Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress malwareDeceptive Site Ahead Warning: Fix a Hacked WordPress Site

Deceptive Site Ahead Warning: Fix a Hacked WordPress Site

A red Deceptive site ahead warning means Google Safe Browsing has identified behaviour or content it considers dangerous or deceptive. On a legitimate WordPress site, that can be a sign of phishing, malicious injected content or another compromise.

Signs you might see

  • Red full-page warning in Chrome
  • Security Issues report in Search Console
  • Traffic drops sharply

Not sure? Run our free WordPress security scanner for a quick outside check.

Why Google shows a Deceptive site ahead warning

Google Safe Browsing warnings are designed to protect visitors from dangerous or deceptive pages. A legitimate business site can receive one after being compromised and used to host phishing pages, misleading downloads, malicious redirects or other social-engineering content.

The warning is not itself the malware. It is a symptom of content or behaviour that needs investigating. Attackers can create new pages, alter legitimate pages or load deceptive material through third-party resources. Some malicious behaviour is conditional, so the website may appear normal when its owner checks it.

A browser warning can sharply affect access to the site because visitors are warned before proceeding. Google also advises site owners to use Search Console's Security Issues report when investigating hacked or deceptive content.

How to investigate a Google Safe Browsing warning

Open Google Search Console and check Security Issues first. Review every example URL Google provides, but remember that examples may not represent every affected page. Check the Pages report as well for unfamiliar indexed URLs.

Run a Google search using site:yourdomain.co.uk and look for titles, descriptions or URLs you did not create. Test suspicious pages from a phone as well as desktop, inspect the HTML source and compare what Google's inspection tools have seen. Conditional redirects and cloaked content may only appear to particular devices, referrers or user agents.

At server level, inspect recent file changes, unexpected PHP, modified themes and plugins, rewrite rules, administrator accounts and the database. Look for phishing content, injected JavaScript, external scripts and redirects. Do not assume that deleting the URL named by Google removes the underlying compromise.

The free WordPress security scanner can provide an additional external check while you investigate the underlying files and database.

How to remove the cause and clear the warning

  1. Preserve a copy before cleaning. Back up all site files and the complete database, then retain an untouched copy of the compromised version for evidence.
  2. Find the source of the compromise. Check vulnerable plugins or themes, compromised users, hosting credentials, malicious files and third-party resources. The route used by the attacker must be closed as part of the cleanup.
  3. Remove all malicious content. Delete confirmed phishing or deceptive pages, remove injected code, replace modified WordPress core files with clean official copies and reinstall affected plugins or themes from trusted sources.
  4. Change credentials and security keys. Replace WordPress passwords, hosting credentials, database passwords, FTP or SFTP credentials and relevant keys. Generate new salts in wp-config.php to invalidate existing WordPress login sessions.
  5. Check the whole site again. Rescan files and database records, verify administrators, test redirects and inspect affected pages from different devices. Cleaning only Google's example URL is not sufficient if the malware exists elsewhere.
  6. Request Google's security review. Once the entire site is clean and the vulnerability has been addressed, use the Security Issues report in Search Console to request a review. Do not request the review while malicious content remains.

Hacked Site Rescue costs £349 fixed price and includes malware removal and help clearing Google and browser warnings.

Preventing another deceptive-site warning

Keep WordPress core, plugins and themes updated and remove software that is no longer used. Protect administrator and hosting accounts with unique strong passwords and two-factor sign-in, and limit privileged access to people who need it.

File integrity checks can help identify unexpected code changes, while routine review of Search Console provides another way to spot security problems reported by Google. Maintain off-server backups so a known recovery point remains available even if the hosting account itself is compromised.

Web Support Services care plans start from £59 a month and include weekly updates, daily off-server backups, 24/7 uptime monitoring and security scanning.

Common questions

Answers to the questions we hear most about this.

Why does Chrome say Deceptive site ahead on my website?

Google Safe Browsing may have detected phishing, deceptive content or another security problem associated with the site. For a legitimate WordPress website, compromise is one possible cause and Search Console's Security Issues report should be checked.

Can I remove the Google warning by deleting one infected page?

Only if that page was genuinely the entire problem, which should not be assumed. You need to check the full site, remove all malicious content and identify how it was introduced before requesting a review.

How do I ask Google to remove the Deceptive site ahead warning?

After the site has been fully cleaned and the security problem has been fixed, use the Security Issues report in Google Search Console to request a security review.

Think your site has been hacked?

Hacked Site Rescue is a fixed £249. We remove the malware, close the way in and help clear the warnings.

Get website support