MB Bluejuice
Security

Your website redirects visitors to unknown pages

Redirect malware works selectively: the administrator never sees it, while visitors from Google land somewhere else.

· updated 2026-10-07

This is one of the most common cases clients bring us: “everything looks fine to me, but people say they end up on some other website”.

Why you do not see it

Redirect code almost always carries conditions. It usually triggers only when:

  • the visitor arrived from a search engine (it checks HTTP_REFERER);
  • a mobile device is used (it checks User-Agent);
  • the visitor is not logged into WordPress;
  • it is a first visit — after that a cookie prevents a repeat.

So an administrator who is permanently logged in and visits directly can miss it for months.

Where the code usually hides

  • .htaccess — RewriteCond rules at the end of the file;
  • the theme’s functions.php or header.php;
  • the wp_options database table, usually in autoloaded rows;
  • a separate plugin named to look legitimate.

How to check

Open the site in a private window through Google search, and again from a phone. In the browser Network panel enable “Preserve log” — you will see exactly where the redirect goes.

Finding it is only half the work. If the entry vector is not identified, the code comes back. An incident investigation starts with evidence, not with cleanup.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.