A red browser warning or a “This site may harm your computer” message can stop traffic and damage trust overnight. The priority is not hiding the warning—it is removing the harmful behavior, closing the attacker’s access and giving Google a clean site to review.
Google’s Security Issues report may identify hacked content, URL injection, malicious downloads, phishing or other harmful behavior and provide sample URLs. Those examples may not represent every affected page.
Security warning, manual action or indexing problem?
A security issue indicates behavior that may harm visitors or devices. A manual action usually concerns search-policy violations. Coverage and indexing reports describe crawling and indexing, not necessarily malware. Check each relevant report instead of assuming one review fixes everything.
Step 1: confirm the warning safely
Verify the correct Search Console property and review every issue category and sample URL. Avoid opening known malicious pages on a normal work device. Record the warning date, examples and recent changes, then export available security, server and authentication logs.
Compare the symptoms with signs of a hacked WordPress site. Search spam may also connect to the Japanese keyword hack.
Step 2: contain visitor risk
If the site redirects, serves malicious downloads or captures credentials, restrict public access or use a controlled maintenance state while investigating. Preserve a full file and database snapshot before cleanup. Coordinate with the host when server-level evidence or account isolation is required.
Step 3: clean the entire environment
Remove malicious files, scripts, database injections, unauthorized users, application passwords, scheduled tasks and hostile server rules. Replace modified core, plugin and theme code with trusted packages. Audit DNS, CDN, tag managers, deployment credentials, sibling sites and hosting users.
For rerouted visitors, use the WordPress redirect-hack guide. For an ordered response, follow Emergency Recovery Steps.
Step 4: remove persistence and close the entry point
Investigate vulnerable extensions, stolen credentials, exposed control panels, insecure permissions, compromised devices and shared hosting. Rotate WordPress, hosting, database, SFTP, SSH, CDN and deployment credentials. Update salts, invalidate sessions and enable multi-factor authentication.
A scanner reporting zero findings is not enough when the cause is unknown. Compare files with trusted copies, review scheduled tasks and monitor the clean build before requesting review.
Step 5: test the repaired site
- Confirm harmful pages and injected URLs are removed or return the correct status.
- Test important pages on mobile and desktop.
- Check redirects, downloads, forms, scripts and outbound links.
- Verify that crawlers are not shown different malicious content.
- Rescan files and review administrator and cron inventories.
- Keep the site accessible to Google for verification.
Step 6: request a security review
When every listed issue is fixed throughout the site, use Request Review in Search Console’s Security Issues report. Explain what happened, the scope checked, what was removed, how the entry point was closed and how the result was verified.
Google states that security reviews can take from a few days to a few weeks. Avoid repeated submissions while a review is pending unless new evidence materially changes the incident.
After the warning is removed
Watch Search Console, analytics, crawl behavior, administrator changes, files and server logs. Restore clean sitemaps, inspect important URLs and let spam URLs disappear through correct status codes and recrawling. A removed warning does not guarantee immediate ranking recovery.
Strengthen updates, access control, backups, site isolation and monitoring. Record the incident timeline and schedule follow-up reviews after one day, one week and one month.
For a compromised business site, use . Ongoing protection is covered by and . See our for the broader remediation approach.
Frequently asked questions
Why does Google say my WordPress site is dangerous?
Google may show a warning when it detects hacking, malware, harmful downloads, phishing or deceptive content. Search Console’s Security Issues report can provide issue types and sample affected URLs.
Is a Google security warning the same as a manual action?
No. Security issues concern potentially harmful or hacked behavior, while manual actions generally concern violations intended to manipulate search results. A site can have one, both or neither.
Can I request a review before cleanup is complete?
Request a security review only after fixing every listed issue across the site, removing persistence, patching the entry point and testing the result. Partial cleanup can delay recovery.
How long does a Google security review take?
Google states that a review can take from a few days to a few weeks. Timing varies, so monitor Search Console and keep the site accessible for verification.
Will removing the warning restore rankings immediately?
Not necessarily. Removing a security warning and rebuilding organic rankings are separate processes. Visibility can take longer as Google recrawls clean pages and reassesses site signals.
How can I prevent another Safe Browsing warning?
Keep WordPress and extensions updated, remove unused software, protect privileged access, monitor files and users, maintain tested backups, isolate sites and respond quickly to suspicious changes.
Final warning-removal checklist
- Review every Security Issues category and sample URL.
- Contain harmful behavior and preserve evidence.
- Clean the full WordPress and hosting environment.
- Remove persistence, patch the cause and rotate credentials.
- Test all affected behavior and important pages.
- Submit one complete review request and monitor the result.




