Got an email from us and not sure why? Here's what it means →
LIVE · Monitoring Newly Disclosed Vulnerabilities and Exploits

Your Website Gets
Hacked Through
Known Holes.

Hacklert continuously monitors public websites and compares what it finds against newly disclosed vulnerabilities. When we identify a match on your site, we'll email you — often before an attacker finds the same weakness.

🚨 SECURITY ALERT — yourdomain.com — just now
WHAT WE FOUND Outdated plugin with known exploit
SEVERITY Critical
RISK Hackers could gain full admin access
ACTION Update plugin to v3.2.1 immediately

Most Website Hacks
Are Preventable

The painful truth: the vast majority of successful website hacks exploit security flaws that were already publicly known — with a fix already available.

The problem? Nobody told the website owner in time. Your web developer isn't watching this. Your hosting provider isn't watching this. Nobody is — until it's too late.

$8,000+

Typical cost to recover a hacked small-business website — not counting lost sales, reputation damage, or customer trust.

hacklert_scanner — scan running
$ hacklert scan yourdomain.com
→ Detecting technologies...
✓ WordPress 6.2 detected
✓ WooCommerce 8.1 detected
→ Checking known vulnerability signatures...
⚠ CVE-2024-3714 matched (CVSS 9.8)
⚠ Outdated plugin: contact-form-7 v5.7
→ Confirming with one safe request...
✗ CRITICAL: exploit confirmed
→ Sending alert to owner...
✓ Alert delivered

You Didn't Sign Up For This.
Here's What Happened.

A security email out of nowhere deserves suspicion. So here's exactly what we do, what we don't, and how to make it stop — no spin.

How we found you

Your website is open to the public

Our scanner visits sites the way Google's crawler does, and reads what they openly show: which software they run, which version of it, and which pages are left open.

Nothing was hacked and nothing leaked. If Google can see it, we can see it — and so can anyone hunting for an easy target.

What we did not do

We didn't log in or take anything

We don't try passwords, upload anything, open your database, or run anything that could break your site. To confirm a problem we send one harmless request that answers yes or no.

All we keep is the public information above and the email address we wrote to.

Is this a scam?

Fair question. Check it yourself.

Nothing in that email asks you for money, a password, or a download. It gives you the official ID of the problem. Look it up, compare it to the version you're running, and you'll know in two minutes whether we're right.

We'd rather you fix it yourself for free than pay us and still be unsure.

Why we bother

Some people hire us afterwards

That's the whole business. Most people fix it and move on, which is fine. A few decide they don't want to be the one watching for this every day, and put their site on a care plan.

The alert is free either way, and always will be.

New Ways In Appear Daily.
So Does The Check.

Attackers use software to find vulnerable sites within hours of a new hole going public. We work on the same clock they do.

New problems are published

Security holes are disclosed publicly every day. We collect the day's list, keep the ones affecting real websites, and turn them into checks.

We look at your site

A quick read of your public pages: which software and version you run, whether your certificate is healthy, and which pages are open that shouldn't be.

We double-check the match

A version number alone is just a guess. One harmless test confirms the problem is real, so what lands in your inbox isn't a false alarm.

The email reaches you

What's exposed, how serious it is, and the one thing to click or update. Written so you can act on it without calling anyone.

Sites on a care plan get checked twice a day, plus a warning when something changes: a new setting on your domain, a certificate about to expire, or your email and password turning up in a leaked database.

Keep The Watch Running —
Or Hand The Whole Thing Over.

One free alert tells you about today. A care plan covers you on the days you're not looking. Billed monthly — cancel whenever you like.

Extra sites past 25: $4/mo each · Pay yearly and two months are free.

Both Sides Of The Fence.

Monitoring shows what's visible from the outside. When you need to know how far someone could really get — or something has already gone wrong — we handle that too.

Offensive

Website Security Audit

We try to break into your site on purpose, by hand, the way a real attacker would: logins, permissions, forms, checkout. You get a list of what worked, ranked by severity, with the fix for each.

See audit levels →
Defensive

Virus & Backdoor Removal

Already hacked? We find how they got in, remove the bad code and anything left to get back in, clean your database, and get you off Google's warning list.

Defensive

Website Lockdown

Closing what shouldn't be open: exposed admin pages, old files, weak settings, unlimited login attempts, and missing two-step login.

Defensive

Emergency Response

Site defaced, sending visitors to spam, or emailing people on its own? We stop it, work out what happened, and write it up so it doesn't happen again.

Can My Website
Actually Be Hacked?

Send us a website you own. We run the same daily check we'd run for a paying customer and send back what we find — including "nothing serious," if that's the answer.

  • 01Every piece of software we can see from outside, and which ones are out of date.
  • 02Any known security hole that matches what you're running, and how serious it is.
  • 03Pages and files left open that shouldn't be: admin logins, backups, error messages.
  • 04Email addresses on your domain that show up in leaked password databases.
  • 05A short verdict in plain English: what to fix first, and what can wait.

Only send websites you own, or ones you're allowed to test. We confirm ownership before doing anything deeper.

Report back within one working day. One email, nothing after that.

Want Us Gone?
One Click.

No hard feelings and nothing follows. Enter the address we wrote to, or your website, and you're off the list.

We stop the emails, stop checking your website, and delete what we hold — all within 48 hours. Or just email privacy@hacklert.com.

What We Hold On You.

Short version: public facts about a website, and one email address. That's the whole file.

What we keepYour website address, which software and version it shows publicly, what we found, when we looked, and the email we wrote to.
Where the email came fromPublic domain records, a contact page on the site itself, or a general address like admin@ or info@ on your domain.
What we never collectPasswords, customer information, your database, your files, or anything behind a login.
Who else sees itNobody. We don't sell, share or publish what we find, and we don't pass it to anyone else.
How long we keep it12 months for free alerts, then deleted. Deleted straight away if you ask. Care-plan records are kept while the plan runs.
Your rightsAsk for a copy, correct it, or have it deleted — email privacy@hacklert.com and you'll hear back within 48 hours.