SleekShield Blog
Hacked Website Symptom Checker

What To Do If Google Shows a Site Warning

Browser and search warnings can hurt trust quickly, so the order of response matters.

A Google "Deceptive site ahead" or "This site may be hacked" warning is one of the most damaging things that can appear on a small business website. Visitors see it before they reach your page. It signals to potential customers that something is wrong, and it often appears without any warning to the site owner. Acting in the right order makes the recovery faster and reduces the chance of the warning returning.

Capture the warning before changing files

Before touching anything on the site, take a screenshot of the exact warning message. Note the date, time, and which browser triggered it. Different browsers show different warning text — Chrome uses Google Safe Browsing data, Firefox uses a similar feed, and some may show different categorisations. The screenshot is evidence you will need when requesting a review.

Check Google Search Console if your site is registered there. Search Console sends notifications when Google detects malware or phishing content, and the Security Issues report shows what Google found and approximately where. If the site is not registered in Search Console, add it now — you will need it for the review request step.

Use Google's Safe Browsing transparency report (transparencyreport.google.com/safe-browsing/search) to see what status Google currently assigns your domain. This gives you an independent view of what triggered the warning.

Check Search Console and hosting logs

In Search Console, navigate to Security & Manual Actions → Security Issues. This report lists what Google detected: malware, unwanted software, social engineering (phishing), or hacked content like spam pages. Each category has different remediation steps, so knowing exactly what Google flagged helps you focus the cleanup.

Access your hosting file manager and look for recently modified files, particularly PHP files in unusual locations like the uploads directory. Check for new files with names that do not match your theme or plugin structure. Look at your WordPress Users list for accounts you did not create. Review your active plugins for any you do not recognise.

Most hosting control panels provide access logs. Look for repeated requests to a specific PHP file — this is often a web shell that attackers use to maintain access and inject content. If you find one, do not delete it immediately; note its path and contents first.

Request review only after cleanup

The most common mistake after a warning is requesting a Google review before the site is clean. Google re-evaluates the site when you submit a request. If malicious content is still present, the review fails, a waiting period resets, and recovery takes longer.

Complete cleanup first: remove malicious files, delete unknown admin accounts, update all plugins and themes, change all passwords (hosting, WordPress admin, FTP, database), and consider installing a security plugin that provides file integrity monitoring. Take a backup after cleanup so you have a clean restore point.

Hacked Website Symptom Checker

Browser and search warnings can hurt trust quickly, so the order of response matters.

Check hacked website symptoms

Related guides

Reference links