miscellaneous

Meta-Refresh-Redirect

This signal marks a client-side redirect implemented with a meta-refresh tag, which sends the browser to another URL after a delay. ScanMalware records it from the page’s meta tags.

Meta-refresh redirects are a classic cloaking and traffic-laundering technique used by phishing and scam pages to hide a final destination. A scanned page that uses one warrants a close look at where it sends visitors.

Public scans
5,752
Category
miscellaneous
Co-detected technologies
14
Versions observed

Commonly deployed alongside Meta-Refresh-Redirect

Of the 5,752 public scans where Meta-Refresh-Redirect was detected, these are the technologies most often present on the same site. The share is the percentage of Meta-Refresh-Redirect sites that also ran each one.

TechnologyCategoryShare of Meta-Refresh-Redirect sites
X-UA-Compatiblemiscellaneous
91.08%
Ghostcms
89.81%
PasswordFieldmiscellaneous
89.41%
HSTSwappalyzer
55.69%
HTTP/3wappalyzer
49.12%
Microsoft ASP.NETwappalyzer
32.99%
Microsoft SharePointwappalyzer
30.33%
Cloudflarewappalyzer
4.22%
Cloudflare Bot Managementwappalyzer
4.05%
Scriptmiscellaneous
2.66%
jQuerywappalyzer
1.6%
Azurewappalyzer
1.3%
Open-Graph-Protocolmiscellaneous
1.23%
Envoywappalyzer
1.22%

How ScanMalware detects Meta-Refresh-Redirect

Meta-Refresh-Redirect is detected by analysing the response headers, HTML markup, JavaScript runtime and asset URLs captured when ScanMalware loads the site in a real headless browser.

From any scan you can pivot into related signals — JARM TLS fingerprints, ASN ownership and BGP routing, certificate history, JavaScript analysis and the overall security verdict — to understand not just that Meta-Refresh-Redirect is present, but how it is being used. Open the full search interface for Meta-Refresh-Redirect

Recent public scans featuring Meta-Refresh-Redirect

A rolling sample of recent public scans where Meta-Refresh-Redirect was detected. Listing a site here is not a safety judgement — open a scan to see its full verdict.

SiteScanned
มนุษย์ทุกคนที่คลิกนี่คือมนุษย์ที่มีความโลภและสมควรได้รับความร่ำรวย
http://ajarin-dpet-x5000cuy.pages.dev/
2026-08-14
Sign in to your account
https://vanburenco-my.sharepoint.com
2026-08-14
Sign in to your account
https://onpxtdev.2staging.wwwdev.en.03-120-55-020.plesk.page/auth/oidc/azure
2026-08-14
Sign in to your account
https://www.dmin.en.slotter.03-120-55-020.plesk.page/auth/oidc/azure
2026-08-14
Sign in to your account
https://n0ljj0hff0dbwhm.03-120-55-020.plesk.pagezutnnwqagjdev.03-120-55-020.plesk.page/aut…
2026-08-14
Sign in to your account
https://hoti.sharepoint.com
2026-08-14
Sign in to your account
https://dgsprmjdzszwuydpxm.03-120-55-020.plesk.page/auth/oidc/azure
2026-08-14
Sign in to your account
https://goodwillky.sharepoint.com
2026-08-14

Frequently asked questions about Meta-Refresh-Redirect

Does using Meta-Refresh-Redirect mean a website is unsafe?
No. Meta-Refresh-Redirect is a stack component, not a verdict. ScanMalware scores the whole page — its scripts, redirects, certificates, threat-intelligence matches and behaviour — so a site using Meta-Refresh-Redirect can be perfectly safe or actively malicious.
How many sites using Meta-Refresh-Redirect has ScanMalware scanned?
Meta-Refresh-Redirect has been detected in 5,752 public scans on ScanMalware.com. Each scan is a real headless-browser visit, and the figure updates as new URLs are submitted.
What technologies are commonly used with Meta-Refresh-Redirect?
Across scanned sites, Meta-Refresh-Redirect is most often seen alongside X-UA-Compatible, Ghost and PasswordField. The full co-occurrence breakdown is listed on this page.

Browse all profiled technologies on the technology index, or scan a URL to see its full stack.