Security Problèmes Report

Ce que Recherche Google Console's Security Problèmes report flags — hacked content, malware, and social engineering — how it differs from manual actions, and how to clean up and requête a examiner.

Première publication : 23 juin 2026 · Dernière mise à jour : 3 août 2026 · Advanced
Langues

The Security Problèmes report dans la recherche Google Console flags user-safety problems, pas ranking penalties: hacked content (malware, code, content, or URL injection), deceptive pages, harmful or uncommon downloads, and social engineering (phishing and deceptive content) are tout current problème types, grouped sous hacked content, malware and unwanted software, and social engineering. It's surfaced via Google Safe Browsing — affected sites peut montrer a 'Ce site may be hacked' étiquette in results or a red 'Deceptive site ahead' interstitial in Chrome and autre navigateurs, though pas every problème blocks every surface the même façon. It n’est pas the même as a manual action: Manual Actions mostly concern attempts to manipulate Google's index (usually aucun visible warning); Security Problèmes concern hacking or utilisateur harm (peut montrer étiquettes or interstitials) — separate reports, separate examiner queues, and ils peut overlap. Vous clair it by fixing the vulnerability à travers every affected page, alors requesting a security examiner — current guidance dit examiner peut prendre anywhere from a few days to a few weeks, and a réussi examiner doesn't guarantee every navigateur or search surface clears at une fois.

TL;DR — The Security Problèmes report flags user-safety problems, pas ranking penalties. Google groupes les sous hacked content (malware, code, content, or URL injection — SQL injection is a courant méthode), malware and unwanted software (qui peut be installed by a hacker or le site owner), and social engineering (phishing and deceptive content) — but the current report aussi listes plus spécifique problèmes comme deceptive pages, harmful and “uncommon” downloads, and unclear mobile billing prompts. Sample URLs are exemples, pas a complet liste — some problèmes montrer none at tout. Warning surfaces are separate signals (a Search étiquette, a Chrome interstitial, a download warning) and don’t toujours déplacer ensemble — an uncommon-download warning, pour instance, peut apparaître in Chrome sans removing lune page from Search. Fix the vulnerability, pas simplement the symptom, à travers every affected page, alors Requête Examiner une fois; Google’s current guidance is a few days to a few weeks to traiter, with aucun guarantee every navigateur or search surface clears simultaneously. Ce is pas a manual action: Manual Actions mostly concern search-index manipulation (usually aucun visible warning), pendant que Security Problèmes concern hacking or utilisateur harm (peut montrer étiquettes or interstitials) — separate reports, separate examiner queues, and ils peut overlap.

Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report Evidence for this claim Site owners should fix the issue across the site and request a security review; security reviews are separate from manual-action reconsideration requests. Scope: Current Google hacked-site recovery and review workflow. Confidence: high · Verified: Google Search Central: Request a security review

Ce que the report en réalité is

The Security Problèmes report sits dans la recherche Google Console alongside the performances, indexation, and enhancement reports. Google’s framing is à propos de utilisateur safety, and que unique fact is the la plupart utile mental model on ce page. As Google puts it in its description of the difference from manual actions, the report “listes indications que votre site was hacked, or behavior on votre site que pourrait potentially harm a visitor or leur computer.” It n’est pas a verdict on votre SEO.

The problème categories Google flags

Google groupes everything sous three top-level headings in its propre documentation, but that’s an organizing frame, pas the complet liste of problème types the report peut en réalité montrer vous. Treat the three headings ci-dessous as buckets, and the current problème liste beneath les as ce que to expect En pratique.

1. Hacked content. Google’s propre definition: “Ce is quelconque content placed on votre site sans votre permission parce que of security vulnerabilities in votre site.” The current report peut flag several spécifique problèmes sous ce heading, notamment:

  • Code injection“A hacker has compromised votre site and is injecting malicious code in votre pages.”
  • Content injection“A hacker has ajouté spammy liens or text to votre site’s pages.”
  • URL injection“A hacker has créé nouveau pages on votre site, souvent containing spammy words or liens.”
  • Hacked malware — malicious code or fichiers placed on le site via the même kind of unauthorized accès as the injection types ci-dessus.

SQL injection is the courant méthode behind ces — a hacker exploits a database requête vulnerability to insert content or code. The étiquettes ci-dessus are ce que the report montre vous; SQL injection is un of the façons the attacker got in.

2. Malware and unwanted software. Google distinguishes the two. Malware is “quelconque software or mobile application specifically designed to harm a computer, a mobile device, the software it’s running, or its utilisateurs.” Unwanted software is “an executable fichier or mobile application que engages in behavior que is deceptive, unexpected, or que negatively affecte the user’s browsing or computing experience.” Importantly, ce category isn’t seulement a third-party hack: malware or unwanted software on a site peut be installed by a hacker or by le site owner (la plupart souvent unknowingly, via a compromised plugin, theme, or ad script). The report aussi separates:

  • Harmful downloads — fichiers Google Safe Browsing believes are malware or unwanted software que a visitor is prompted to download.
  • Uncommon downloads — a download Safe Browsing simply hasn’t seen suffisant of to vouch pour yet; ce peut trigger a Chrome download warning même though the page itself isn’t necessarily malicious (plus on the warning-surface distinction ci-dessous).

Confirmer the exact current étiquette wording contre votre propre report — Google has adjusted ces étiquettes over temps.

3. Social engineering. Google: “A social engineering attack is quand a web utilisateur is tricked into doing something dangerous online.” Sub-types inclure:

  • Phishing“Le site tricks utilisateurs into revealing leur personal information (Par exemple, passwords, phone numbers, or social security numbers).” Google’s current report peut aussi flag suspected phishing pages detected specifically autour login flows.
  • Deceptive content / deceptive pages — content que tries to trick vous into doing something you’d seulement do pour a trusted entity, tel as sharing a password, appel tech prise en charge, or downloading software — notamment deceptive embedded resources (ads or widgets) on an sinon legitimate page.
  • Unclear mobile billing — a subscription or billing flow, usually on mobile, que doesn’t clearly disclose price or terms avant charging the utilisateur.

Operating a site on behalf of un autre party sans making que relationship clair peut aussi be flagged as social engineering — worth knowing si vous run white-label or affiliate pages.

Où the warning montre up — and pourquoi Safe Browsing matters

Affected pages don’t simplement sink in rankings. Google: “Pages or sites affected by a security problème peut apparaître with a warning étiquette in résultats de recherche or an interstitial warning page in le navigateur quand a utilisateur tries to visit les.”

Two surfaces, alors:

  • In Search, hacked sites peut montrer a “This site may be hacked” étiquette sous le résultat.
  • In le navigateur, Chrome may montrer a full-page interstitial. Google: “Si Google detects que votre website contient social engineering content, the Chrome navigateur may afficher a ‘Deceptive site ahead’ warning quand visitors view votre site.” Malware triggers a similaire “the site ahead contains malware” interstitial.
Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report

Le navigateur warnings are powered by Google Safe Browsing, and that’s the partie personnes miss. Firefox, Safari, and autre navigateurs consume the Safe Browsing API, so the red warning peut apparaître à travers navigateurs — pas simplement in Chrome, and pas seulement via Search Console.

Don’t assume every problème type produces every warning, or que surfaces déplacer in lockstep. Search warning étiquettes, navigateur interstitials, Chrome’s download warnings, and si une page peut apparaître in Search at tout are separate, independently-updated signals. A bon exemple: an uncommon-download warning peut montrer up as a Chrome download prompt sans necessarily preventing lune page itself from appearing dans la recherche Google — it’s pas the même as a complet interstitial or a de-indexing. Parce que ces surfaces mettre à jour independently, and Safe Browsing behavior peut aussi depend on browsing context, treat the Security Problèmes report itself as the authoritative record of ce que Google has recorded and fixed pour votre site — don’t assume a warning vous personally can’t reproduce in un navigateur signifie nothing is incorrect, and don’t assume clearing the report signifie every consuming navigateur or product has caught up yet.

Evidence for this claim Search warning labels and browser interstitial/download warnings are separate surfaces. Not every issue blocks Search: uncommon-download warnings, for example, can appear in Chrome without preventing the page or site from appearing in Google Search. Scope: web UI and Google Search reporting Confidence: high · Verified: Security issues report

Security Problèmes vs. Manual Actions

Ce is the distinction que trips up the la plupart personnes, so let’s utiliser Google’s propre boundary plutôt que a simplified causer split.

Security ProblèmesManual Actions
Ce que cela signifieSite is hacked, or hosts content/behavior que pourrait harm a visitorA reviewer determined le site attempted to manipulate Google’s search index
Typical causerHacking, deceptive content, or malware/unwanted software — qui peut be installed by a hacker or, parfois unknowingly, by le site ownerVotre propre SEO practices (unnatural liens, contenu pauvre, cloaking, sneaky redirections)
Type of problemUtilisateur safetySearch-index manipulation
User-facing warningPeut montrer a Search étiquette or a navigateur interstitialUsually aucun visible warning — affected pages are simplement ranked lower or omitted
ReportSecurity Problèmes reportManual Actions report
Examiner queueSecurity examinerManual-action reconsideration

Ils are separate reports with separate examiner queues — a site peut have un, les deux, or neither, and it’s possible pour the two to overlap (a hacked page que obtient stuffed with spammy liens, Par exemple, pourrait eventually surface in les deux reports). Don’t reduce ce to “someone else hacked me” versus “I did my propre spam” — the réel dividing line Google draws is ce que the report is protecting contre (utilisateurs, versus the integrity of the search index), pas who caused it.

Triage and remediation

Front-load the triage; comprendre the categories second.

  1. Confirmer it in the report. Lire exactly qui category and qui sample URLs Google listes — but treat ceux URLs as exemples, pas a complet inventory. Google is explicit que the liste isn’t necessarily complet, and some problèmes peut montrer aucun sample URLs at tout, qui doesn’t mean nothing is affected. Utiliser URL Inspection on the samples to voir ce que Google en réalité récupéré, alors regarder pour the même vulnerability or injected pattern elsewhere on le site.
  2. Limite the damage. Selon severity, prendre le site (or the affected section) offline or behind maintenance mode so vous arrêter serving malware or phishing to réel utilisateurs pendant que vous fonctionner. Éviter directement opening a suspected infected page in a normal navigateur — some attacks cloak content fondé on browsing context, so ce que vous voir may pas match ce que Google recorded; utiliser isolated tooling (a scanner, a sandboxed environment, or Inspection d’URL) à la place.
  3. Trouver and supprimer the injected content. Spam pages, injected scripts, rogue admin accounts, modified core fichiers.
  4. Fermer the vulnerability. Ce is the step que decides si votre examiner passes. Patch the out-of-date plugin/CMS, rotate credentials, fix the insecure directory or the input que allowed the injection. Supprimer the symptom and the entry point, or vous obtenir reinfected and the examiner fails.
  5. Handle the leftover indexé URLs. Injected spam pages que got indexé devrait retourner 404 or 410 so Google drops les over temps (410 is a touch faster as a signal). Don’t leave les resolving with a 200.
  6. CMS notes. On WordPress, the usual suspects are outdated plugins/themes and weak admin credentials — mettre à jour everything, audit utilisateurs, and considérer a security plugin scan. On autre stacks, the principle is identical même si the tooling isn’t: patch, rotate, and fermer the input que was exploited.

Requesting a security examiner

Une fois every flagged problème is fixed à travers tout pages, utiliser Requête Examiner in the report. Google: “Quand tout problèmes listed in the report are fixed in tout pages, select Requête Examiner in the Security Problèmes report.”

Document ce que vous did. Google demande vous to “provide plus information on ce que vous did to clean votre site. Pour chaque category of hacked spam, inclure a brief explanation of how le site was cleaned.” Google’s own example of good wording: “Pour Content injection hacked URLs, I supprimé the spam content and corrected the vulnerability by updating an out-of-date plugin.” Remarque how it noms les deux the cleanup and the closed hole.

On timing: Google’s current guidance is que a security examiner peut prendre anywhere from a few days to a few weeks to traiter. Précédent guidance (publié separately from the report’s propre documentation) broke ce bas by problème type — phishing faster, hacked-spam cas slower — and promised warnings clair dans 72 hours of approval. Que per-type breakdown and the fixed 72-hour figure ne sont pas ce que the report’s current documentation states, so treat les as outdated plutôt que a schedule vous pouvez rely on. What’s consistent: the warning fait pas disappear the instant vous fix choses — it clears seulement après the examiner passes, and même alors propagation à travers every navigateur, résultat de recherche, and Google product isn’t instant or guaranteed to se produire at the même moment everywhere. A réussi examiner aussi isn’t a promise of restored rankings, trafic, or AI-search visibility — ceux are separate outcomes the examiner traiter doesn’t cover.

A few rules of the road: submit une fois, entièrement fixed and documented — re-submitting avant you’ve en réalité closed everything simplement wastes a examiner cycle. Don’t définir a hard internal deadline autour a spécifique number of hours or days; monitor the report and votre site’s status au lieu de repeatedly resubmitting.

Preventing reinfection

The cleanup is seulement half the job. Garder CMS core, plugins, and themes patched; enforce least-privilege on accounts and rotate quelconque credentials que may have leaked; turn on 2FA pour admin logins; monitor pour unexpected nouveau fichiers or utilisateurs; and periodically vérifier votre site’s status in Google’s Safe Browsing site-status outil. The vulnerability que let les in the premier temps is the un they’ll essayer à nouveau.

Add an expert note

Pin an expert quote

New person? Create their unclaimed profile at /admin/experts/ → Pin a quote first.