More software holes are published every year, and AI makes them faster to find and to exploit. We scan every site, match it to the holes attackers use today and warn the owner first. Free.
19 days after we first saw them, at least 68% of the confirmed sites were still infected. Removing the code is only half the job: Google keeps injected URLs in its results until it crawls them again.
Of the 581 that show a version, 52% already ran WordPress 7.x. An up-to-date core does not help when a plugin has the hole.
| Plugin present on infected site | Sites | Share of 747 |
|---|---|---|
| contact-form-7 | 273 | 37% |
| elementor | 205 | 27% |
| woocommerce | 155 | 21% |
| elementor-pro | 116 | 16% |
| revslider | 95 | 13% |
| js_composer | 74 | 10% |
We never publish which sites are hacked: not companies, not public bodies, not people. Every case goes privately to the site, CERT Polska and the host. What we publish is how many.
The home page twice: with Google’s crawler user-agent plus our name and contact, and as a normal browser. Then the sitemap and two site-search probes. Plain GET requests only: no logins, no exploits, no forms.
No false alarm on 90 sites we know are clean. Each flagged site counts only with a hard signal (hidden spam block, cloaking, a known spam network) or a second source such as Google results. 190 without one are not counted. On search probes only hard evidence counts.
Hosts see the infected sites on their own network, CERTs get the full feed, researchers get aggregated data only. So you can help your customers first. Free for CERTs and non-profits.
Request data accessHackedIndex is my side project, built after hours for a good cause. I want the owner of a hacked site to hear it from someone friendly before their customers see it. HackedIndex watches and warns. It does not clean sites, sell cleanup or take referral fees. Monitoring fees cover the cost of daily scanning, and money never changes what we count or report.