Cloaking & SEO Poison Scanner

Complete guide to detecting cloaking, blackhat SEO techniques, malware-laced redirections, and suspicious code patterns.

What is Cloaking & SEO Poisoning?

Cloaking is a blackhat SEO technique where a website shows different content to search engine crawlers (like Googlebot) than it shows to regular users. This violates Google's Webmaster Guidelines and can result in severe penalties, including complete deindexing from search results.

SEO Poisoning (also called "search poisoning") is when attackers compromise legitimate websites to inject malicious content, redirects, or links. The goal is to manipulate search rankings to drive traffic to malicious sites, distribute malware, or steal user data.

⚠️ Warning: These techniques are illegal in many jurisdictions and violate search engine terms of service. This tool is designed for defensive security auditing only — to help you detect if your site has been compromised or to verify that competitors aren't using blackhat tactics.

What Does This Tool Detect?

🔎 Cloaking Detection

Compares the content served to Googlebot versus normal users. The tool fetches your page twice — once with a Googlebot User-Agent and once with a normal browser User-Agent — then analyzes:

  • Content similarity: Text comparison (should be >95% similar)
  • HTML length difference: Significant size differences indicate cloaking
  • Meta tag differences: Different titles, descriptions, or keywords
  • HTTP status codes: Different response codes for different user agents

🔁 Suspicious Redirect Analysis

Tracks the complete redirect chain (up to 10 hops) and identifies:

  • Redirect chains: 301, 302, 307, 308 redirects
  • External domain redirects: Redirects to different domains
  • Risky file downloads: .exe, .apk, .sh, .ipa, .bat, .cmd, .scr, .vbs, .jar, .zip, .rar
  • Redirect loops: Circular redirect patterns

📜 JavaScript Obfuscation Detection

Scans for suspicious JavaScript patterns commonly used in malware and blackhat SEO:

  • eval(): Dynamic code execution (high risk)
  • Function constructor: new Function() for code generation
  • setTimeout/setInterval with strings: Delayed code execution
  • document.write(): Dynamic content injection
  • window.location manipulation: JavaScript redirects
  • unescape(): Decoding obfuscated strings
  • String.fromCharCode(): Character encoding obfuscation
  • Hex/Unicode encoding: \x00 and \u0000 patterns

🧪 Base64 Payload Detection

Identifies and decodes base64-encoded content (often used to hide malicious code):

  • Pattern matching: Finds base64 strings (40+ characters)
  • Automatic decoding: Decodes and previews content
  • Nested encoding detection: Multiple layers of encoding
  • Content analysis: Checks for HTML, JavaScript, or suspicious strings

🪟 Hidden Elements Detection

Finds hidden HTML elements and CSS cloaking techniques:

  • Hidden iframes: display:none, visibility:hidden, 0x0 size
  • Meta refresh redirects: <meta http-equiv="refresh">
  • CSS cloaking: text-indent:-9999px, opacity:0, absolute positioning
  • External iframe sources: Iframes loading content from other domains

📥 Risky File Download & Analysis

Automatically downloads and analyzes suspicious files:

  • Auto-download: Downloads files with risky extensions
  • Quarantine storage: Isolates files in quarantine/YYYY-MM-DD/[hash]/
  • Hash calculation: SHA256, MD5, SHA1 for file identification
  • VirusTotal integration: Generates direct links for manual verification
  • Metadata logging: Stores download date, URL, size, content type

How to Use the Scanner

1

Enter the URL

Enter the full URL of the website you want to scan (e.g., https://example.com). Make sure you have permission to scan the site.

2

Wait for Analysis

The scan takes 30-60 seconds. The tool fetches the page twice (Googlebot + normal UA), analyzes redirects, downloads risky files, and performs pattern matching.

3

Review Results

Check the severity rating (Clean, Low, Medium, High, Critical) and review detailed findings in each category: Cloaking, Redirects, JavaScript, Base64, Hidden Elements, and Downloaded Files.

4

Verify Findings

For downloaded files, use the VirusTotal links to check if they're malicious. Review JavaScript snippets and base64 payloads manually to confirm they're suspicious.

5

Take Action

If your site is compromised, remove malicious code immediately, change passwords, update software, and consider professional security help. If a competitor is using blackhat SEO, you can report them to Google.

Real-World Use Cases & Detection Guides

Explore detailed guides for specific security threats and practical scenarios where our cloaking scanner can help protect your website.

Understanding Severity Levels

✅ Clean

No security issues detected. The site appears legitimate with no cloaking, suspicious redirects, or malicious code patterns.

⚠️ Low

Minor issues detected (e.g., hex encoding, single redirect). These could be legitimate but warrant a quick review.

🟡 Medium

Moderate concerns (e.g., multiple redirects, document.write, base64 content). Review findings carefully to determine if they're legitimate.

🟠 High

Serious issues detected (e.g., eval(), hidden iframes, external redirects). Likely indicates malicious activity or blackhat SEO.

🔴 Critical

Severe security threats (e.g., confirmed cloaking, risky file downloads, base64-encoded scripts). Immediate action required.

Best Practices & Tips

✅

Always Get Permission

Only scan websites you own or have explicit permission to test. Unauthorized scanning may violate terms of service or laws.

✅

Verify Findings Manually

Not all detected patterns are malicious. Review JavaScript snippets and base64 content to confirm they're actually suspicious.

✅

Use VirusTotal for Files

Before opening any downloaded files, check them on VirusTotal using the provided links. Never execute files directly.

✅

Regular Monitoring

Scan your site monthly or after major updates to catch compromises early.

✅

Document Everything

If reporting blackhat SEO to Google, save screenshots and detailed findings as evidence.

⚠️

False Positives Happen

Some legitimate sites use techniques that trigger warnings (e.g., A/B testing, personalization). Context matters.

Frequently Asked Questions

What is cloaking and why is it bad?

Cloaking shows different content to search engines than to users. It's a blackhat SEO technique that violates Google's guidelines. Sites caught cloaking can be penalized or completely removed from search results. It's considered deceptive because it manipulates search rankings by showing optimized content to crawlers while showing different (often low-quality or malicious) content to real users.

Is it legal to use this tool?

Yes, when used for legitimate security auditing and defensive purposes. You should only scan websites you own or have explicit permission to test. Using this tool to detect if your own site has been compromised is perfectly legal. However, using findings to engage in blackhat SEO yourself is illegal and unethical.

How accurate is the cloaking detection?

The tool compares content similarity between Googlebot and normal user agents. Legitimate sites should have >95% similarity. However, some legitimate techniques (A/B testing, personalization, geo-targeting) can trigger false positives. Always review findings manually and consider the context. A low similarity score doesn't automatically mean cloaking — it means further investigation is needed.

What should I do if my site is flagged?

First, review the findings carefully to determine if they're false positives. If you confirm malicious code: (1) Take the site offline immediately, (2) Change all passwords, (3) Remove malicious code, (4) Update all software/plugins, (5) Scan for backdoors, (6) Restore from a clean backup if needed, (7) Consider hiring a security professional. After cleaning, submit a reconsideration request to Google if you were penalized.

Can I report competitors using blackhat SEO?

Yes. If you have evidence of cloaking or other blackhat techniques, you can report it to Google via their spam report form. Document your findings with screenshots and detailed evidence. However, be absolutely certain before reporting — false accusations can backfire. Remember that some techniques that look suspicious may be legitimate (e.g., personalization, mobile optimization).

Why does the tool download files?

If the tool detects redirects to risky file types (.exe, .apk, .sh, etc.), it automatically downloads them for analysis. Files are quarantined in a safe directory and never executed. The tool calculates file hashes (SHA256, MD5) and provides VirusTotal links so you can check if they're malicious. This helps identify malware distribution networks and compromised sites.

What are common signs of a compromised site?

Common indicators include: hidden iframes loading external content, base64-encoded JavaScript, eval() or Function() calls, suspicious redirects to external domains, meta refresh tags, CSS cloaking (hidden text), obfuscated code, and unexpected file downloads. If you see multiple high-severity findings, your site may be compromised.

How often should I scan my site?

For high-value sites, scan monthly or after any major updates, plugin installations, or security incidents. For smaller sites, quarterly scans are sufficient. If you've been hacked before, increase frequency to weekly until you're confident the site is secure. Also scan immediately if you notice unusual traffic patterns, ranking drops, or security warnings.

Ready to Scan Your Site?

Detect cloaking, blackhat SEO, and malware in under 60 seconds.

Start Free Scan