Why you might not notice.
WHAT ATTACKERS DO TO AVOID DETECTION
Show the compromise only to search visitors Exclude logged-in users Show it only on certain devices Activate only at certain times Hide files in unexpected locations
WHY
An unnoticed compromise lasts longer and is worth more.
WHAT THIS MEANS
Your site looking fine to you proves nothing.
HOW TO CHECK PROPERLY
Load it logged out, in a private window From a different network On a phone Check how it appears in search results
THE SEARCH APPEARANCE CHECK
Search for your site and look at the description shown.
Injected content frequently appears there before anywhere else.
WHERE FILES HIDE
Upload directories Directories with legitimate-looking names Inside theme and plugin folders Above public_html
WHAT ELSE TO CHECK
Cron jobs, which attackers use to reinstate themselves Database entries, for injected content
WHAT THIS MEANS FOR CLEANUP
Finding one file is not finishing.