## **🔍 Overview**

If your antivirus has flagged a script in your WordPress footer and you suspect the Search Atlas OTTO plugin, this article will help you quickly determine the true source and take the right action. The OTTO plugin does inject a script into your site — but it follows a predictable format. Anything that deviates from that format is **not** from Search Atlas and should be treated as a potential security threat.

## **📋 How to Check Whether the Script Is from OTTO**

The most reliable way to determine whether the flagged script comes from the OTTO plugin is to deactivate the plugin and observe whether the script disappears:

1. Log in to your WordPress admin panel.
2. Navigate to your installed plugins list and **deactivate** the Search Atlas OTTO plugin.
3. Clear your site's cache and any CDN cache.
4. Reload your website and check whether the suspicious script is still present.
5. If the script **disappears** after deactivating OTTO, it was injected by the plugin. If it **remains**, it originates from another source and should be treated as a potential malicious injection.

## **🚨 Signs the Script May Be External Malware (Not OTTO)**

The following are red flags that indicate the script is **not** from Search Atlas and is likely a malicious injection — including techniques used in ClickFix and similar social-engineering malware campaigns:

- The script loads from an unrecognised or suspicious domain unrelated to Search Atlas.
- The code contains long strings of base64 or hex-encoded text.
- It uses **eval()**, **Function()**, or **unescape()** to execute hidden code.
- The script tag is embedded deep inside theme files, other plugin files, or directly in the WordPress database (wp\_options, post content).
- It appears even after you **deactivate** the OTTO plugin.
- Your antivirus names a specific threat — such as a ClickFix script, a fake CAPTCHA injector, or a clipboard hijacker — rather than flagging a generic tracking pixel.

If any of these apply, the injection is likely external malware and **Search Atlas OTTO is not the cause**.

## **✅ Next Steps If You Suspect Malware**

If the script persists after deactivating OTTO, take the following steps:

- Run a full malware scan using a trusted WordPress security plugin (such as Wordfence or Sucuri).
- Review recently modified files in your WordPress installation for unexpected changes.
- Check your WordPress database (particularly **wp\_options** and post content) for injected script tags.
- Consider restoring from a clean backup taken before the injection appeared.
- Contact your hosting provider, as they may have server-level scanning tools available.

When escalating to our support team, please have the following ready: your site URL, the exact script or code snippet that was flagged, the name of the threat your antivirus identified, and a note of whether the script persisted after deactivating the OTTO plugin.

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type **human teammate** to be connected with a member of our team.