Google says "Deceptive site ahead". Here's what that means.
A full red screen where your website should be, and every visitor is told to turn back. It is fixable, it is common, and it is not the end of your website. Here is what triggered it and how the warning gets lifted.
What you're seeing
Instead of your website, visitors get a full red screen with "Deceptive site ahead" across it, a "Back to safety" button, and a small "Details" link most people never click. Some people see "This site may be hacked" or "The site ahead contains malware" instead — same system, slightly different wording depending on what Google found.
It shows up in Chrome, Firefox, Safari and Android, because they all use the same Google Safe Browsing list. That is why it feels like the whole internet turned on you at once. Two things usually make it more confusing:
- The site often loads perfectly for you, because you have visited it a hundred times and your browser has cached its way past the warning — or because the malware deliberately hides from logged-in users.
- Traffic does not taper off, it stops. Analytics goes flat within hours, and if you sell online, so do the orders.
If you have Google Search Console set up for the domain, there will be a message in there under Security & Manual Actions → Security Issues, and that message is the single most useful thing you have. It names the category of problem and lists sample URLs.
Why it happens
Google Safe Browsing crawls the web looking for pages that attack or mislead visitors. When it finds one on your domain, it flags the domain. For an ordinary business website that has done nothing wrong, the cause is nearly always one of these:
- Injected phishing pages. Someone has uploaded a fake bank or webmail login page into a folder on your hosting. Your site is being used as free hosting for someone else's scam, and Google flags the whole domain for it.
- Malicious code in your pages. A script added to your theme, plugins or database that pushes visitors towards malware downloads or scam sites.
- An injected redirect. Visitors arriving from search get bounced somewhere else, while direct visitors see the normal site.
- A forgotten install in a subfolder. An old WordPress, a staging copy in
/dev/, a demo left in/old/. Nobody has updated it in six years and it is the way in. - A third-party script that went bad. An ad network, a chat widget or a tracking script whose provider was compromised. Rare, but it does happen, and it flags you even though your own files are clean.
Almost none of this requires you to have been careless. The most common single cause is an out-of-date plugin with a publicly known vulnerability, found by an automated scanner that was never looking for you specifically.
Safe first steps you can try
None of these can make the situation worse, and all of them help whoever ends up doing the cleanup.
- Take a full backup first — files and database. Even an infected backup is evidence. It tells you what was changed and when, and it is your undo button if a cleanup attempt goes sideways.
- Read the Security Issues report in Search Console. It names the problem type and gives you sample URLs. Those URLs are where the payload is. If you have never set Search Console up, do it now — verification by DNS record takes a few minutes and you will need it to request the review anyway.
- Look at the sample URLs. Open them in a private browsing window, not your normal one. If a page exists that you did not create, you have found the injected content.
- Sort your files by modification date. In your host's file manager or over FTP, sort the site folder by "last modified", newest first. Files changed on a day you did not touch the site are the ones to look at.
- Check the user list. In WordPress, Users → All Users. An administrator account you did not create is a clear answer. Note it down rather than deleting it immediately — how it got there matters.
- Look in the folders you forgot about. Any subfolder with an old install in it. If you do not need it, it is one of the few things safe to delete outright.
- Rotate credentials. Hosting control panel, FTP/SFTP, database, and every WordPress administrator. Do this even if you find nothing — it costs ten minutes and closes the most common route back in.
Only once you genuinely believe the site is clean do you go back to Search Console and use Request Review. Describe what you found and what you did — a review that explains itself is processed faster than a blank one.
What not to do
- Don't request a review before the site is clean. A failed review does not just waste 72 hours, it makes the next one slower. Request it once, when you mean it.
- Don't restore an old backup and call it done. Restoring rolls the files back — including the out-of-date plugin that let them in. You will be re-infected, often within the week, and now with a compromised site and no recent backup.
- Don't delete files you don't recognise at random. WordPress core has plenty of oddly named files that belong there. Deleting the wrong one turns a hacked site into a hacked site that also does not load.
- Don't change hosts in the middle of it. Moving hosting migrates the infection with it and loses you the server logs that show how it started.
- Don't wait it out. The warning does not expire on its own. Left long enough, the spam pages get indexed, your domain reputation drops, and your business email starts landing in other people's spam folders.
When it's beyond DIY
If Search Console shows security issues and you cannot find what triggered them, if the site keeps getting re-flagged after you clean it, or if you simply cannot afford the days this takes to work through — that is the point to hand it over.
We answer 24/7 and the diagnosis starts the moment you call. You get a fixed quote before any work starts, and if we can't help, the assessment costs nothing. See what emergency hacked website repair involves, or just pick up the phone.
That's 1300 WEB SOS. Emergency Website Rescue starts from $1,500 + GST.
Common Questions
How long does it take for the warning to disappear?
Once the site is genuinely clean and you have requested a review in Search Console, Google normally processes it within about 72 hours, and often inside a day. The clock only starts when the site is actually clean — a review requested on a site that is still infected gets rejected, and you start again.
Will my traffic come back afterwards?
Usually, yes — visitors return as soon as the warning stops appearing, and Google recrawls over the following days. Recovery is slower if the hack ran for months and got thousands of spam pages indexed, because those pages have to be cleared out of the index as well as off the server.
Can I get the warning removed without fixing the site?
No. Google re-scans the site before lifting the warning, so it has to be clean first. Even if you could, removing the warning without removing the cause just means it comes back within days — and a site that keeps getting re-flagged is treated less generously each time.
Want this never to happen again? Protection Plans keep the software updated, monitored and backed up — from $249/month + GST.