Skip to content

"Deceptive site ahead" on a WordPress site: what the red warning means and how to get it lifted

The red full-page warning comes from Google Safe Browsing, which most browsers consult. Google found phishing, malware or unwanted software on your site or loaded by it. The warning goes only after the cause is removed and Google has reviewed the site.

By
WP Ministry
Published

In short

  • The warning comes from Google Safe Browsing, not from WordPress or your host. Chrome now titles it "Dangerous site". Firefox still says "Deceptive site ahead".
  • The Security issues report in Google Search Console names what Google found and lists sample addresses. Go by that report, not by what your own browser shows.
  • The cause can be an advert or a script loaded from someone else's server, with no file of yours changed.
  • Clean every page and close the way in before you select "Request Review". A request sent too early slows the next one.
  • Google gives about a day for a phishing review, a few days for malware, and up to several weeks for a site hacked with spam.
  • A new domain does not remove the warning. The cause moves with the files and the database.

The red full-page warning comes from Google Safe Browsing, a list of dangerous sites that most major browsers check before they open a page. Your site is on it because Google found something on the site, or loaded by it, that it classes as social engineering (phishing), malware or unwanted software. The warning goes only after the cause has been removed and Google has looked at the site again.

You cannot switch it off for your visitors from WordPress or from your hosting account. The work has three parts, in this order: find out what Google found, remove it, and ask for a review.

What the warning says in each browser

Chrome no longer shows the words "Deceptive site ahead". Its help page says the red warning now reads "Dangerous site", and Chrome's source code has that one heading for all three kinds of problem. Firefox still uses the older wording, and so does Google's own page for site owners about social engineering. Whichever wording you see, the problem and the way out are the same.

What the page saysBrowserWhat it means
"Dangerous site"ChromeAny of the three: social engineering, malware or unwanted software
"Deceptive site ahead"Firefox, and older versions of ChromeSocial engineering: content that tricks a visitor into something dangerous, such as giving up a password or downloading software
"The site ahead contains malware"Older versions of ChromeMalware: software built to harm a device or the person using it
"Visiting this website may harm your computer"FirefoxMalware. Mozilla's help calls this an attack site
"The site ahead contains harmful programs"Older versions of ChromeUnwanted software: programs that deceive, or that change how a browser behaves, such as swapping the home page
"The site ahead may contain harmful programs"FirefoxUnwanted software
"The site ahead may contain malware"FirefoxAn app reported as potentially harmful, one that could steal or delete a visitor's information
"Deceptive Website Warning", "Malware Website Warning", "Website With Harmful Software Warning"Safari. These are the titles in WebKit, the engine Safari is built onThe same three, in that order

In Chrome, select "Details" on the warning. The paragraph that opens says which of the three it is: that Google Safe Browsing recently found malware, recently found phishing, or found harmful software on the site.

Microsoft Edge takes its warnings from a list of Microsoft's own. That list, and what Firefox and Safari consult, are covered further down.

How to tell it from a certificate warning

Go by the words on the page.

  • A Safe Browsing warning is a full-page red screen that calls the site dangerous or deceptive. Chrome's help says that page means the site is flagged as unsafe by Google Safe Browsing. It is about what the site serves.
  • A certificate warning is also a full page. In Chrome it says "Your connection is not private" and shows a code such as NET::ERR_CERT_DATE_INVALID. It is about the certificate that secures the connection, and it is fixed at your host: see how to fix "Your connection is not private".
  • A page that loads, but is not shown as fully secure, is neither. On a site that has a certificate, the page is fetching something over plain http. See how to fix mixed content warnings.

Neither of the last two has anything to do with Safe Browsing, and a review request does nothing for them.

Find out what Google found

Do this before you change anything on the site. The names and addresses Google gives you are what you clean, and what you later describe in the review request.

  1. Step 1: Check the Safe Browsing site status

    Enter your address on Google's site status page. It needs no account. It says whether the site currently contains content that Safe Browsing has determined to be dangerous. For the name of each issue and for sample pages, you need Search Console.

  2. Step 2: Add the site to Search Console and verify it

    If the site is already there, skip this. Otherwise open the property selector in Google Search Console and select "+ Add property". A Domain property covers every subdomain, with http and https, and is verified with a DNS record at your domain provider. A URL-prefix property covers only addresses that begin exactly as you typed them, and can be verified by uploading an HTML file to the site's main folder. Google's instructions also name Site Kit, a WordPress plugin that Google sponsors, which can handle verification for you. On a site you believe is hacked, the DNS record changes nothing on the server.

  3. Step 3: Open the Security issues report

    The Security issues report shows a count of issues at the top. Expand each one. You get its name, the date it was first detected, a short description and a list of sample addresses. Google says the list is a sample and not every affected page, and that an issue can appear with no sample at all. That does not mean no page is affected. Write down every issue name and every sample address.

  4. Step 4: Look at a flagged page the way Google is served it

    Google advises against opening an infected page in your browser, because malware often spreads through browser vulnerabilities. Type one of the sample addresses into the inspection bar at the top of Search Console, select "Test live URL", then "View tested page". You get a screenshot, the page's HTML as Google received it, and the list of resources the page loaded, including those from other servers.

The report's issue names map to the three kinds of problem like this.

In the reportWhat Google found
Hacked: MalwareThe site is infected with malware, or hosts it, after a break-in
Hacked: Code injectionMalicious code added to your pages, such as a redirect to another site
Hacked: Content injectionSpam links or text added to your pages
Hacked: URL injectionNew pages created on your site, often full of spam words and links
Deceptive pagesSocial engineering in the pages themselves
Deceptive embedded resourcesSocial engineering in an advert, an image or another third-party component the page loads
Harmful downloadsA file your site offers that Safe Browsing classes as malware or unwanted software
Links to harmful downloadsLinks from your pages to sites that offer such files

In Google's own table of what it does about each kind of problem, the browser warning page belongs to malware and unwanted software and to phishing and social engineering. Hacked spam content is dealt with in search results.

The cause may not be a file on your server

A page is judged by everything it loads. Google's guidance is plain that a site can be flagged for content it does not host:

  • An advert. Deceptive content inside an ad counts against the page that shows it. Ad networks rotate what they serve, so Google suggests reloading the page several times, and looking at both the mobile and the desktop view, before deciding an ad slot is clean.
  • A script or frame from another server. Google's examples of injected code include a script tag that loads its code from an attacker's domain, and a hidden frame that loads a malicious site.
  • A pop-up or a redirect. A page with no visible ad can still send visitors on to a deceptive page, and that counts against it too.
  • A link or a download. Linking to a site that offers harmful downloads, or offering such a file yourself, is enough.

WordPress lets a plugin or a theme add a script by its full address, so the code a page runs can sit on any server. Look at what your plugins and theme load, and at any advert, chat or tracking code that was pasted into a settings box. In the list of resources that "View tested page" shows, every domain should be one you can account for.

Google notes that attackers often show their code only to certain visitors, such as those arriving from a search engine. How to check whether your WordPress site has been hacked shows how to request a page as a visitor from Google, and the hacked-site check makes both requests for you and compares them.

Remove the cause

If the report names a hack, or you find code nobody on your side added, this is a break-in and it is cleaned as one. Start with the hacked site runbook for the first hour, then follow how to remove malware from a hacked WordPress site, which covers the clean-up in full.

If the cause is an advert, an embed or a script you added yourself, remove that ad unit, embed or plugin. Then check the sample addresses again.

What "removed" has to mean for the review to pass

  • The content is gone from every page. Google says that fixing only some pages earns no partial return, and that every issue in the report has to be fixed. The samples are examples. Search the rest of the site for the same thing.
  • The way in is closed. Google's list of what must be true before a review includes correcting the vulnerability, not only removing what the attacker left. A cleaned site with the same out-of-date plugin or the same stolen password can be broken into again, and flagged again.
  • The site is back online and Google can read it. The cleanup guide has you take the site offline while you work. For the review, the pages must be reachable, and not blocked by robots.txt or by a noindex tag. In WordPress, check that "Discourage search engines from indexing this site" under Settings, Reading is not ticked, and that no maintenance page is still in front of the site.
  • Each flagged address answers properly. A page you keep returns a clean page. A page the attacker created is deleted, and its address returns a 404. Google's guidance also describes malware placed in a site's error page, so request an address that does not exist and read what comes back.

Google recommends checking with curl or Wget and not with a browser. This prints the status code an address answers with: 200 for a page that is there, 404 for one that is gone. The HTTP status and redirect checker shows the same without a terminal.

bash
curl -s -o /dev/null -w "%{http_code}\n" https://example.com/sample-page/

Ask Google for the review

  1. Step 1: Select "Request Review" in the Security issues report

    Google's help says to select it when all the issues listed in the report are fixed on all pages. The report may still show the warnings and sample addresses you saw before. That is not a sign that the fix failed.

  2. Step 2: Say what was wrong, what you did and how it turned out

    Google asks for three things: the exact issue, the steps you took to fix it, and the outcome. Write a sentence or two for each issue the report names. Be specific about the cause and about what was removed. This is an example of the shape, with every detail to be replaced by your own.

    text
    Issue: Hacked: Code injection, on the sample URLs in the report and on other pages.
    Cause: an out-of-date plugin, [name], let an attacker add a script to the theme's header file.
    What was done: removed the script; replaced WordPress, every plugin and the theme with clean
    copies; updated everything; deleted two administrator accounts nobody had created; changed
    every password.
    Outcome: the sample URLs now return clean pages. The pages the attacker added return 404.
  3. Step 3: Wait for the decision

    Google emails when it receives the request and again when the review is complete. Do not send a second request while the first is open.

How long each kind of review takes

These are Google's own figures, from its guide to requesting a review and its Search Console help.

What was flaggedWhat Google says
Phishing or social engineeringAbout a day. A second Google page, on social engineering, says several days
MalwareA few days
A site hacked with spamUp to several weeks, because the review can involve a manual investigation or reprocessing every hacked page
Harmful downloads and unwanted softwareNo figure of their own. The Security issues help gives one range for every issue it lists: from a few days to a few weeks

After an approval, Google's guide says warnings in browsers and in search results are removed within 72 hours. Its Search Console help adds that an update can take a day or two to reach browsers, so one can go on showing the warning for a short while after the site status page has cleared.

If Google decides the problem is still there, the warning stays, and the report may show more sample addresses to help you look again.

What Google says about repeat offenders

Google introduced the term in 2016 for a site that switches back and forth between clean and harmful in order to pass a review. Such a site cannot request another review through Search Console for 30 days, the warnings stay up, and the owner is told by email. The same announcement says that hacked sites are not classified as repeat offenders, only sites that post harmful content on purpose.

That does not make an early request harmless. Google's Search Console help says a request sent before the issue is fixed can lengthen the turnaround of the next one, and can even get a site marked as a repeat offender.

Lists other than Google's

A review at Google clears Google's list. Browsers that consult that list follow it. Other products keep lists of their own, and each has to be asked separately.

  • Microsoft Edge uses Microsoft Defender SmartScreen, which checks sites against Microsoft's own list of reported phishing and malware sites. Microsoft's help gives the route from the warning page: select "More information", then "Report that this site doesn't contain threats", and follow the instructions on Microsoft's feedback site.
  • Firefox checks pages against lists of reported sites that it updates about every 30 minutes. For a site listed as deceptive that has been repaired, or was listed in error, Mozilla points to Google's report form. Google's guide says that form also triggers a review of a cleaned phishing page.
  • Safari checks an address with Google Safe Browsing and with Apple, by Apple's account, and may also use Tencent Safe Browsing on devices set to the China mainland or Hong Kong region. WebKit's warning for a deceptive site carries a link for reporting an error to the provider that listed it.
  • Antivirus and security products. WordPress's documentation notes that desktop antivirus applications and other search engines keep blacklists too, and that a visitor may be using any of them. The warning a visitor sees names the product that raised it. Ask them which one, and use that product's own form.

What not to do

  • Do not request a review before the site is clean. Google says it only prolongs the time the site stays flagged, and the next request can take longer.
  • Do not send the request twice. Google asks you to wait for the decision on the first.
  • Do not just move the site to a new domain. The warning follows what the pages serve. Copy the same files and database to a new address and the same content is there for Google to find, since it checks the pages it indexes for malicious scripts and downloads. The old address stays flagged, and every link, bookmark and search result that points to it still meets the warning.
  • Do not tell visitors to click through. Chrome's warning offers a way past it, and Chrome's help says using it is not recommended. Until the review passes, assume the page can harm the people who open it.

When to hand it over

Get help when the report names a hack and you cannot find the code, when a review comes back refused and you do not know why, or when the site takes orders and each day behind the warning costs sales.

Our malware removal service is a one-time clean-up with hardening, a blacklist removal request and a written report. The company that issued the warning reviews the site and decides, so nobody can promise the outcome or how long it takes.

Common questions

Chrome says "Dangerous site", not "Deceptive site ahead". Is that a different problem?

No. Chrome's help page gives "Dangerous site" as the warning for phishing, malware, unwanted software and social engineering alike, and "Deceptive site ahead" is the earlier wording, which Firefox still uses. In Chrome, select "Details" on the warning to see which kind Google found.

Does this warning mean my site was hacked?

Not always. Google flags a page for deceptive adverts, for third-party components it embeds, and for downloads or links the owner added, as well as for code an attacker planted. The Security issues report says which: the issues that begin with "Hacked" are break-ins. If you did not add what Google found, treat it as one.

I cannot see the warning myself. Is it gone?

Not necessarily. Google says Safe Browsing shows warnings according to the context a page is opened in, so an owner may not be able to reproduce one. Check the Security issues report and the Safe Browsing site status page. Those tell you whether the site is still listed.

The Security issues report is empty, but a browser still warns. What now?

Look at the Safe Browsing site status page first. If it no longer lists the site, Google says an update can take a day or two to reach browsers. If the browser is Microsoft Edge, the warning comes from Microsoft's list, and the request goes to Microsoft. If the site is still listed as deceptive and you believe the page is clean, Google's report form asks for a review of that page.

How long does the warning stay once the site is clean?

Until Google has reviewed the site and approved it. Google gives about a day for a phishing review, a few days for malware and up to several weeks for a site hacked with spam, then up to 72 hours for the warnings to be removed. Cleaning the site without requesting a review leaves you waiting for Google to notice.

More on this subject

Malware removal, done for you

Malware removal is $99. Full clean-up, hardening, blacklist removal request and a written report. 30-day re-clean guarantee. It starts with a free diagnosis.