Cloaking & SEO Poison Scanner
Complete guide to detecting cloaking, blackhat SEO techniques, malware-laced redirections, and suspicious code patterns.
What is Cloaking & SEO Poisoning?
Cloaking is a blackhat SEO technique where a website shows different content to search engine crawlers (like Googlebot) than it shows to regular users. This violates Google's Webmaster Guidelines and can result in severe penalties, including complete deindexing from search results.
SEO Poisoning (also called "search poisoning") is when attackers compromise legitimate websites to inject malicious content, redirects, or links. The goal is to manipulate search rankings to drive traffic to malicious sites, distribute malware, or steal user data.
⚠️ Warning: These techniques are illegal in many jurisdictions and violate search engine terms of service. This tool is designed for defensive security auditing only — to help you detect if your site has been compromised or to verify that competitors aren't using blackhat tactics.
What Does This Tool Detect?
🔎 Cloaking Detection
Compares the content served to Googlebot versus normal users. The tool fetches your page twice — once with a Googlebot User-Agent and once with a normal browser User-Agent — then analyzes:
- Content similarity: Text comparison (should be >95% similar)
- HTML length difference: Significant size differences indicate cloaking
- Meta tag differences: Different titles, descriptions, or keywords
- HTTP status codes: Different response codes for different user agents
🔁 Suspicious Redirect Analysis
Tracks the complete redirect chain (up to 10 hops) and identifies:
- Redirect chains: 301, 302, 307, 308 redirects
- External domain redirects: Redirects to different domains
- Risky file downloads: .exe, .apk, .sh, .ipa, .bat, .cmd, .scr, .vbs, .jar, .zip, .rar
- Redirect loops: Circular redirect patterns
📜 JavaScript Obfuscation Detection
Scans for suspicious JavaScript patterns commonly used in malware and blackhat SEO:
- eval(): Dynamic code execution (high risk)
- Function constructor: new Function() for code generation
- setTimeout/setInterval with strings: Delayed code execution
- document.write(): Dynamic content injection
- window.location manipulation: JavaScript redirects
- unescape(): Decoding obfuscated strings
- String.fromCharCode(): Character encoding obfuscation
- Hex/Unicode encoding: \x00 and \u0000 patterns
🧪 Base64 Payload Detection
Identifies and decodes base64-encoded content (often used to hide malicious code):
- Pattern matching: Finds base64 strings (40+ characters)
- Automatic decoding: Decodes and previews content
- Nested encoding detection: Multiple layers of encoding
- Content analysis: Checks for HTML, JavaScript, or suspicious strings
🪟 Hidden Elements Detection
Finds hidden HTML elements and CSS cloaking techniques:
- Hidden iframes: display:none, visibility:hidden, 0x0 size
- Meta refresh redirects: <meta http-equiv="refresh">
- CSS cloaking: text-indent:-9999px, opacity:0, absolute positioning
- External iframe sources: Iframes loading content from other domains
📥 Risky File Download & Analysis
Automatically downloads and analyzes suspicious files:
- Auto-download: Downloads files with risky extensions
- Quarantine storage: Isolates files in quarantine/YYYY-MM-DD/[hash]/
- Hash calculation: SHA256, MD5, SHA1 for file identification
- VirusTotal integration: Generates direct links for manual verification
- Metadata logging: Stores download date, URL, size, content type
How to Use the Scanner
Enter the URL
Enter the full URL of the website you want to scan (e.g., https://example.com). Make sure you have permission to scan the site.
Wait for Analysis
The scan takes 30-60 seconds. The tool fetches the page twice (Googlebot + normal UA), analyzes redirects, downloads risky files, and performs pattern matching.
Review Results
Check the severity rating (Clean, Low, Medium, High, Critical) and review detailed findings in each category: Cloaking, Redirects, JavaScript, Base64, Hidden Elements, and Downloaded Files.
Verify Findings
For downloaded files, use the VirusTotal links to check if they're malicious. Review JavaScript snippets and base64 payloads manually to confirm they're suspicious.
Take Action
If your site is compromised, remove malicious code immediately, change passwords, update software, and consider professional security help. If a competitor is using blackhat SEO, you can report them to Google.
Real-World Use Cases & Detection Guides
Explore detailed guides for specific security threats and practical scenarios where our cloaking scanner can help protect your website.
WooCommerce Malware & Credit Card Skimmers
Detect payment hijacking, credit card skimmers, and malware in WordPress WooCommerce stores. Learn how to protect customer payment data.
Read Full Guide →Pharma Hack & Japanese Keyword Spam
The #1 most common WordPress hack. Detect hidden pharmaceutical spam, Japanese keywords, and cloaking techniques.
Read Full Guide →Affiliate Link Hijacking & Commission Theft
Stop losing commissions to link hijacking. Detect stolen affiliate IDs, modified tracking codes, and malicious redirects.
Read Full Guide →SEO Spam Injection & Doorway Pages
Detect mass spam page injection, Japanese/Russian keyword hacks, and thousands of hidden doorway pages.
Read Full Guide →Competitor Analysis
Identify if competitors are using blackhat SEO techniques like cloaking to manipulate search rankings. Document findings for reporting to search engines.
Post-Hack Recovery Verification
After cleaning a hacked site, verify that all malicious code has been removed and no backdoors remain. Essential for reconsideration requests.
Understanding Severity Levels
✅ Clean
No security issues detected. The site appears legitimate with no cloaking, suspicious redirects, or malicious code patterns.
⚠️ Low
Minor issues detected (e.g., hex encoding, single redirect). These could be legitimate but warrant a quick review.
🟡 Medium
Moderate concerns (e.g., multiple redirects, document.write, base64 content). Review findings carefully to determine if they're legitimate.
🟠 High
Serious issues detected (e.g., eval(), hidden iframes, external redirects). Likely indicates malicious activity or blackhat SEO.
🔴 Critical
Severe security threats (e.g., confirmed cloaking, risky file downloads, base64-encoded scripts). Immediate action required.
Best Practices & Tips
Always Get Permission
Only scan websites you own or have explicit permission to test. Unauthorized scanning may violate terms of service or laws.
Verify Findings Manually
Not all detected patterns are malicious. Review JavaScript snippets and base64 content to confirm they're actually suspicious.
Use VirusTotal for Files
Before opening any downloaded files, check them on VirusTotal using the provided links. Never execute files directly.
Regular Monitoring
Scan your site monthly or after major updates to catch compromises early.
Document Everything
If reporting blackhat SEO to Google, save screenshots and detailed findings as evidence.
False Positives Happen
Some legitimate sites use techniques that trigger warnings (e.g., A/B testing, personalization). Context matters.
Frequently Asked Questions
Cloaking shows different content to search engines than to users. It's a blackhat SEO technique that violates Google's guidelines. Sites caught cloaking can be penalized or completely removed from search results. It's considered deceptive because it manipulates search rankings by showing optimized content to crawlers while showing different (often low-quality or malicious) content to real users.
Yes, when used for legitimate security auditing and defensive purposes. You should only scan websites you own or have explicit permission to test. Using this tool to detect if your own site has been compromised is perfectly legal. However, using findings to engage in blackhat SEO yourself is illegal and unethical.
The tool compares content similarity between Googlebot and normal user agents. Legitimate sites should have >95% similarity. However, some legitimate techniques (A/B testing, personalization, geo-targeting) can trigger false positives. Always review findings manually and consider the context. A low similarity score doesn't automatically mean cloaking — it means further investigation is needed.
First, review the findings carefully to determine if they're false positives. If you confirm malicious code: (1) Take the site offline immediately, (2) Change all passwords, (3) Remove malicious code, (4) Update all software/plugins, (5) Scan for backdoors, (6) Restore from a clean backup if needed, (7) Consider hiring a security professional. After cleaning, submit a reconsideration request to Google if you were penalized.
Yes. If you have evidence of cloaking or other blackhat techniques, you can report it to Google via their spam report form. Document your findings with screenshots and detailed evidence. However, be absolutely certain before reporting — false accusations can backfire. Remember that some techniques that look suspicious may be legitimate (e.g., personalization, mobile optimization).
If the tool detects redirects to risky file types (.exe, .apk, .sh, etc.), it automatically downloads them for analysis. Files are quarantined in a safe directory and never executed. The tool calculates file hashes (SHA256, MD5) and provides VirusTotal links so you can check if they're malicious. This helps identify malware distribution networks and compromised sites.
Common indicators include: hidden iframes loading external content, base64-encoded JavaScript, eval() or Function() calls, suspicious redirects to external domains, meta refresh tags, CSS cloaking (hidden text), obfuscated code, and unexpected file downloads. If you see multiple high-severity findings, your site may be compromised.
For high-value sites, scan monthly or after any major updates, plugin installations, or security incidents. For smaller sites, quarterly scans are sufficient. If you've been hacked before, increase frequency to weekly until you're confident the site is secure. Also scan immediately if you notice unusual traffic patterns, ranking drops, or security warnings.
Ready to Scan Your Site?
Detect cloaking, blackhat SEO, and malware in under 60 seconds.
Start Free Scan