Meta-Refresh-Redirect
This signal marks a client-side redirect implemented with a meta-refresh tag, which sends the browser to another URL after a delay. ScanMalware records it from the page’s meta tags.
Meta-refresh redirects are a classic cloaking and traffic-laundering technique used by phishing and scam pages to hide a final destination. A scanned page that uses one warrants a close look at where it sends visitors.
Commonly deployed alongside Meta-Refresh-Redirect
Of the 5,144 public scans where Meta-Refresh-Redirect was detected, these are the technologies most often present on the same site. The share is the percentage of Meta-Refresh-Redirect sites that also ran each one.
| Technology | Category | Share of Meta-Refresh-Redirect sites |
|---|---|---|
| X-UA-Compatible | miscellaneous | 91.62% |
| Ghost | cms | 90.24% |
| PasswordField | miscellaneous | 89.48% |
| HSTS | wappalyzer | 58.27% |
| HTTP/3 | wappalyzer | 46.06% |
| Microsoft ASP.NET | wappalyzer | 34.38% |
| Microsoft SharePoint | wappalyzer | 31.47% |
| Cloudflare | wappalyzer | 3.58% |
| Cloudflare Bot Management | wappalyzer | 3.4% |
| Script | miscellaneous | 2.97% |
| Open-Graph-Protocol | miscellaneous | 1.36% |
| Azure | wappalyzer | 1.36% |
| Envoy | wappalyzer | 1.34% |
| Google Analytics | wappalyzer | 1.28% |
How ScanMalware detects Meta-Refresh-Redirect
Meta-Refresh-Redirect is detected by analysing the response headers, HTML markup, JavaScript runtime and asset URLs captured when ScanMalware loads the site in a real headless browser.
From any scan you can pivot into related signals — JARM TLS fingerprints, ASN ownership and BGP routing, certificate history, JavaScript analysis and the overall security verdict — to understand not just that Meta-Refresh-Redirect is present, but how it is being used. Open the full search interface for Meta-Refresh-Redirect →
Recent public scans featuring Meta-Refresh-Redirect
A rolling sample of recent public scans where Meta-Refresh-Redirect was detected. Listing a site here is not a safety judgement — open a scan to see its full verdict.
| Site | Scanned |
|---|---|
| Sign in to your account https://3whm.mvd.en.update.wqagjdev.03-120-55-020.plesk.page/auth/oidc/azure | 2026-07-22 |
| Sign in to your account https://432update.staging.en.slotter.03-120-55-020.plesk.page/auth/oidc/azure | 2026-07-22 |
| Juez federal suspende arrestos de migrantes en tribunales de EE.UU. https://www.diarioenpositivo.com/politica/juez-eeuu-bloquea-nivel-nacional-arrestos-person… | 2026-07-22 |
| Sign in to your account https://whm.en.eqlzufpnkyadmin.dev.03-120-55-020.plesk.page/auth/oidc/azure | 2026-07-22 |
| Sign in to your account https://whm.mvd.806440204020mvd.update.gyxmorzv.03-120-55-020.plesk.page/auth/oidc/azure | 2026-07-22 |
| Sign in to your account https://mvl.50315031mvd.whm.whm.atmlruhe.03-120-55-020.plesk.page/auth/oidc/azure | 2026-07-22 |
| Sign in to your account http://ratenschutz-int.creditlife.de/ | 2026-07-22 |
| Sign in to your account https://9086whm.whm.pagelyqxjdemo.03-120-55-020.plesk.page/auth/oidc/azure | 2026-07-22 |
Frequently asked questions about Meta-Refresh-Redirect
- Does using Meta-Refresh-Redirect mean a website is unsafe?
- No. Meta-Refresh-Redirect is a stack component, not a verdict. ScanMalware scores the whole page — its scripts, redirects, certificates, threat-intelligence matches and behaviour — so a site using Meta-Refresh-Redirect can be perfectly safe or actively malicious.
- How many sites using Meta-Refresh-Redirect has ScanMalware scanned?
- Meta-Refresh-Redirect has been detected in 5,144 public scans on ScanMalware.com. Each scan is a real headless-browser visit, and the figure updates as new URLs are submitted.
- What technologies are commonly used with Meta-Refresh-Redirect?
- Across scanned sites, Meta-Refresh-Redirect is most often seen alongside X-UA-Compatible, Ghost and PasswordField. The full co-occurrence breakdown is listed on this page.
Browse all profiled technologies on the technology index, or scan a URL to see its full stack.