A defaced site is the obvious case. The expensive case is quieter: injected links in your footer, a redirect added to one template, spam pages published under your domain. Your uptime monitor reports 200 the entire time, because the server is working perfectly — it is just serving someone else's content.
Free plan forever · No credit card · Set up in under a minute
How do you detect if your website has been defaced?
Watch your own pages the way you would watch a competitor's. When the content changes and no one on your team deployed anything, that is the signal. Uptime monitoring cannot do this — a compromised page returns a perfectly healthy 200 — so it needs a content comparison, checked often, with alerts going somewhere seen out of hours.
Most website compromises are not announced with a banner. Attackers who want to keep access do not deface — they inject links, add redirects that only fire for search engine traffic or mobile visitors, and publish pages deep in your URL structure. The site works. Nothing goes down. Nobody is alerted.
The first sign is usually external and late: a warning in Search Console, a customer forwarding a strange email, or rankings dropping for reasons nobody can explain. By that point the content has often been live for weeks.
Content monitoring turns this into a same-day signal. It is not a security product and it will not stop an intrusion — but it answers a question no firewall does, which is whether the page your visitors are being served is still the page you published.
This is the gap, and it is the reason both kinds of check belong in one place.
An uptime monitor asks whether the server responded and judges the status code. A compromised page responds beautifully. The HTML is valid, the response is fast, the certificate is fine — and the footer now contains two hundred links to a pharmacy site. Every availability check in the world reports green.
Content monitoring asks a different question: is this page the same as it was yesterday? That is the only question that catches injected content, and it is the reason we put both kinds of check in the same account rather than treating them as separate products. The same URL can be watched for outages and for unauthorised edits at the same time, with one bill and one place to look.
If you take one thing from this page: a green uptime dashboard is not evidence your site has not been tampered with. It is evidence the server is answering.
You do not need to watch everything. You need to watch the templates.
The most likely target for actual defacement, and the page whose compromise is most immediately damaging.
Injected content usually arrives through a shared template — header, footer, or a widget area. Watching one representative page per template catches a change affecting thousands of pages.
The highest-value targets, because a modified form is how credentials and card details are harvested. Watch these more often than anything else.
Both are small, both are frequently altered by SEO spam injections to get spam pages indexed, and neither is looked at by anyone from one year to the next.
A stable page — an old policy or an archive page — is a useful control. If that changes, something systemic happened.
Change detection is a detective control. It should not be sold as anything more.
This tells you something changed. It does not block an intrusion, patch a vulnerability or clean a compromise. It belongs alongside a firewall and a patching routine, not instead of them.
Compromises that only trigger for signed-in users, particular geographies or a specific user agent may not appear to us. Cloaked attacks that show clean content to unfamiliar clients are specifically designed to defeat this.
A defacement that replaces your page with an image would change the surrounding text and almost certainly alert. A change that alters only styling might not.
This is a feature, not a bug — but it means you should expect an alert when you publish. Teams that ship often should watch stable templates rather than pages that change daily.
Set up alerts that tell you when your own site changes and nobody deployed anything.
Select the main content region so a rotating banner does not alert you every hour.
Injected content usually arrives through a shared header or footer, so one page per template covers thousands.
Every five minutes. A modified form is how credentials get harvested, and minutes matter.
Small, frequently targeted by SEO spam, and never looked at otherwise.
Browser push reaches a phone lock screen; Slack or a webhook reaches whoever is on. Compromises rarely happen during office hours.
Content monitoring catches tampering; uptime catches outages. Both allowances are separate, so this costs no watches.
Typically about 5 minutes from start to finish.
Uptime monitors, watched pages and heartbeats each get their own allowance, so adding a page watch never costs you a monitor. SSL and domain checks ride along with the monitor they belong to and use nothing extra.
| Plan | Monitors | Watched pages | Heartbeats | Fastest interval | Alert channels | Price |
|---|---|---|---|---|---|---|
| Free | 1 | 1 | 1 | Every 30 minutes | 1 email address | $0 |
| Founding Member first 20 only | 25 | 25 | 25 | Every 5 minutes | Email + webhook & chat | $5/mo |
| Basic | 10 | 10 | 10 | Every 10 minutes | Email + webhook & chat | $8/mo |
| Growth | 50 | 50 | 50 | Every 5 minutes | Email + webhook & chat | $19/mo |
| Pro | 100 | 100 | 100 | Every 60 seconds | Email + webhook & chat | $34/mo |
Annual billing is cheaper on every paid tier. The pricing page is the authoritative list.
Every recorded change is compared word by word and kept with a before-and-after image. This is the real output, shown with worked example data.
Price fell from $49 to $39, and an annual discount was added.
The item is available again and the basket button returned.
A new subprocessor was added in another jurisdiction.
The free plan sends to one email address. Every paid plan adds the chat and webhook channels below, with 2 to 10 destinations depending on the plan. However many alerts you receive, the price does not change — nothing here is metered or charged per alert.
There are no voice calls and no SMS. If a phone call at 3am is a hard requirement, say so before you subscribe — we would rather tell you now than refund you later.
Watch your own pages for content changes. If the wording changes and nobody on your team deployed anything, that is your signal. Uptime monitoring cannot tell you — a compromised page returns a perfectly healthy 200 while serving someone else's content.
Because it asks whether the server responded, not whether it responded with your content. Injected links, added redirects and spam pages all return valid, fast, correctly certificated responses.
Usually hidden links in a footer or template, sometimes a redirect that only fires for search engine crawlers or mobile visitors, often spam pages published deep in your URL structure. The visible site looks normal, which is the point.
The homepage, one page per template, login and checkout, robots.txt and your sitemap. One page per template matters most, because template injection affects every page at once.
Yes, and that is the intended behaviour — the tool cannot tell your change from anyone else's. If you deploy frequently, watch stable templates and control pages rather than pages that change daily.
Often not. We see what an anonymous visitor sees, so attacks cloaked to show clean content to unfamiliar clients are specifically designed to defeat this approach. It is a real limitation of any external checker.
No, and we would rather be clear about that. It is a detective control that tells you a page changed. It does not prevent intrusion, patch anything or clean a compromise, and it belongs alongside a firewall and a patching routine rather than instead of one.
Within your check interval — as little as five minutes on paid plans. Compared with the usual discovery route of a Search Console warning weeks later, that is the entire value.
No. Watched pages and uptime monitors have separate allowances, so you can watch and monitor the same URL without either costing the other.
Somewhere seen outside office hours. Browser push reaches a phone lock screen, and Slack, Teams, Discord, Telegram or a webhook are available on paid plans. Compromises rarely respect working hours.
Last updated August 4, 2026 · Written by Amit Gupta, founder of MonitoringDaddy
Free plan covers one page and one uptime monitor. $5/mo covers 25 of each, checked every five minutes.