Alt text fields are an overlooked attack surface. Scan any webpage to detect hidden payloads, script injection, SQL injection, base64-encoded strings, and malicious content buried in image attributes — before someone else finds it first. Free, no account needed.
Public pages only. Scans static HTML — for JS-rendered pages or login-protected pages, use the bookmarklet below for a full in-browser scan.
Scan any page you're currently on — including login-protected pages, staging environments, and localhost — with one click. No URL required. The bookmarklet runs entirely in your browser.
Chrome: Ctrl+Shift+B (Windows) / Cmd+Shift+B (Mac) ·
Firefox: View → Toolbars → Bookmarks Toolbar
Click and hold the AEOfix Alt Scanner button above and drag it up to your bookmarks bar. Release to drop.
Go to the page you want to audit. Click AEOfix Alt Scanner in your bookmarks bar. A panel appears overlaid on the page — images are highlighted by status.
Click the × button in the panel or click the bookmark again to remove the overlay and outlines.
Right-click your bookmarks bar → Add page → paste the code below as the URL:
Most people think alt text is just for screen readers. Attackers know better. Image alt attributes are rarely audited, never visible to casual visitors, and processed by crawlers, scrapers, search engines, and AI systems — making them a low-visibility channel for embedding malicious content.
This scanner detects what you can't see. It reads the raw HTML the same way a security auditor or malicious bot would — exposing anything that doesn't belong.
Script tags, event handlers, and javascript: URIs embedded in alt text can execute in vulnerable parsers, scrapers, and legacy CMS preview systems.
Base64 strings, hex-encoded data, and null-byte sequences can be used to exfiltrate data or smuggle content past content filters.
Keyword stuffing and URL injection in alt text manipulate search crawler behavior — a sign of compromised pages or malicious third-party scripts.
Several ways: a compromised CMS plugin that injects content into image metadata, a malicious third-party script that rewrites the DOM, a supply chain attack on an image optimization service, or a bad actor who gained write access to your site. Because alt text is invisible to visitors and rarely monitored, it's a low-risk, high-persistence hiding spot for attackers.
The scanner flags alt text containing: script tags or javascript: URIs, inline HTML elements, event handler patterns (onerror=, onmouseover=), SQL injection strings, base64-encoded payloads (40+ chars), long hex strings, multiple URLs, and HTML-encoded control characters. Any of these in an alt attribute is abnormal and warrants investigation.
Suspicious alt text isn't necessarily malicious but indicates something worth reviewing: filenames used as descriptions (IMG_4532.jpg), generic placeholder labels, alt text over 150 characters, or comma-separated keyword lists (a classic SEO spam signal). These may indicate lazy CMS defaults, a compromised page, or a third-party script gone wrong.
Not in a modern browser rendering the page normally — browsers don't execute alt text as code. However, it can execute in: XML parsers that process the raw attribute, RSS feed readers that render HTML, screen scraper tools, AI crawlers that pass content to downstream processors, and some legacy CMS preview systems. The risk is real for automated pipelines, not just human visitors.
Not by itself — empty alt is correct for purely decorative images. But empty alt on a content image (product photo, team headshot, chart) is a red flag. It either means the CMS stripped the value, a script cleared it, or someone intentionally removed it to hide a previously populated field. The scanner flags these as "decorative" so you can verify intent.
No — the URL scanner fetches public pages only. Use the free bookmarklet for authenticated pages. It runs entirely inside your browser — the page HTML never leaves your machine.
No. The scan fetches the target URL server-side, processes the HTML, and returns results directly to your browser. Nothing is stored or logged. The bookmarklet runs 100% client-side — no data is transmitted anywhere.
First: don't panic, but act fast. Check your CMS audit log for recent file changes. Scan your active plugins and third-party scripts against known CVE databases. Pull a clean backup and diff it against current files. Change all admin credentials. If you can't identify the source, a full malware scan and server audit is warranted. The alt text is the symptom — the injection point is the real problem.
Alt text is one layer. AEOfix's Access product shows whether AI can reach and understand your site at all — crawler access controls, schema integrity, robots.txt exposure, and how AI engines are currently reading and representing your content.