A "Deceptive Site Ahead" or "This site may be hacked" warning appears when Google's Safe Browsing system finds malware, phishing content, or suspicious code on your website. Browsers like Chrome and Firefox use the same data, so visitors are blocked from reaching your site until the issue is fixed and Google reviews it again. This is different from your email being blacklisted for spam. It means your actual website files have been flagged.
Why This Warning Appears
It almost always means your website has been compromised in some way. Common causes include an outdated CMS or plugin with a known vulnerability, a weak admin password that was guessed or leaked, or malicious code injected into your files that redirects visitors or serves hidden ads. You may not notice anything wrong yourself since the malicious code is often hidden from a logged-in admin.
Step 1: Confirm the Warning and See What Google Found
- Open Google Search Console for your domain and go to the Security Issues report in the left menu. If Google has flagged your site, it will list the type of issue and often example URLs.
- If you don't have Search Console set up, you can also check your domain's status using Google's Safe Browsing site status checker, which tells you whether a URL is currently flagged without needing an account.
Step 2: Clean Up Your Website
Don't skip straight to asking for a review. Google will re-flag your site if the problem is still there. Work through these checks first:
- Scan your website files for malware and remove anything suspicious. If your hosting account has ClamAV available, our guide on scanning your website for malware walks through running a scan from your control panel.
- Update your CMS core, themes, and plugins to the latest versions, since outdated software is the most common way attackers get in.
- Check your admin user list for accounts you don't recognize and remove them, then reset all remaining admin passwords.
- Look through recently modified files for code you didn't add, especially in theme files, uploads folders, or the site's root .htaccess file.
If you're not confident going through your files manually, contact your hosting provider's support team before you proceed. Removing the wrong file can break your site, and leaving malicious code behind means the warning will likely return.
Step 3: Request a Review From Google
- Once you're confident the site is clean, go back to the Security Issues report in Search Console.
- Click Request a Review.
- Describe the steps you took to fix the problem, then submit the request.
Reviews are usually completed within a few days, though it can take longer. The warning stays in place until the review finishes, even if your site is already clean.
How to Prevent It Happening Again
- Keep your CMS, plugins, and themes updated as soon as new versions are released.
- Use strong, unique passwords for all admin accounts and enable two-factor authentication where it's available.
- Remove any plugins, themes, or scripts you're no longer using instead of leaving them installed and outdated.
- Keep regular backups so you can restore a clean version of your site quickly if it happens again.