Uptime and content in one account

Know your own site changed when you did not change it

A defaced site is the obvious case. The expensive case is quieter: injected links in your footer, a redirect added to one template, spam pages published under your domain. Your uptime monitor reports 200 the entire time, because the server is working perfectly — it is just serving someone else's content.

Free plan forever · No credit card · Set up in under a minute

How do you detect if your website has been defaced?

Watch your own pages the way you would watch a competitor's. When the content changes and no one on your team deployed anything, that is the signal. Uptime monitoring cannot do this — a compromised page returns a perfectly healthy 200 — so it needs a content comparison, checked often, with alerts going somewhere seen out of hours.

Most website compromises are not announced with a banner. Attackers who want to keep access do not deface — they inject links, add redirects that only fire for search engine traffic or mobile visitors, and publish pages deep in your URL structure. The site works. Nothing goes down. Nobody is alerted.

The first sign is usually external and late: a warning in Search Console, a customer forwarding a strange email, or rankings dropping for reasons nobody can explain. By that point the content has often been live for weeks.

Content monitoring turns this into a same-day signal. It is not a security product and it will not stop an intrusion — but it answers a question no firewall does, which is whether the page your visitors are being served is still the page you published.

Why uptime is blind to it

A compromised page returns a perfect 200

This is the gap, and it is the reason both kinds of check belong in one place.

An uptime monitor asks whether the server responded and judges the status code. A compromised page responds beautifully. The HTML is valid, the response is fast, the certificate is fine — and the footer now contains two hundred links to a pharmacy site. Every availability check in the world reports green.

Content monitoring asks a different question: is this page the same as it was yesterday? That is the only question that catches injected content, and it is the reason we put both kinds of check in the same account rather than treating them as separate products. The same URL can be watched for outages and for unauthorised edits at the same time, with one bill and one place to look.

If you take one thing from this page: a green uptime dashboard is not evidence your site has not been tampered with. It is evidence the server is answering.

What to watch

Pages worth a watch on your own site

You do not need to watch everything. You need to watch the templates.

The homepage

The most likely target for actual defacement, and the page whose compromise is most immediately damaging.

One page per template

Injected content usually arrives through a shared template — header, footer, or a widget area. Watching one representative page per template catches a change affecting thousands of pages.

Login and checkout pages

The highest-value targets, because a modified form is how credentials and card details are harvested. Watch these more often than anything else.

Your robots.txt and sitemap

Both are small, both are frequently altered by SEO spam injections to get spam pages indexed, and neither is looked at by anyone from one year to the next.

A page you never change

A stable page — an old policy or an archive page — is a useful control. If that changes, something systemic happened.

Being honest

What this is and is not

Change detection is a detective control. It should not be sold as anything more.

It detects, it does not prevent

This tells you something changed. It does not block an intrusion, patch a vulnerability or clean a compromise. It belongs alongside a firewall and a patching routine, not instead of them.

It sees what an anonymous visitor sees

Compromises that only trigger for signed-in users, particular geographies or a specific user agent may not appear to us. Cloaked attacks that show clean content to unfamiliar clients are specifically designed to defeat this.

It compares text, not appearance

A defacement that replaces your page with an image would change the surrounding text and almost certainly alert. A change that alters only styling might not.

Your own deployments will alert you

This is a feature, not a bug — but it means you should expect an alert when you publish. Teams that ship often should watch stable templates rather than pages that change daily.

How it works

How to monitor your website for unauthorised changes

Set up alerts that tell you when your own site changes and nobody deployed anything.

1

Watch your homepage

Select the main content region so a rotating banner does not alert you every hour.

2

Add one page per template

Injected content usually arrives through a shared header or footer, so one page per template covers thousands.

3

Watch login and checkout more often

Every five minutes. A modified form is how credentials get harvested, and minutes matter.

4

Add robots.txt and your sitemap

Small, frequently targeted by SEO spam, and never looked at otherwise.

5

Send alerts where they will be seen out of hours

Browser push reaches a phone lock screen; Slack or a webhook reaches whoever is on. Compromises rarely happen during office hours.

6

Add an uptime monitor to the same URLs

Content monitoring catches tampering; uptime catches outages. Both allowances are separate, so this costs no watches.

Typically about 5 minutes from start to finish.

Pricing

What it costs

Uptime monitors, watched pages and heartbeats each get their own allowance, so adding a page watch never costs you a monitor. SSL and domain checks ride along with the monitor they belong to and use nothing extra.

PlanMonitorsWatched pagesHeartbeatsFastest intervalAlert channelsPrice
Free111Every 30 minutes1 email address$0
Founding Member first 20 only252525Every 5 minutesEmail + webhook & chat$5/mo
Basic101010Every 10 minutesEmail + webhook & chat$8/mo
Growth505050Every 5 minutesEmail + webhook & chat$19/mo
Pro100100100Every 60 secondsEmail + webhook & chat$34/mo

Annual billing is cheaper on every paid tier. The pricing page is the authoritative list.

See it

What an alert actually looks like

Every recorded change is compared word by word and kept with a before-and-after image. This is the real output, shown with worked example data.

competitor.com/pricing Watching: Pricing table
Pro plan — $49 per month
+ Pro plan — $39 per month
+ Save 20% with annual billing

Price fell from $49 to $39, and an annual discount was added.

2 words added · 1 removed · 4.1% of the watched region

retailer.com/product/… Watching: Availability
Out of stock
+ In stock — ships tomorrow
+ Add to basket

The item is available again and the basket button returned.

6 words added · 3 removed · 12.5% of the watched region

supplier.com/subprocessors Watching: Subprocessor list
~ Data is processed in the EUthe EU and the United States
+ Added: Northwind Analytics Inc. (United States)

A new subprocessor was added in another jurisdiction.

9 words added · 2 removed · 1.8% of the watched region

Worked example — not live data. Start monitoring free
Alerts

Where we can reach you

The free plan sends to one email address. Every paid plan adds the chat and webhook channels below, with 2 to 10 destinations depending on the plan. However many alerts you receive, the price does not change — nothing here is metered or charged per alert.

Email Before and after images inline
Browser push On a phone or desktop lock screen
RSS feed Every recorded change, as a feed
SlackPaid Through an incoming webhook
Microsoft TeamsPaid Through an incoming webhook
DiscordPaid Through an incoming webhook
TelegramPaid Straight to a chat or channel
FlockPaid Through an incoming webhook
WebhooksPaid Post to anything you run yourself

There are no voice calls and no SMS. If a phone call at 3am is a hard requirement, say so before you subscribe — we would rather tell you now than refund you later.

FAQ

Website defacement monitoring questions

How do I know if my website has been hacked?

Watch your own pages for content changes. If the wording changes and nobody on your team deployed anything, that is your signal. Uptime monitoring cannot tell you — a compromised page returns a perfectly healthy 200 while serving someone else's content.

Why does my uptime monitor not catch this?

Because it asks whether the server responded, not whether it responded with your content. Injected links, added redirects and spam pages all return valid, fast, correctly certificated responses.

What does SEO spam injection look like?

Usually hidden links in a footer or template, sometimes a redirect that only fires for search engine crawlers or mobile visitors, often spam pages published deep in your URL structure. The visible site looks normal, which is the point.

Which pages should I watch on my own site?

The homepage, one page per template, login and checkout, robots.txt and your sitemap. One page per template matters most, because template injection affects every page at once.

Will my own deployments trigger alerts?

Yes, and that is the intended behaviour — the tool cannot tell your change from anyone else's. If you deploy frequently, watch stable templates and control pages rather than pages that change daily.

Can it detect a compromise that only shows to some visitors?

Often not. We see what an anonymous visitor sees, so attacks cloaked to show clean content to unfamiliar clients are specifically designed to defeat this approach. It is a real limitation of any external checker.

Is this a security product?

No, and we would rather be clear about that. It is a detective control that tells you a page changed. It does not prevent intrusion, patch anything or clean a compromise, and it belongs alongside a firewall and a patching routine rather than instead of one.

How quickly would I find out?

Within your check interval — as little as five minutes on paid plans. Compared with the usual discovery route of a Search Console warning weeks later, that is the entire value.

Does watching my own site use up my uptime monitors?

No. Watched pages and uptime monitors have separate allowances, so you can watch and monitor the same URL without either costing the other.

Where should the alerts go?

Somewhere seen outside office hours. Browser push reaches a phone lock screen, and Slack, Teams, Discord, Telegram or a webhook are available on paid plans. Compromises rarely respect working hours.

Keep reading

Related monitoring guides

Last updated August 4, 2026 · Written by Amit Gupta, founder of MonitoringDaddy

AG
Written by

Amit Gupta

Amit Gupta is the founder of MonitoringDaddy , a website and infrastructure monitoring platform built by Toto Dream Marketing. He writes about uptime, change detection, SSL and domain monitoring, and helps teams keep their websites fast, secure and online.

Watch your own site tonight.

Free plan covers one page and one uptime monitor. $5/mo covers 25 of each, checked every five minutes.