Why Google shows a Deceptive site ahead warning
Google Safe Browsing warnings are designed to protect visitors from dangerous or deceptive pages. A legitimate business site can receive one after being compromised and used to host phishing pages, misleading downloads, malicious redirects or other social-engineering content.
The warning is not itself the malware. It is a symptom of content or behaviour that needs investigating. Attackers can create new pages, alter legitimate pages or load deceptive material through third-party resources. Some malicious behaviour is conditional, so the website may appear normal when its owner checks it.
A browser warning can sharply affect access to the site because visitors are warned before proceeding. Google also advises site owners to use Search Console's Security Issues report when investigating hacked or deceptive content.
How to investigate a Google Safe Browsing warning
Open Google Search Console and check Security Issues first. Review every example URL Google provides, but remember that examples may not represent every affected page. Check the Pages report as well for unfamiliar indexed URLs.
Run a Google search using site:yourdomain.co.uk and look for titles, descriptions or URLs you did not create. Test suspicious pages from a phone as well as desktop, inspect the HTML source and compare what Google's inspection tools have seen. Conditional redirects and cloaked content may only appear to particular devices, referrers or user agents.
At server level, inspect recent file changes, unexpected PHP, modified themes and plugins, rewrite rules, administrator accounts and the database. Look for phishing content, injected JavaScript, external scripts and redirects. Do not assume that deleting the URL named by Google removes the underlying compromise.
The free WordPress security scanner can provide an additional external check while you investigate the underlying files and database.
How to remove the cause and clear the warning
- Preserve a copy before cleaning. Back up all site files and the complete database, then retain an untouched copy of the compromised version for evidence.
- Find the source of the compromise. Check vulnerable plugins or themes, compromised users, hosting credentials, malicious files and third-party resources. The route used by the attacker must be closed as part of the cleanup.
- Remove all malicious content. Delete confirmed phishing or deceptive pages, remove injected code, replace modified WordPress core files with clean official copies and reinstall affected plugins or themes from trusted sources.
- Change credentials and security keys. Replace WordPress passwords, hosting credentials, database passwords, FTP or SFTP credentials and relevant keys. Generate new salts in wp-config.php to invalidate existing WordPress login sessions.
- Check the whole site again. Rescan files and database records, verify administrators, test redirects and inspect affected pages from different devices. Cleaning only Google's example URL is not sufficient if the malware exists elsewhere.
- Request Google's security review. Once the entire site is clean and the vulnerability has been addressed, use the Security Issues report in Search Console to request a review. Do not request the review while malicious content remains.
Hacked Site Rescue costs £349 fixed price and includes malware removal and help clearing Google and browser warnings.
Preventing another deceptive-site warning
Keep WordPress core, plugins and themes updated and remove software that is no longer used. Protect administrator and hosting accounts with unique strong passwords and two-factor sign-in, and limit privileged access to people who need it.
File integrity checks can help identify unexpected code changes, while routine review of Search Console provides another way to spot security problems reported by Google. Maintain off-server backups so a known recovery point remains available even if the hosting account itself is compromised.
Web Support Services care plans start from £59 a month and include weekly updates, daily off-server backups, 24/7 uptime monitoring and security scanning.