Malware
Malicious redirect
Malicious redirect is code that sends a visitor to a page they did not choose, usually a scam, a fake update, or an ad network. It often runs only for some visitors, so the owner sees a normal site.
How it is measured
Observe it by following the chain, not the page. Request the URL with a mobile user agent, with a Google referrer, and with no referrer, and record every Location header, meta refresh, and JavaScript location change. A clean site ends at the same URL every time; a redirect infection ends at a different host for some combinations.
Places to look: .htaccess rewrite rules, theme functions.php, injected <script> tags in the footer, and the options table in a WordPress database. Search results are a signal too: a browser warning when people click through from Google, but not when they type the address.
Worked example
A recipe blog on WordPress gets complaints that tapping a search result lands people on a fake 'Your phone is infected' page. The owner types the URL and sees the recipe fine. A curl with a Google referrer and an Android user agent returns a 302 to 'track-offer-live.top' after a 1 KB script in the header.php of a nulled theme.
Grepping the theme for 'document.referrer' finds the logic: redirect only if the referrer contains 'google' and the cookie 'wp_seen' is absent. That cookie is set for logged-in admins, which is why the owner never reproduced the problem.
How it differs
An open redirect is a legitimate redirect endpoint that an attacker can aim anywhere through a parameter; the site's code is working as written. A malicious redirect is planted code that does the sending on its own. The first needs input validation, the second needs a cleanup and a search for how it got in.
Common errors
Testing only from the admin's logged-in browser. Checking the homepage and ignoring deep URLs or the 404 page. Cleaning the visible script and leaving the .htaccess rule that restores it. Treating a Search Console warning as a false alarm because the site loads fine. Blaming the ad network when the redirect fires with ads disabled.
In practice
Reproduce with a fresh private window, a mobile user agent, and a search-engine referrer before you touch anything, and save the redirect chain. Compare .htaccess, index.php, and the active theme with clean copies, remove unknown admin users, and update the plugin that let the file be written. Request a review after cleanup if a browser or search engine flagged the domain.