FREE
Day 0 · our scan finds a break-in
FromHackedIndex <[notice address]>
To[contact listed on the site]
RefHI-7Q4K-2M9P
example.com is showing casino spam to Google
Hello,
Our scanner found pages on example.com that you most likely didn't write: [n] casino and betting pages listed in your sitemap, and a block of links on the home page that only Google sees.
These pages were almost certainly added by someone else. Visitors don't see them, which is why they often stay for months. If you added them on purpose, reply and we will close the case.
Confirm it without clicking anything in this email: search Google for site:example.com casino, or open example.com/sitemap.xml yourself.
No links in this email. For the evidence and a step-by-step fix, type hackedindex.com into your browser and enter this code.HI-7Q4K-2M9P
This notice and the report are free. We will never ask you for a password, a payment or a plugin install.
One notice per case, re-check in 7 days. To stop scanning: TXT record hackedindex-optout. Sent by Mateusz Haber, HackedIndex, [address]. We found this address on example.com/[page] and use it only to tell you about this security problem (GDPR Art. 6(1)(f), network security). Reply STOP and we never write to this address again. Privacy notice: hackedindex.com/privacy
FREE
Day 7 · still infected on re-check
FromHackedIndex <[notice address]>
To[same contact]
RefHI-7Q4K-2M9P
Still infected: example.com. The re-check is free.
A week ago we told you about spam on example.com. Today's re-check still finds it: [n] spam pages, [n] of them visible in Google search.
Cleaned it already? Ask for a re-check and we close the case the moment it comes back clean.
Cleaning Google takes longer than cleaning the site, so spam can stay in search results for weeks after the fix.
Still no links. To re-check, type hackedindex.com into your browser and enter the same code.HI-7Q4K-2M9P
Fixing it yourself? The private report includes a free cleanup guide: the injected code, the backdoor, then Google.
Last reminder. After this we write only if something changes. Sent by Mateusz Haber, HackedIndex, [address]. We found this address on example.com/[page] and use it only to tell you about this security problem (GDPR Art. 6(1)(f), network security). Reply STOP and we never write to this address again. Privacy notice: hackedindex.com/privacy
OPT-IN ONLY · FIRST OFFER
Clean, to an owner who asked for offers
FromHackedIndex <[notice address]>
To[verified owner]
example.com is clean. Google isn't yet.
Good news: our re-check finds no spam on example.com. The case is closed and the site is off our count of infected sites.
Google still shows [n] of the spam pages. They drop out as Google re-crawls, which can take weeks. We'll look once more in 30 days, free.
Want us to watch every day instead? Monitoring scans daily, tells you within 24 h if anything comes back, and follows Google until the last spam page is gone.
Public institution or non-profit? Monitoring is free for you for as long as HackedIndex runs.
How to get it
You get offers because you ticked “send me offers” when you verified example.com. Reply STOP to turn them off. Do nothing and you won't hear from us about this case again.
FREE
Any day · likely affected (version-based)
FromHackedIndex <[notice address]>
To[contact listed on the site]
RefHI-3LX8-5T2C
Urgent: the WordPress hole attackers are using now may affect example.com
On 25.09.2026 CISA added CVE-2026-87902 to its list of vulnerabilities attackers are actively using. It lets anyone run code on a WordPress site without logging in.
example.com shows WordPress [version] publicly, which is in the affected range. Judging by the version alone, it is likely affected.
Today: update WordPress to [fixed version] or newer. Then check for free that nobody got in first.
No links in this email. For the free check, type hackedindex.com into your browser and enter this code.HI-3LX8-5T2C
We send this only for holes attackers are using right now, once per hole. It's free and there is nothing to buy.
Based on the version your site shows publicly. Some hosts patch without changing it. If yours did, ignore this. Sent by Mateusz Haber, HackedIndex, [address]. We found this address on example.com/[page] and use it only to tell you about this security problem (GDPR Art. 6(1)(f), network security). Reply STOP and we never write to this address again. Privacy notice: hackedindex.com/privacy
PAID · MONITORING
Daily match finds a new hole · email or Slack
HackedIndex alert · shop.example.com
New vulnerability in a module your shop runs
ModuleAdvanced Popup Creator
ProblemSQL injection · CVE-2025-69633
Your version[version]
Fixed in[version]
SourceFriends of Presta advisory
What to do: update the module, or switch it off until you can. We check again tomorrow and tell you when it's closed.
You get this because shop.example.com is on Monitoring. Alerts go to [email] and [Slack channel].
FREE · NON-PROFIT
Status verified
FromHackedIndex <[notice address]>
To[verified owner]
Monitoring for [organisation] is free for as long as HackedIndex runs
We've verified [organisation] (KRS [number]) and example.org. Everything in Monitoring is now on at no cost: daily scans, vulnerability alerts and Google tracking.
No card and no trial. Once a year we'll ask you to confirm your status. Nothing else.
Alerts go to [email]. You can add a colleague or a Slack channel in settings.
Know a school, parish or foundation that could use this? Forward this email.