Visitors hit a red "Dangerous site" screen before reaching you, or Google writes "This site may be hacked" under your search result. The warning comes from the Google Safe Browsing list, and it is lifted through a set process: find out what Google detected, clean it up, then request a review.
transparencyreport.google.com/safe-browsing/search?url=your-site.com.Chrome shows a red page titled "Dangerous site". To get past it, a visitor has to click "Details" and then "Visit this unsafe site". Safari and Firefox also rely on the Google Safe Browsing list and show their own warning. In search results, Google can add "This site may be hacked" or "This site may harm your computer" under your link.
Search Console files what Google found under one of three categories, and each one is hunted down in a different place:
| Category in Search Console | What Google detected | Where to look |
|---|---|---|
| Hacked content | Content added by a third party: spam pages, hidden links, redirects, code injected into pages. | Recent files and pages, the database, .htaccess, added sitemap files. |
| Malware and unwanted software | A site that installs or offers harmful programs, or sends its visitors to them. | Scripts injected into pages and theme files, downloadable files dropped on the server. |
| Social engineering | Pages that deceive visitors: a fake login page for a bank, a mailbox or a courier, fake tech support. | A folder dropped on the server, often with a harmless-looking name, holding a copy of a well-known brand’s page. |
Google’s Transparency Report gives a site’s Safe Browsing status without any account: swap in your address in the link below.
https://transparencyreport.google.com/safe-browsing/search?url=your-site.com
For the details, and to request the review, you need Google Search Console. If the site is not in it yet, add a Domain property: it is verified through a DNS record (the "Domain name provider" method) and covers every address on the domain, with and without www, over http and https. A URL-prefix property can also be verified with an HTML file, an HTML tag, Google Analytics or Google Tag Manager.
Once inside Search Console, open Settings > Users and permissions. Google advises checking that no new, suspicious owners have been added. If one has, remove it, then delete its unused ownership tokens (the file, tag or DNS record it used to verify), or it can verify itself again.
The report lives under Security & Manual Actions > Security issues. It names each issue detected and gives sample URLs. They are samples: the same issue can affect other pages, and the review covers the whole site.
Google points out that many hackers make changes that are visible only to its crawlers. To see a page the way Google sees it, use the URL Inspection tool, then Test live URL, and read the HTML of the tested page: a script or links missing from the page in your own browser are the injected content.
The neighbouring Manual actions report covers something else: attempts to manipulate Google’s index, which are not necessarily dangerous for visitors. The "Dangerous site" warning belongs to security issues.
site:your-site.com to list indexed pages you did not write. Delete them so they return 404 or 410, remove added sitemap files (Search Console, Sitemaps), and look for redirects in .htaccess, PHP files and the database.In all three cases, close the access the attacker used: hosting, FTP, database and administrator passwords, unknown accounts, up-to-date plugins and theme. Otherwise the content comes back.
A site that switches back from compliant to non-compliant within a short time is classed as a repeat offender by Google: for 30 days, its owner can no longer request a review in Search Console. A thorough clean-up before the first request beats a quick request.
| Issue type | Review time stated by Google |
|---|---|
| Phishing (social engineering) | About a day |
| Malware | A few days |
| Hacked with spam | Up to several weeks |
Once the review is accepted, the warnings disappear from browsers and search results within the following days. If it is rejected, the email explains what is left: fix it and request a review again.
Microsoft Edge relies on its own list, Microsoft Defender SmartScreen. If Edge blocks the site as well, report it from Edge’s warning page: open "More information", then report that the site does not contain the threat. Microsoft replies by email.
With the warning lifted, one question remains: who looks after the site from now on? Simafri takes over your WordPress site, puts it back online on a base we host, secure and keep up to date, and looks after it month after month. You keep your domain name and your content.
According to Google, the review takes about a day for phishing, a few days for malware and up to several weeks for a hack with spam. Once the review is accepted, the warnings disappear within the following days. The clock starts when you request the review in Search Console.
You can, but an issue still present leads to a rejection. And a site that turns non-compliant again soon after becoming compliant is classed as a repeat offender: for 30 days, no review request is accepted. Clean the whole site, beyond the sample URLs, before the first request.
If the Security issues report in Search Console lists an issue, the warning is lifted after an accepted review, so you need to request one. If the report lists no issue, the label disappears after Google next crawls the site.
You first need to verify the site in Search Console. A Domain property is verified with a DNS record at your domain name provider and covers every address on the site. The Security issues report and the Request Review button are then available.
Simafri
Let's talk about your project
Tell us what you need in a few words: we will get back to you quickly.
Thank you! Your request has been sent. We'll get back to you shortly.
Prefer email? Write to us at support@simafri.com.