Panduan Security Issues Report
What Google Search Console's Security Issues report flags — hacked konten, malware, dan social engineering — how ini differs dari manual tindakan, dan cara clean up dan permintaan sebuah review.
Bahasa
Security Issues report di Google Search Console flags pengguna-safety masalah, not peringkat penalties: hacked konten (malware, code, konten, atau URL injection), deceptive halaman, harmful atau uncommon downloads, dan social engineering (phishing dan deceptive konten) adalah semua saat ini issue jenis, grouped di bawah hacked konten, malware dan unwanted software, dan social engineering. ini adalah surfaced melalui Google Safe Browsing — affected situs dapat tampilkan sebuah 'ini situs dapat menjadi hacked' label di hasil atau sebuah red 'Deceptive situs ahead' interstitial di Chrome dan lainnya browser, though not setiap issue blocks setiap surface yang sama cara. ini adalah not yang sama sebagai sebuah manual tindakan: Manual tindakan mostly concern attempts untuk manipulate Google's indeks (biasanya no terlihat warning); Security Issues concern hacking atau pengguna harm (dapat tampilkan labels atau interstitials) — separate reports, separate review queues, dan mereka dapat overlap. Anda jelas ini oleh fixing vulnerability di seluruh setiap affected halaman, lalu requesting sebuah security review — saat ini guidance says review dapat take anywhere dari sebuah few days untuk sebuah few weeks, dan sebuah passed review doesn't guarantee setiap browser atau search surface clears di once.
Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report Evidence for this claim Site owners should fix the issue across the site and request a security review; security reviews are separate from manual-action reconsideration requests. Scope: Current Google hacked-site recovery and review workflow. Confidence: high · Verified: Google Search Central: Request a security reviewTL;DR — Security Issues report di Google Search Console tells Anda when Google thinks Anda situs memiliki telah hacked atau adalah doing something itu dapat hurt pengunjung — like phishing atau spreading malware. ini adalah sebuah safety warning, not sebuah peringkat penalty. Anda fix masalah, lalu tanyakan Google untuk review situs dan jelas warning.
What ini report adalah
Open Google Search Console dan Anda’ll temukan sebuah Security Issues report. sebagian besar dari time ini says “No issues detected” (terjemahan) “No issues detected” — which adalah exactly what Anda ingin. When ini melakukan tampilkan something, Google adalah telling Anda one dari two things: Anda situs memiliki telah hacked, atau Anda situs adalah behaving di sebuah cara itu dapat harm people who visit ini.
itu kedua bagian adalah key idea. ini report adalah tentang pengguna safety, not tentang whether Google likes Anda SEO. ini adalah sebuah completely berbeda thing dari sebuah penalty.
What ini flags
Google groups masalah ke three broad buckets, though actual list dari issue jenis inside them adalah longer daripada sebagian besar people expect:
- Hacked konten — someone broke ke Anda situs dan ditambahkan spam, tautan, atau malicious code without Anda permission.
- Malware dan unwanted software — Anda situs adalah serving software itu dapat harm sebuah pengunjung’s device. ini isn’t selalu someone else’s doing — ini dapat happen karena sebuah compromised plugin Anda installed yourself, not hanya sebuah hacker.
- Social engineering — Anda halaman trick people ke doing something dangerous, like handing di atas sebuah password atau downloading something mereka shouldn’t (ini adalah what “phishing” (terjemahan) “phishing” berarti).
Google’s actual report dapat tampilkan more spesifik labels di dalam itu buckets — things like deceptive halaman, harmful atau “uncommon” (terjemahan) “uncommon” downloads, dan unclear mobile billing prompts. Advanced tab breaks full saat ini list down.
Where Anda’ll pertama notice ini
Anda mungkin see ini sebelum Anda bahkan open Search Console:
- sebuah “This site may be hacked” (terjemahan) “ini situs dapat menjadi hacked” label di bawah Anda listing di Google’s search hasil.
- sebuah full red warning halaman di Chrome — “Deceptive site ahead” (terjemahan) “Deceptive situs ahead” — when someone tries untuk visit. ini sama warning dapat tampilkan up di lainnya browser too, because ini adalah powered oleh sebuah Google sistem called Safe Browsing.
- sebuah email dari Search Console (jika Anda’ve verified Anda situs there).
What untuk melakukan
- Don’t panic, tetapi move fast. warning adalah scaring away pengunjung.
- temukan dan hapus buruk stuff — injected spam, malicious code, deceptive halaman. Remember URLs listed di report adalah hanya contoh, not sebuah full list — beberapa issues dapat tampilkan no sample URLs di semua, which tidak berarti nothing adalah affected.
- Close hole ini came di melalui. ini adalah bagian people skip. jika Anda hanya delete spam tetapi leave out-dari-date plugin atau weak password itu let ini happen, ini’ll come right back — dan Anda review akan fail.
- permintaan sebuah review inside report once everything adalah fixed. Google currently says sebuah review dapat take anywhere dari sebuah few days untuk sebuah few weeks — there’s no fixed one-day atau 72-hour guarantee, dan sebuah passed review doesn’t berarti setiap browser dan search hasil clears di exact sama moment.
thing sebagian besar people get wrong
sebuah security issue adalah not yang sama sebagai sebuah manual tindakan. sebuah manual tindakan adalah when Google’s team decides Anda situs attempted untuk manipulate -nya search indeks — biasanya dengan no terlihat warning untuk pengunjung. sebuah security issue berarti Anda situs adalah hacked, hosts deceptive konten, atau menyajikan malware/unwanted software itu dapat harm sebuah pengunjung — dan ini adalah one itu dapat tampilkan sebuah warning label atau sebuah red browser interstitial. berbeda report, berbeda review queue, dan ini adalah mungkin untuk memiliki one, both, atau neither. ingin full saat ini issue list dan what “request a review” (terjemahan) “permintaan sebuah review” actually guarantees? Switch untuk Advanced tab.
Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report Evidence for this claim Site owners should fix the issue across the site and request a security review; security reviews are separate from manual-action reconsideration requests. Scope: Current Google hacked-site recovery and review workflow. Confidence: high · Verified: Google Search Central: Request a security reviewTL;DR — Security Issues report flags pengguna-safety masalah, not peringkat penalties. Google groups them di bawah hacked konten (malware, code, konten, atau URL injection — SQL injection adalah sebuah umum metode), malware dan unwanted software (which dapat menjadi installed oleh sebuah hacker atau situs owner), dan social engineering (phishing dan deceptive konten) — tetapi saat ini report juga lists more spesifik issues like deceptive halaman, harmful dan “uncommon” (terjemahan) “uncommon” downloads, dan unclear mobile billing prompts. Sample URLs adalah contoh, not sebuah complete list — beberapa issues tampilkan none di semua. Warning surfaces adalah separate signals (sebuah Search label, sebuah Chrome interstitial, sebuah download warning) dan don’t selalu move together — sebuah uncommon-download warning, misalnya, dapat appear di Chrome tanpa menghapus halaman dari Search. Fix vulnerability, not hanya symptom, di seluruh setiap affected halaman, lalu permintaan Review once; Google’s saat ini guidance adalah sebuah few days untuk sebuah few weeks untuk process, dengan no guarantee setiap browser atau search surface clears simultaneously. ini adalah not sebuah manual tindakan: Manual tindakan mostly concern search-indeks manipulation (biasanya no terlihat warning), while Security Issues concern hacking atau pengguna harm (dapat tampilkan labels atau interstitials) — separate reports, separate review queues, dan mereka dapat overlap.
What report actually adalah
Security Issues report sits di Google Search Console alongside performa, pengindeksan, dan enhancement reports. Google’s framing adalah tentang pengguna safety, dan itu single fact adalah paling berguna mental model pada ini halaman. sebagai Google puts ini di -nya deskripsi dari difference dari manual tindakan, report “lists indications that your site was hacked, or behavior on your site that could potentially harm a visitor or their computer.” (terjemahan) “lists indications itu Anda situs adalah hacked, atau perilaku pada Anda situs itu dapat potentially harm sebuah pengunjung atau mereka computer.” ini adalah not sebuah verdict pada Anda SEO.
issue categories Google flags
Google groups everything di bawah three top-tingkat heading di -nya own documentation, tetapi itu’s sebuah organizing frame, not full list dari issue jenis report dapat actually tampilkan Anda. Treat three heading below sebagai buckets, dan saat ini issue list beneath them sebagai what untuk expect dalam praktik.
1. Hacked konten. Google’s own definition: “This is any content placed on your site without your permission because of security vulnerabilities in your site.” (terjemahan) “ini adalah apa pun konten placed pada Anda situs without Anda permission karena security vulnerabilities di Anda situs.” saat ini report dapat flag several spesifik issues di bawah ini heading, including:
- Code injection — “A hacker has compromised your site and is injecting malicious code in your pages.” (terjemahan) “sebuah hacker memiliki compromised Anda situs dan adalah injecting malicious code di Anda halaman.”
- konten injection — “A hacker has added spammy links or text to your site’s pages.” (terjemahan) “sebuah hacker memiliki ditambahkan spammy tautan atau text untuk Anda situs’s halaman.”
- URL injection — “A hacker has created new pages on your site, often containing spammy words or links.” (terjemahan) “sebuah hacker memiliki dibuat baru halaman pada Anda situs, sering containing spammy kata atau tautan.”
- Hacked malware — malicious code atau files placed pada situs melalui sama jenis dari tidak terotorisasi access sebagai injection jenis above.
SQL injection adalah umum metode behind ini — sebuah hacker exploits sebuah database kueri vulnerability untuk insert konten atau code. labels above adalah what report menampilkan Anda; SQL injection adalah one dari cara attacker got di.
2. Malware dan unwanted software. Google distinguishes two. Malware adalah “any software or mobile application specifically designed to harm a computer, a mobile device, the software it’s running, or its users.” (terjemahan) “apa pun software atau mobile application specifically designed untuk harm sebuah computer, sebuah perangkat seluler, software ini adalah running, atau -nya pengguna.” Unwanted software adalah “an executable file or mobile application that engages in behavior that is deceptive, unexpected, or that negatively affects the user’s browsing or computing experience.” (terjemahan) “sebuah executable file atau mobile application itu engages di perilaku itu adalah deceptive, unexpected, atau itu negatively affects pengguna’s browsing atau computing experience.” Importantly, ini category isn’t hanya sebuah ketiga-party hack: malware atau unwanted software pada sebuah situs dapat menjadi installed oleh sebuah hacker atau oleh situs owner (sebagian besar sering unknowingly, via sebuah compromised plugin, theme, atau ad script). report juga separates:
- Harmful downloads — files Google Safe Browsing believes adalah malware atau unwanted software itu sebuah pengunjung adalah prompted untuk download.
- Uncommon downloads — sebuah download Safe Browsing simply hasn’t seen enough dari untuk vouch untuk yet; ini dapat trigger sebuah Chrome download warning bahkan though halaman itself isn’t necessarily malicious (more pada warning-surface distinction below).
Confirm exact saat ini label wording terhadap Anda own report — Google memiliki adjusted ini labels di atas time.
3. Social engineering. Google: “A social engineering attack is when a web user is tricked into doing something dangerous online.” (terjemahan) “sebuah social engineering attack adalah when sebuah web pengguna adalah tricked ke doing something dangerous online.” Sub-jenis sertakan:
- Phishing — “The site tricks users into revealing their personal information (for example, passwords, phone numbers, or social security numbers).” (terjemahan) “ situs tricks pengguna ke revealing mereka personal informasi (misalnya, passwords, phone angka, atau social security angka).” Google’s saat ini report dapat juga flag suspected phishing halaman detected specifically sekitar login flows.
- Deceptive konten / deceptive halaman — konten itu tries untuk trick Anda ke doing something Anda’d hanya melakukan untuk sebuah trusted entity, such sebagai sharing sebuah password, calling tech mendukung, atau downloading software — including deceptive embedded resources (ads atau widgets) pada sebuah otherwise legitimate halaman.
- Unclear mobile billing — sebuah subscription atau billing flow, biasanya pada mobile, itu doesn’t clearly disclose price atau istilah sebelum charging pengguna.
Operating sebuah situs pada behalf dari lainnya party without membuat itu relationship jelas dapat juga menjadi flagged sebagai social engineering — worth knowing jika Anda run white-label atau affiliate halaman.
Where warning menampilkan up — dan why Safe Browsing penting
Affected halaman don’t hanya sink di rankings. Google: “Pages or sites affected by a security issue can appear with a warning label in search results or an interstitial warning page in the browser when a user tries to visit them.” (terjemahan) “halaman atau situs affected oleh sebuah security issue dapat appear dengan sebuah warning label di hasil pencarian atau sebuah interstitial warning halaman di browser when sebuah pengguna tries untuk visit them.”
Two surfaces, lalu:
- di Search, hacked situs dapat tampilkan sebuah “This site may be hacked” (terjemahan) “ini situs dapat menjadi hacked” label di bawah hasil.
- di browser, Chrome dapat tampilkan sebuah full-halaman interstitial. Google: “If Google detects that your website contains social engineering content, the Chrome browser may display a ‘Deceptive site ahead’ warning when visitors view your site.” (terjemahan) “jika Google detects itu Anda situs web berisi social engineering konten, Chrome browser dapat display sebuah ‘Deceptive situs ahead’ warning when pengunjung view Anda situs.” Malware triggers sebuah similar “the site ahead contains malware” (terjemahan) “ situs ahead berisi malware” interstitial.
browser warnings adalah powered oleh Google Safe Browsing, dan itu’s bagian people miss. Firefox, Safari, dan lainnya browser consume Safe Browsing API, so red warning dapat appear di seluruh browser — not hanya di Chrome, dan not hanya via Search Console.
Don’t assume setiap issue jenis produces setiap warning, atau itu surfaces move di lockstep. Search warning labels, browser interstitials, Chrome’s download warnings, dan whether sebuah halaman dapat appear di Search di semua adalah separate, independently-updated signals. sebuah baik contoh: sebuah uncommon-download warning dapat tampilkan up sebagai sebuah Chrome download prompt without necessarily preventing halaman itself dari appearing di Google Search — ini adalah not yang sama sebagai sebuah full interstitial atau sebuah de-pengindeksan. Because ini surfaces update independently, dan Safe Browsing perilaku dapat juga depend pada browsing context, treat Security Issues report itself sebagai authoritative record dari what Google memiliki recorded dan fixed untuk Anda situs — don’t assume sebuah warning Anda personally dapat’t reproduce di one browser berarti nothing adalah wrong, dan don’t assume clearing report berarti setiap consuming browser atau product memiliki caught up yet.
Evidence for this claim Search warning labels and browser interstitial/download warnings are separate surfaces. Not every issue blocks Search: uncommon-download warnings, for example, can appear in Chrome without preventing the page or site from appearing in Google Search. Scope: web UI and Google Search reporting Confidence: high · Verified: Security issues reportSecurity Issues vs. Manual tindakan
ini adalah distinction itu trips up paling people, so let’s gunakan Google’s own boundary alih-alih sebuah simplified cause split.
| Security Issues | Manual tindakan | |
|---|---|---|
| What ini berarti | situs adalah hacked, atau hosts konten/perilaku itu dapat harm sebuah pengunjung | sebuah reviewer determined situs attempted untuk manipulate Google’s search indeks |
| Typical cause | Hacking, deceptive konten, atau malware/unwanted software — which dapat menjadi installed oleh sebuah hacker atau, sometimes unknowingly, oleh situs owner | Anda own SEO practices (unnatural tautan, thin konten, cloaking, sneaky redirects) |
| jenis dari masalah | pengguna safety | Search-indeks manipulation |
| pengguna-facing warning | dapat tampilkan sebuah Search label atau sebuah browser interstitial | biasanya no terlihat warning — affected halaman adalah hanya diperingkatkan lower atau omitted |
| Report | Security Issues report | Manual tindakan report |
| Review queue | Security review | Manual-tindakan reconsideration |
mereka adalah separate reports dengan separate review queues — sebuah situs dapat memiliki one, both, atau neither, dan ini adalah mungkin untuk two untuk overlap (sebuah hacked halaman itu gets stuffed dengan spammy tautan, misalnya, dapat eventually surface di both reports). Don’t reduce ini untuk “someone else hacked me” (terjemahan) “someone else hacked me” versus “I did my own spam” (terjemahan) “I melakukan my own spam” — nyata dividing line Google draws adalah what report adalah protecting terhadap (pengguna, versus integrity dari search indeks), not who caused ini.
Triage dan remediation
Front-muat triage; memahami categories kedua.
- Confirm ini di report. Read exactly which category dan which sample URLs Google lists — tetapi treat itu URLs sebagai contoh, not sebuah full inventory. Google adalah explicit itu list isn’t necessarily complete, dan beberapa issues dapat tampilkan no sample URLs di semua, which tidak berarti nothing adalah affected. gunakan URL Inspection pada samples untuk see what Google actually fetched, lalu cari yang sama vulnerability atau injected pattern elsewhere pada situs.
- Limit damage. Depending pada severity, take situs (atau affected bagian) offline atau behind maintenance mode so Anda stop serving malware atau phishing untuk pengguna nyata while Anda berfungsi. hindari directly opening sebuah suspected infected halaman di sebuah normal browser — beberapa attacks cloak konten berdasarkan browsing context, so what Anda see dapat not match what Google recorded; gunakan isolated tooling (sebuah scanner, sebuah sandboxed environment, atau pemeriksaan URL) instead.
- temukan dan hapus injected konten. Spam halaman, injected scripts, rogue admin accounts, modified core files.
- Close vulnerability. ini adalah langkah itu decides whether Anda review passes. Patch out-dari-date plugin/CMS, rotate credentials, fix insecure directory atau input itu allowed injection. hapus symptom dan entry poin, atau Anda get reinfected dan review fails.
- Handle leftover terindeks URLs. Injected spam halaman itu got terindeks
seharusnya kembalikan 404 atau 410 so Google drops them di atas time (410 adalah sebuah touch
faster sebagai sebuah signal). Don’t leave them resolving dengan sebuah
200. - CMS notes. pada WordPress, usual suspects adalah outdated plugins/themes dan weak admin credentials — update everything, audit pengguna, dan pertimbangkan sebuah security plugin scan. pada lainnya stacks, principle adalah identical bahkan jika tooling isn’t: patch, rotate, dan close input itu adalah exploited.
Requesting sebuah security review
Once setiap flagged issue adalah fixed di seluruh semua halaman, gunakan permintaan Review di report. Google: “When all issues listed in the report are fixed in all pages, select Request Review in the Security Issues report.” (terjemahan) “When semua issues listed di report adalah fixed di semua halaman, select permintaan Review di Security Issues report.”
Document what Anda melakukan. Google menanyakan Anda untuk “provide more information on what you did to clean your site. For each category of hacked spam, include a brief explanation of how the site was cleaned.” (terjemahan) “menyediakan more informasi pada what Anda melakukan untuk clean Anda situs. untuk setiap category dari hacked spam, sertakan sebuah brief explanation dari how situs adalah cleaned.” Google’s own contoh dari baik wording: “For Content injection hacked URLs, I removed the spam content and corrected the vulnerability by updating an out-of-date plugin.” (terjemahan) “untuk konten injection hacked URLs, I dihapus spam konten dan corrected vulnerability oleh updating sebuah out-dari-date plugin.” Note how ini names both cleanup dan closed hole.
pada timing: Google’s saat ini guidance adalah itu sebuah security review dapat take anywhere dari sebuah few days untuk sebuah few weeks untuk process. Earlier guidance (published separately dari report’s own documentation) broke ini down oleh issue jenis — phishing faster, hacked-spam cases slower — dan promised warnings jelas di dalam 72 hours dari approval. itu per-jenis breakdown dan fixed 72-hour figure adalah not what report’s saat ini documentation states, so treat them sebagai outdated alih-alih sebuah schedule Anda dapat rely pada. What’s consistent: warning melakukan not disappear instant Anda fix things — ini clears hanya setelah review passes, dan bahkan lalu propagation di seluruh setiap browser, search hasil, dan Google product isn’t instant atau guaranteed untuk happen di yang sama moment everywhere. sebuah passed review juga isn’t sebuah promise dari restored rankings, traffic, atau AI-search visibilitas — itu adalah separate outcomes review process doesn’t cover.
sebuah few aturan dari road: submit once, fully fixed dan documented — re-submitting sebelum Anda’ve actually closed everything hanya wastes sebuah review cycle. Don’t set sebuah hard internal deadline sekitar sebuah spesifik angka dari hours atau days; monitor report dan Anda situs’s status alih-alih repeatedly resubmitting.
Preventing reinfection
cleanup adalah hanya half job. pertahankan CMS core, plugins, dan themes patched; enforce least-privilege pada accounts dan rotate apa pun credentials itu dapat memiliki leaked; turn pada 2FA untuk admin logins; monitor untuk unexpected baru files atau pengguna; dan periodically periksa Anda situs’s status di Google’s Safe Browsing situs-status alat. vulnerability itu let them di pertama time adalah one mereka’ll try again.
AI summary
sebuah condensed take pada Advanced versi:
- ** report adalah tentang pengguna safety, not rankings.** ini flags itu Anda situs adalah hacked atau hosts konten/perilaku itu dapat harm pengunjung — sebuah berbeda animal dari sebuah peringkat penalty.
- More daripada three sederhana buckets. Google groups issues di bawah hacked konten, malware & unwanted software, dan social engineering, tetapi saat ini report dapat tampilkan more spesifik labels — code/konten/URL injection, deceptive halaman, harmful dan uncommon downloads, unclear mobile billing, dan suspected phishing sekitar login flows. Malware atau unwanted software dapat menjadi installed oleh sebuah hacker atau situs owner (sering unknowingly).
- Sample URLs adalah contoh, not sebuah full list. beberapa issues dapat tampilkan none di semua — itu tidak berarti nothing’s affected. Investigate shared vulnerability, not hanya listed samples.
- Warning surfaces adalah separate, independently-updated signals. sebuah Search label, sebuah Chrome interstitial, dan sebuah download warning don’t selalu move together — sebuah uncommon-download warning, misalnya, dapat appear tanpa menghapus halaman dari Search. Treat report itself sebagai sumber kebenaran untuk what Google memiliki recorded.
- Not sebuah manual tindakan. Manual tindakan mostly concern search-indeks manipulation, biasanya dengan no terlihat warning; Security Issues concern hacking atau pengguna harm dan dapat tampilkan labels atau interstitials. Separate reports, separate review queues — dan mereka dapat overlap.
- Fix vulnerability, not hanya symptom. hapus injected konten dan close entry poin di seluruh setiap halaman, atau Anda get reinfected dan review fails. kembalikan 404/410 pada leftover terindeks spam URLs.
- permintaan Review once, fully fixed, dengan per-category notes pada what Anda cleaned dan how Anda closed hole.
- Timing: saat ini guidance adalah sebuah few days untuk sebuah few weeks untuk process — not older per-jenis atau 72-hour promises. sebuah passed review doesn’t guarantee setiap browser/product clears simultaneously atau itu rankings, traffic, atau AI-search visibilitas recover.
Official documentation
Primary-source documentation dari Google.
- Security Issues report — report itself: categories, hacked-konten subtypes, dan permintaan Review flow.
- Manual tindakan report — separate report, dengan bagian explaining how ini differs dari security issues.
- Social Engineering (Phishing dan Deceptive situs) — phishing, deceptive konten, dan “Deceptive site ahead” (terjemahan) “Deceptive situs ahead” warning.
- Malware dan unwanted software — definitions Google menggunakan untuk separate two.
- Why adalah my situs labeled sebagai dangerous di Google Search? — pengguna-facing explanation dari warnings.
- permintaan sebuah review (web.dev / Search Central) — what untuk document per category, contoh wording, dan per-jenis review timelines.
Quotes dari source
pada—record statements dari Google’s documentation. setiap tautan adalah sebuah deep tautan itu jumps untuk quoted passage pada source halaman.
Google — what report covers
- “This is any content placed on your site without your permission because of security vulnerabilities in your site.” (terjemahan) “ini adalah apa pun konten placed pada Anda situs without Anda permission karena security vulnerabilities di Anda situs.” (Hacked konten) Jump untuk quote
- “This is software that is designed to harm a device or its users, that engages in deceptive or unexpected practices, or that negatively affects the user.” (terjemahan) “ini adalah software itu adalah designed untuk harm sebuah device atau -nya pengguna, itu engages di deceptive atau unexpected practices, atau itu negatively affects pengguna.” (Malware dan unwanted software) Jump untuk quote
- “This is content that tricks visitors into doing something dangerous, such as revealing confidential information or downloading software.” (terjemahan) “ini adalah konten itu tricks pengunjung ke doing something dangerous, such sebagai revealing confidential informasi atau downloading software.” (Social engineering) Jump untuk quote
Google — hacked-konten subtypes
- “A hacker has compromised your site and is injecting malicious code in your pages.” (terjemahan) “sebuah hacker memiliki compromised Anda situs dan adalah injecting malicious code di Anda halaman.” (Code injection) Jump untuk quote
- “A hacker has added spammy links or text to your site’s pages.” (terjemahan) “sebuah hacker memiliki ditambahkan spammy tautan atau text untuk Anda situs’s halaman.” (konten injection) Jump untuk quote
- “A hacker has created new pages on your site, often containing spammy words or links.” (terjemahan) “sebuah hacker memiliki dibuat baru halaman pada Anda situs, sering containing spammy kata atau tautan.” (URL injection) Jump untuk quote
Google — how pengguna see warning
- “Pages or sites affected by a security issue can appear with a warning label in search results or an interstitial warning page in the browser when a user tries to visit them.” (terjemahan) “halaman atau situs affected oleh sebuah security issue dapat appear dengan sebuah warning label di hasil pencarian atau sebuah interstitial warning halaman di browser when sebuah pengguna tries untuk visit them.” Jump untuk quote
- “If Google detects that your website contains social engineering content, the Chrome browser may display a ‘Deceptive site ahead’ warning when visitors view your site.” (terjemahan) “jika Google detects itu Anda situs web berisi social engineering konten, Chrome browser dapat display sebuah ‘Deceptive situs ahead’ warning when pengunjung view Anda situs.” Jump untuk quote
Google — malware vs. unwanted software
- “Malware is any software or mobile application specifically designed to harm a computer, a mobile device, the software it’s running, or its users.” (terjemahan) “Malware adalah apa pun software atau mobile application specifically designed untuk harm sebuah computer, sebuah perangkat seluler, software ini adalah running, atau -nya pengguna.” Jump untuk quote
- “Unwanted software is an executable file or mobile application that engages in behavior that is deceptive, unexpected, or that negatively affects the user’s browsing or computing experience.” (terjemahan) “Unwanted software adalah sebuah executable file atau mobile application itu engages di perilaku itu adalah deceptive, unexpected, atau itu negatively affects pengguna’s browsing atau computing experience.” Jump untuk quote
Google — social engineering / phishing
- “A social engineering attack is when a web user is tricked into doing something dangerous online.” (terjemahan) “sebuah social engineering attack adalah when sebuah web pengguna adalah tricked ke doing something dangerous online.” Jump untuk quote
- “The site tricks users into revealing their personal information (for example, passwords, phone numbers, or social security numbers).” (terjemahan) “ situs tricks pengguna ke revealing mereka personal informasi (misalnya, passwords, phone angka, atau social security angka).” (Phishing) Jump untuk quote
Google — requesting sebuah review
- “When all issues listed in the report are fixed in all pages, select Request Review in the Security Issues report.” (terjemahan) “When semua issues listed di report adalah fixed di semua halaman, select permintaan Review di Security Issues report.” Jump untuk quote
- “For each category of hacked spam, include a brief explanation of how the site was cleaned.” (terjemahan) “untuk setiap category dari hacked spam, sertakan sebuah brief explanation dari how situs adalah cleaned.” Jump untuk quote
- “For Content injection hacked URLs, I removed the spam content and corrected the vulnerability by updating an out-of-date plugin.” (terjemahan) “untuk konten injection hacked URLs, I dihapus spam konten dan corrected vulnerability oleh updating sebuah out-dari-date plugin.” (Google’s contoh wording) Jump untuk quote
- “A review can take several days to complete.” (terjemahan) “sebuah review dapat take several days untuk complete.” (Google, Search Central, Social Engineering (Phishing dan Deceptive situs)) — source
Google — Security Issues vs. Manual tindakan
- “The Security Issues report lists indications that your site was hacked, or behavior on your site that could potentially harm a visitor or their computer: for example, phishing attacks or installing malware or unwanted software on the user’s computer.” (terjemahan) “ Security Issues report lists indications itu Anda situs adalah hacked, atau perilaku pada Anda situs itu dapat potentially harm sebuah pengunjung atau mereka computer: misalnya, phishing attacks atau installing malware atau unwanted software pada pengguna’s computer.” Jump untuk quote
Clean-up dan permintaan-review checklist
sebuah pass untuk take Anda dari “flagged” (terjemahan) “flagged” untuk “cleared.” (terjemahan) “cleared.”
Clean up
- Read report dan note exact category dan sample URLs Google lists — treat them sebagai contoh, not sebuah complete inventory (beberapa issues list none).
- Inspect sample URLs (pemeriksaan URL) untuk see what Google actually fetched, lalu search untuk yang sama pattern elsewhere pada situs.
- Take affected situs/bagian offline atau ke maintenance mode jika ini adalah actively serving malware atau phishing.
- hapus injected konten: spam halaman, scripts, rogue files, unknown admin pengguna.
- Close vulnerability — patch CMS/plugin/theme, rotate credentials, fix exploited input atau insecure directory. (Symptom dan entry poin.)
- kembalikan 404 atau 410 pada injected URLs itu got terindeks so Google drops them.
- Re-scan untuk confirm nothing adalah left, lalu verify Anda status di Google’s Safe Browsing situs-status alat.
permintaan review
- Confirm setiap listed issue adalah fixed di seluruh semua affected halaman pertama.
- Click permintaan Review di Security Issues report.
- untuk setiap category, write sebuah brief explanation dari what Anda dihapus dan how Anda closed hole (mirror Google’s contoh wording).
- Submit once — don’t re-submit sebelum Anda’ve actually fixed everything.
- Set expectations pada timing: Google’s saat ini guidance adalah sebuah few days untuk sebuah few weeks untuk process — not sebuah fixed one-day atau 72-hour promise — dan clearing doesn’t guarantee setiap browser/product updates di yang sama moment atau itu rankings/traffic recover.
Security Issues — cheat sheet
** report’s groupings (not sebuah exhaustive list)**
| Category | What ini berarti | Subtypes / notes |
|---|---|---|
| Hacked konten | konten atau code ditambahkan without Anda permission via sebuah vulnerability | Code injection, konten injection, URL injection, hacked malware (SQL injection adalah sebuah umum entry metode) |
| Malware & unwanted software | Software itu harms sebuah device atau behaves deceptively | Web-based malware, harmful downloads, uncommon downloads — dapat menjadi installed oleh sebuah hacker atau situs owner |
| Social engineering | konten itu tricks pengguna ke dangerous tindakan | Phishing (incl. suspected login-halaman phishing), deceptive konten/halaman, unclear mobile billing, undisclosed ketiga-party operation |
Sample URLs listed di bawah apa pun category adalah contoh, not sebuah full inventory — beberapa issues dapat list none di semua.
Where warning appears
| Surface | Warning | Notes |
|---|---|---|
| hasil pencarian | ”This site may be hacked” (terjemahan) “ini situs dapat menjadi hacked” label | Tied untuk Search’s own indeks dari report |
| Chrome / lainnya browser | ”Deceptive site ahead” (terjemahan) “Deceptive situs ahead” / “contains malware” (terjemahan) “berisi malware” interstitial | Powered oleh Google Safe Browsing (cross-browser) |
| Chrome downloads | Download warning (e.g. uncommon/harmful download) | dapat appear without menghapus halaman dari Search |
Surfaces update independently — clearing one melakukan not guarantee others memiliki caught up yet.
Review timelines
| What Google currently says | What ini melakukan not promise |
|---|---|
| sebuah review dapat take sebuah few days untuk sebuah few weeks | sebuah fixed one-day, few-day, atau several-week figure oleh issue jenis |
| — | Simultaneous clearance di seluruh setiap browser/product |
| — | Recovered rankings, traffic, atau AI-search visibilitas |
(Older per-jenis figures — phishing ~1 day, malware ~days, spam hacks up untuk weeks — dan sebuah universal “72 hours after approval” (terjemahan) “72 hours setelah approval” clearance line adalah outdated; don’t quote them sebagai saat ini.)
kode status untuk leftover spam URLs
404/410— hilang; drops dari indeks di atas time (410sebuah touch faster).200pada injected spam — buruk; leave ini dan URL stays terindeks.
mental models
1. Safety, not peringkat. sebuah security issue jawaban “is this site dangerous to visit?” (terjemahan) “adalah ini situs dangerous untuk visit?” — not “is this site’s SEO acceptable?” (terjemahan) “adalah ini situs’s SEO acceptable?” Reach untuk pengguna-safety frame pertama; ini tells Anda who’s affected (Anda pengunjung) dan what clears ini (sebuah fix + sebuah review, not sebuah peringkat appeal).
2. Symptom vs. entry poin. setiap cleanup memiliki two halves: symptom ( injected spam, malicious script, phishing halaman) dan entry poin ( unpatched plugin, weak credential, unsanitized input). Fix hanya symptom dan Anda get reinfected dan fail review. selalu close both.
3. Separate surfaces, not one dial. sebuah Search label, sebuah browser interstitial, dan sebuah Chrome download warning adalah independently-updated signals — sebuah uncommon-download warning dapat appear without blocking Search. Don’t assume “I don’t use Chrome” (terjemahan) “I don’t gunakan Chrome” atau “the report looks clean” (terjemahan) “ report looks clean” berarti setiap surface memiliki cleared; treat Security Issues report sebagai source dari truth untuk what Google memiliki recorded dan fixed.
4. Which report am I di? sebelum Anda plan sebuah fix, name report. Security Issues → hacking atau pengguna harm, fixed oleh cleanup + security review, dapat tampilkan sebuah warning. sebuah manual tindakan → sebuah attempt untuk manipulate search indeks, fixed oleh changing offending SEO + reconsideration, biasanya menampilkan no warning di semua. mereka dapat overlap, so periksa both reports alih-alih assuming ini adalah one atau lainnya.
5. Submit once, dan don’t expect sebuah guarantee. Treat review sebagai sebuah single shot per fix: fully clean, fully documented, per category. Re-submitting sebelum Anda’ve actually closed everything wastes cycle — dan sebuah passed review clears report’s finding, not necessarily Anda rankings, traffic, atau setiap browser’s warning di yang sama instant.
alat untuk diagnosing dan clearing sebuah security issue
- Google Search Console — Security Issues report — sumber kebenaran: category, sample URLs, dan permintaan Review button.
- pemeriksaan URL (GSC) — periksa what Google actually fetched dan rendered untuk sebuah flagged sample URL.
- Google Safe Browsing situs-status periksa — see whether Safe Browsing masih flags Anda domain, independent dari Search Console.
- sebuah malware/situs scanner — Sucuri SiteCheck dan similar remote scanners help locate injected konten; pada WordPress, security plugins (e.g. Wordfence) scan core, plugins, dan themes untuk modifications.
- server access dan logs — file diffs, recent-modified-file lists, dan access logs help Anda temukan what adalah changed dan how attacker got di.
- Anda CMS’s update dan pengguna-management screens — patch everything dan audit accounts; closing entry poin adalah bagian itu membuat review pass.
Prove sebuah security cleanup adalah ready untuk review
Test setiap flagged category dan sample
- Test untuk run: Open setiap category di Security Issues report, inventory -nya sample URLs, dan inspect live dan rendered respons untuk setiap sample setelah remediation.
- Expected hasil: Injected konten, deceptive elements, malicious downloads, dan tidak terotorisasi redirects adalah absent dari setiap sampled URL dan surrounding template.
- Failure interpretation: cleanup missed sebuah file, database entry, template, pengguna-generated payload, atau conditional delivery path.
- Monitoring window: Immediate setelah caches adalah cleared dan cleaned versi adalah deployed.
- Rollback trigger: melakukan not restore compromised release; roll back hanya sebuah cleanup perubahan itu breaks legitimate situs perilaku, lalu replace ini dengan sebuah safe fix sebelum requesting review.
Test entry poin adalah closed
- Test untuk run: Patch vulnerable component, rotate compromised credentials, audit privileged pengguna, dan review server atau application logs untuk renewed access.
- Expected hasil: vulnerable versi adalah hilang, tidak terotorisasi accounts dan keys adalah disabled, dan no matching compromise activity appears setelah fix.
- Failure interpretation: attacker masih memiliki sebuah viable path atau persistence mechanism, so cleaning terlihat payloads alone akan not hold.
- Monitoring window: periksa immediately, lalu watch logs continuously melalui review period.
- Rollback trigger: Halt review permintaan dan isolate affected sistem jika sama exploit, account, atau payload reappears.
Test external warning state sebelum dan setelah review
- Test untuk run: periksa domain di Google Safe Browsing’s situs-status alat dan compare ini dengan Security Issues report setelah submitting one complete review.
- Expected hasil: Search Console review passes dan external browser atau Search warnings jelas setelah Google reprocesses situs.
- Failure interpretation: Google masih detects unsafe perilaku, lainnya category remains unresolved, atau warning sistem memiliki not refreshed yet.
- Monitoring window: Google’s saat ini guidance adalah sebuah few days untuk sebuah few weeks; pertahankan cleaned situs stable dan monitor alih-alih repeatedly resubmitting.
- Rollback trigger: jika warnings kembalikan setelah clearing, treat ini sebagai reinfection, isolate situs, dan reopen incident respons alih-alih filing lainnya unchanged review.
Resources worth Anda time
dari Google
- Security Issues report — canonical reference untuk categories dan review flow.
- permintaan sebuah review — per-category documentation guidance dan review timelines.
- Social Engineering (Phishing dan Deceptive situs) dan Malware dan unwanted software — deep definitions.
dari others
- MalCare — Google Search Console Security Issues: 10 cara untuk fix them — WordPress/plugin-leaning remediation walkthrough.
- SEOZoom — Guide untuk GSC Security Issue report — sebuah kedua perspective pada triage.
- Google Safe Browsing situs status — periksa apakah Safe Browsing masih flags Anda domain independently dari what Search Console menampilkan.
- mesin pencari Land — Google’s Mueller pada hacked konten dan situs recovery — context pada how Google handles hacked halaman returning 404 dan dropping dari indeks.
- mesin pencari Roundtable — GSC manual-tindakan review detail (Mueller) — background pada how review submissions adalah processed; berguna untuk understanding review-queue distinction antara security issues dan manual tindakan.
- r/TechSEO — community untuk berfungsi melalui hacked-situs recovery di nyata time.
Test yourself: Search Console security issues
Five quick pertanyaan pada diagnosis, cleanup, dan review. Pick sebuah jawaban untuk setiap, lalu periksa Anda hasil.
Log perubahan
Diperbarui 18 Jul 2026.
Ringkasan editorial dan detail perubahan yang tercatat.Detail perubahan
-
Catatan perubahan terperinci saat ini tersedia dalam bahasa Inggris.
-
Catatan perubahan terperinci saat ini tersedia dalam bahasa Inggris.
-
Catatan perubahan terperinci saat ini tersedia dalam bahasa Inggris.
-
Catatan perubahan terperinci saat ini tersedia dalam bahasa Inggris.
Perbandingan lengkap tidak tersedia — tidak ada cuplikan sebelumnya yang diarsipkan untuk revisi ini.