A Google "Deceptive site ahead" or "This site may be hacked" warning is one of the most damaging things that can appear on a small business website. Visitors see it before they reach your page. It signals to potential customers that something is wrong, and it often appears without any warning to the site owner. Acting in the right order makes the recovery faster and reduces the chance of the warning returning.
Capture the warning before changing files
Before touching anything on the site, take a screenshot of the exact warning message. Note the date, time, and which browser triggered it. Different browsers show different warning text — Chrome uses Google Safe Browsing data, Firefox uses a similar feed, and some may show different categorisations. The screenshot is evidence you will need when requesting a review.
Check Google Search Console if your site is registered there. Search Console sends notifications when Google detects malware or phishing content, and the Security Issues report shows what Google found and approximately where. If the site is not registered in Search Console, add it now — you will need it for the review request step.
Use Google's Safe Browsing transparency report (transparencyreport.google.com/safe-browsing/search) to see what status Google currently assigns your domain. This gives you an independent view of what triggered the warning.
Check Search Console and hosting logs
In Search Console, navigate to Security & Manual Actions → Security Issues. This report lists what Google detected: malware, unwanted software, social engineering (phishing), or hacked content like spam pages. Each category has different remediation steps, so knowing exactly what Google flagged helps you focus the cleanup.
Access your hosting file manager and look for recently modified files, particularly PHP files in unusual locations like the uploads directory. Check for new files with names that do not match your theme or plugin structure. Look at your WordPress Users list for accounts you did not create. Review your active plugins for any you do not recognise.
Most hosting control panels provide access logs. Look for repeated requests to a specific PHP file — this is often a web shell that attackers use to maintain access and inject content. If you find one, do not delete it immediately; note its path and contents first.
Request review only after cleanup
The most common mistake after a warning is requesting a Google review before the site is clean. Google re-evaluates the site when you submit a request. If malicious content is still present, the review fails, a waiting period resets, and recovery takes longer.
Complete cleanup first: remove malicious files, delete unknown admin accounts, update all plugins and themes, change all passwords (hosting, WordPress admin, FTP, database), and consider installing a security plugin that provides file integrity monitoring. Take a backup after cleanup so you have a clean restore point.
- Screenshot the warning before making any changes — you need it for the review.
- Check Search Console Security Issues for what Google actually detected.
- Clean the site thoroughly before submitting a review request.
- In Search Console, use the Request Review button under Security Issues after cleanup.
- Monitor for 24–72 hours after the review — Google usually processes requests within this window.
- Set up Search Console email alerts so you are notified of future security issues promptly.
Browser and search warnings can hurt trust quickly, so the order of response matters.
Check hacked website symptoms