Remove a Google security warning
Clean the complete compromise and close the entry point before requesting a review
Google Search Console’s Security issues report is the source of truth for a warning on a verified site. Review the issue type and sample URLs, preserve evidence, clean every affected area and fix the vulnerable password, account or software that allowed the compromise.
How do I recover a site flagged by Google?
- 1Open Security issues
Verify ownership in Search Console, check for unknown owners and record each listed issue type and sample URL.
- 2Protect evidence and access
Save useful logs, change compromised credentials from a clean device and remove unfamiliar administrators or access keys.
- 3Clean the whole site
Remove injected pages, redirects, scripts, downloads and backdoors. Restore known-good files where appropriate and check databases and scheduled tasks.
- 4Fix the cause
Update the CMS and extensions, remove abandoned software, correct permissions and secure every account that could reintroduce the problem.
How do I request a Google review?
Test the reported URLs
Confirm the harmful content, redirect or download is gone and that the pages now return the intended result.
Check beyond the samples
Google may show only examples. Search files, database content, users and indexed pages for related compromise.
Explain the repair
Describe what was compromised, what you removed and how the original access route was secured.
Submit once
Use the review control in Search Console. Review timing varies, so do not promise a same-day removal or repeatedly resubmit.
Why can the browser warning remain after a clean review?
Search Console, Safe Browsing data and browser caches are separate systems. Status changes can take time to appear everywhere. Confirm the Search Console result, test the exact hostname and URL, and avoid making unrelated DNS or certificate changes while waiting.
Reduce the chance of another warning
Update applications and extensions promptly.
Remove unused accounts, plugins, themes and old test sites.
Use unique passwords and multi-factor authentication where available.
Keep tested off-site backups and monitor unexpected file changes.
Review Search Console messages and security reports regularly.
Need recovery help?
Send the warning type, sample URL and incident time
Do not include passwords in the ticket.