See all monitors →
Security & integrity

Website blacklist monitoring, and the hacks built to hide from you.

Relvato watches for the outside signs of a hacked site: spam on your pages, spam or redirects only Google and its visitors get, spam in Google Search, and Google's list of unsafe sites that browsers warn about.

Supported sitesNo plugin needed
WordPresssupportedAI-built appssupportedAny websitesupported
Add your URL and this monitor runs from the outside, the way a visitor sees your site.
What it checks
  • ✓Pharmacy, gambling, counterfeit, payday-loan and adult spam on your pages, including hidden text and links
  • ✓Japanese text on a site that isn't in Japanese (the Japanese keyword hack)
  • ✓Spam or a redirect that only Google's crawler gets, or only visitors arriving from Google search (cloaking)
  • ✓Links to other sites that only Google's crawler sees
  • ✓Google's list of unsafe sites (malware, phishing, unwanted software), through Google Web Risk
  • ✓Spam search terms and spam pages in Google Search, when Search Console is connected
Why it matters

Most hacks aren't built to break your site. They're built to earn money from it without you noticing: pharmacy or gambling spam shown only to Google's crawler, or visitors from Google search sent to a scam while the site looks normal when you open it yourself. You find out weeks later, when your pages are replaced in Google's results or Chrome starts showing a red warning. Relvato looks at the site the way Google and its visitors do, every day.

Related guide

Found spam you didn't write, or a redirect you can't reproduce? Our checklist walks you through cleaning a hacked WordPress site and closing the way in.

How it works
  • Every day Relvato loads your homepage and a few pages it links to three ways: as a visitor, as Google's crawler, and as a visitor arriving from a Google search.
  • It compares the three. Spam or a redirect that only Google or its visitors get is cloaking, the way most SEO spam hacks stay hidden from the site's owner.
  • It asks Google's Web Risk service whether those pages are on Google's list of unsafe sites, and, with Search Console connected, looks for spam search terms and pages in Google's results.

Data sourceGoogle Web Risk

Questions, answered
Why can't I see the spam when I open my site?

Because the hack shows it only to Google's crawler, or only to visitors who arrive from a Google search. Opening the site directly gets you the normal page. Relvato asks for each page as all three, so it sees what you don't.

My site legitimately mentions some of these words. Will it keep alerting?

Every finding can be ignored on the run, by page and kind of spam. Ignore "pharmacy terms on /products" once and Relvato keeps watching for everything else, including new kinds of spam on the same page.

Where does the unsafe-sites list come from?

From Google's Web Risk service, the commercial version of the list behind Chrome's and Google Search's warnings. Relvato sends Google only the page addresses. Google's list isn't perfect: some unsafe sites aren't on it, and a safe site can be listed in error.

Does it work on sites that aren't WordPress?

Yes. It only loads your public pages, so it works on any site. The Search Console part needs Search Console connected in the site's settings.

Related monitors
Signs of a hack

Put this monitor on autopilot.

Free forever on one site — every monitor, 100 runs a month. No card, no sales call.