily query snapshots in your Search Console data are read, and queries that do not belong to your site are separated out.24
Total61
  • Every signature carries a weight. A strong one flags the page on its own, while a weak one asks for a second hit on the same page. A weak hit that stands alone is not even recorded.
  • Only the server-side crawl reads the raw HTML. The extension never sends HTML, which is why the obfuscated code check runs on the server crawl.
  • Turning a finding into evidence takes context. A weak domain counts for nothing on its own, but it becomes evidence once a flagged page links to it. A trace on the search side can still show that the attack happened long after the pages were cleaned up.
  • Signature version v1. Because the check runs on the server, you never have to update the extension when that version goes up. The next crawl simply runs the new signatures.

Core updates: what we added to the crawl, and when

If something turns up, you will not have to go looking

The verdict is written to your panel the moment the crawl ends. If it is not clean, a warning banner appears on the site's landing screen and an email goes out the same day, telling you what was found and which pages to look at. In the panel, the order to follow is this:

  1. 01Send the evidence list to your hosting company or your developer. The cleanup has to happen at file level. Deleting the spam pages alone is usually not enough, because the back door stays where it is.
  2. 02Change every administrator password: site panel, hosting, FTP and database.
  3. 03Open the Security Issues section in Search Console. After the cleanup, file removal requests for the URLs you deleted.
  4. 04Once the cleanup is done, start a fresh crawl. Keep watching until the verdict comes back Clean.

Let us say up front that this is not an antivirus

We cannot see the files on your server. What we see are the traces the attack leaves in the open: pages that went live, code planted in those pages and records piling up on Google's side. So a Clean verdict does not mean “your site is definitely safe”, it means “none of the traces we look for showed up in this crawl”. Protection at server level comes from your hosting company's tools and from keeping your site software up to date. What we do is tell you early, and telling you early is usually what saves the traffic.

Frequently asked questions

Does the security check cost extra?

No. It is part of the Website Crawler and comes free with your Türk SEM membership. There is no extra plan or add-on to buy.

Do I have to start a separate scan?

No. The security check runs every time you crawl your site. There is no separate button and no separate queue.

How much longer does the crawl take?

A few minutes. The check runs on the text and HTML of a page that has already been fetched, so no second request is made and no extra load lands on your server.

Will it find a malicious file on my server?

No, this is not an antivirus. We cannot see the files on your server. We see the traces the attack leaves in the open: the pages that went live, the code planted in them and the records piling up on Google's side. Cleanup at file level is done by your hosting company or your developer.

The verdict came back Clean. Can I be sure nothing happened?

A Clean verdict means one thing: none of the traces we look for showed up in the pages we crawled or in your search data. It is not a guarantee, because not every attack leaves a trace in the open. That is exactly why we look again on every crawl.

My industry overlaps with the subjects the crawl looks for. Will it keep raising alarms?

No. If your industry overlaps with the subject of a trace, that group is not treated as evidence, and your panel says plainly that it was not counted. The other checks keep running.

If something turns up, do you clean it for me?

Cleanup happens at file level and needs server access, so your hosting company or your developer does it. What we give you is the evidence, the list of affected pages and the order to work through. After the cleanup you start a fresh crawl and confirm that the verdict is back to Clean.

Crawl your site today

Free · Inside the Website Crawler · An email if anything turns up

Start a crawl in the panel