Panduan Security Issues Report

What Google Search Console's Security Issues report flags — hacked konten, malware, dan social engineering — how ini differs dari manual tindakan, dan cara clean up dan permintaan sebuah review.

Pertama kali diterbitkan: 23 Jun 2026 · Terakhir diperbarui: 3 Agu 2026 · Advanced
Bahasa

Security Issues report di Google Search Console flags pengguna-safety masalah, not peringkat penalties: hacked konten (malware, code, konten, atau URL injection), deceptive halaman, harmful atau uncommon downloads, dan social engineering (phishing dan deceptive konten) adalah semua saat ini issue jenis, grouped di bawah hacked konten, malware dan unwanted software, dan social engineering. ini adalah surfaced melalui Google Safe Browsing — affected situs dapat tampilkan sebuah 'ini situs dapat menjadi hacked' label di hasil atau sebuah red 'Deceptive situs ahead' interstitial di Chrome dan lainnya browser, though not setiap issue blocks setiap surface yang sama cara. ini adalah not yang sama sebagai sebuah manual tindakan: Manual tindakan mostly concern attempts untuk manipulate Google's indeks (biasanya no terlihat warning); Security Issues concern hacking atau pengguna harm (dapat tampilkan labels atau interstitials) — separate reports, separate review queues, dan mereka dapat overlap. Anda jelas ini oleh fixing vulnerability di seluruh setiap affected halaman, lalu requesting sebuah security review — saat ini guidance says review dapat take anywhere dari sebuah few days untuk sebuah few weeks, dan sebuah passed review doesn't guarantee setiap browser atau search surface clears di once.

TL;DR — Security Issues report flags pengguna-safety masalah, not peringkat penalties. Google groups them di bawah hacked konten (malware, code, konten, atau URL injection — SQL injection adalah sebuah umum metode), malware dan unwanted software (which dapat menjadi installed oleh sebuah hacker atau situs owner), dan social engineering (phishing dan deceptive konten) — tetapi saat ini report juga lists more spesifik issues like deceptive halaman, harmful dan “uncommon” (terjemahan) “uncommon” downloads, dan unclear mobile billing prompts. Sample URLs adalah contoh, not sebuah complete list — beberapa issues tampilkan none di semua. Warning surfaces adalah separate signals (sebuah Search label, sebuah Chrome interstitial, sebuah download warning) dan don’t selalu move together — sebuah uncommon-download warning, misalnya, dapat appear di Chrome tanpa menghapus halaman dari Search. Fix vulnerability, not hanya symptom, di seluruh setiap affected halaman, lalu permintaan Review once; Google’s saat ini guidance adalah sebuah few days untuk sebuah few weeks untuk process, dengan no guarantee setiap browser atau search surface clears simultaneously. ini adalah not sebuah manual tindakan: Manual tindakan mostly concern search-indeks manipulation (biasanya no terlihat warning), while Security Issues concern hacking atau pengguna harm (dapat tampilkan labels atau interstitials) — separate reports, separate review queues, dan mereka dapat overlap.

Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report Evidence for this claim Site owners should fix the issue across the site and request a security review; security reviews are separate from manual-action reconsideration requests. Scope: Current Google hacked-site recovery and review workflow. Confidence: high · Verified: Google Search Central: Request a security review

What report actually adalah

Security Issues report sits di Google Search Console alongside performa, pengindeksan, dan enhancement reports. Google’s framing adalah tentang pengguna safety, dan itu single fact adalah paling berguna mental model pada ini halaman. sebagai Google puts ini di -nya deskripsi dari difference dari manual tindakan, report “lists indications that your site was hacked, or behavior on your site that could potentially harm a visitor or their computer.” (terjemahan) “lists indications itu Anda situs adalah hacked, atau perilaku pada Anda situs itu dapat potentially harm sebuah pengunjung atau mereka computer.” ini adalah not sebuah verdict pada Anda SEO.

issue categories Google flags

Google groups everything di bawah three top-tingkat heading di -nya own documentation, tetapi itu’s sebuah organizing frame, not full list dari issue jenis report dapat actually tampilkan Anda. Treat three heading below sebagai buckets, dan saat ini issue list beneath them sebagai what untuk expect dalam praktik.

1. Hacked konten. Google’s own definition: “This is any content placed on your site without your permission because of security vulnerabilities in your site.” (terjemahan) “ini adalah apa pun konten placed pada Anda situs without Anda permission karena security vulnerabilities di Anda situs.” saat ini report dapat flag several spesifik issues di bawah ini heading, including:

  • Code injection“A hacker has compromised your site and is injecting malicious code in your pages.” (terjemahan) “sebuah hacker memiliki compromised Anda situs dan adalah injecting malicious code di Anda halaman.”
  • konten injection“A hacker has added spammy links or text to your site’s pages.” (terjemahan) “sebuah hacker memiliki ditambahkan spammy tautan atau text untuk Anda situs’s halaman.”
  • URL injection“A hacker has created new pages on your site, often containing spammy words or links.” (terjemahan) “sebuah hacker memiliki dibuat baru halaman pada Anda situs, sering containing spammy kata atau tautan.”
  • Hacked malware — malicious code atau files placed pada situs melalui sama jenis dari tidak terotorisasi access sebagai injection jenis above.

SQL injection adalah umum metode behind ini — sebuah hacker exploits sebuah database kueri vulnerability untuk insert konten atau code. labels above adalah what report menampilkan Anda; SQL injection adalah one dari cara attacker got di.

2. Malware dan unwanted software. Google distinguishes two. Malware adalah “any software or mobile application specifically designed to harm a computer, a mobile device, the software it’s running, or its users.” (terjemahan) “apa pun software atau mobile application specifically designed untuk harm sebuah computer, sebuah perangkat seluler, software ini adalah running, atau -nya pengguna.” Unwanted software adalah “an executable file or mobile application that engages in behavior that is deceptive, unexpected, or that negatively affects the user’s browsing or computing experience.” (terjemahan) “sebuah executable file atau mobile application itu engages di perilaku itu adalah deceptive, unexpected, atau itu negatively affects pengguna’s browsing atau computing experience.” Importantly, ini category isn’t hanya sebuah ketiga-party hack: malware atau unwanted software pada sebuah situs dapat menjadi installed oleh sebuah hacker atau oleh situs owner (sebagian besar sering unknowingly, via sebuah compromised plugin, theme, atau ad script). report juga separates:

  • Harmful downloads — files Google Safe Browsing believes adalah malware atau unwanted software itu sebuah pengunjung adalah prompted untuk download.
  • Uncommon downloads — sebuah download Safe Browsing simply hasn’t seen enough dari untuk vouch untuk yet; ini dapat trigger sebuah Chrome download warning bahkan though halaman itself isn’t necessarily malicious (more pada warning-surface distinction below).

Confirm exact saat ini label wording terhadap Anda own report — Google memiliki adjusted ini labels di atas time.

3. Social engineering. Google: “A social engineering attack is when a web user is tricked into doing something dangerous online.” (terjemahan) “sebuah social engineering attack adalah when sebuah web pengguna adalah tricked ke doing something dangerous online.” Sub-jenis sertakan:

  • Phishing“The site tricks users into revealing their personal information (for example, passwords, phone numbers, or social security numbers).” (terjemahan) “ situs tricks pengguna ke revealing mereka personal informasi (misalnya, passwords, phone angka, atau social security angka).” Google’s saat ini report dapat juga flag suspected phishing halaman detected specifically sekitar login flows.
  • Deceptive konten / deceptive halaman — konten itu tries untuk trick Anda ke doing something Anda’d hanya melakukan untuk sebuah trusted entity, such sebagai sharing sebuah password, calling tech mendukung, atau downloading software — including deceptive embedded resources (ads atau widgets) pada sebuah otherwise legitimate halaman.
  • Unclear mobile billing — sebuah subscription atau billing flow, biasanya pada mobile, itu doesn’t clearly disclose price atau istilah sebelum charging pengguna.

Operating sebuah situs pada behalf dari lainnya party without membuat itu relationship jelas dapat juga menjadi flagged sebagai social engineering — worth knowing jika Anda run white-label atau affiliate halaman.

Where warning menampilkan up — dan why Safe Browsing penting

Affected halaman don’t hanya sink di rankings. Google: “Pages or sites affected by a security issue can appear with a warning label in search results or an interstitial warning page in the browser when a user tries to visit them.” (terjemahan) “halaman atau situs affected oleh sebuah security issue dapat appear dengan sebuah warning label di hasil pencarian atau sebuah interstitial warning halaman di browser when sebuah pengguna tries untuk visit them.”

Two surfaces, lalu:

  • di Search, hacked situs dapat tampilkan sebuah “This site may be hacked” (terjemahan) “ini situs dapat menjadi hacked” label di bawah hasil.
  • di browser, Chrome dapat tampilkan sebuah full-halaman interstitial. Google: “If Google detects that your website contains social engineering content, the Chrome browser may display a ‘Deceptive site ahead’ warning when visitors view your site.” (terjemahan) “jika Google detects itu Anda situs web berisi social engineering konten, Chrome browser dapat display sebuah ‘Deceptive situs ahead’ warning when pengunjung view Anda situs.” Malware triggers sebuah similar “the site ahead contains malware” (terjemahan) “ situs ahead berisi malware” interstitial.
Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report

browser warnings adalah powered oleh Google Safe Browsing, dan itu’s bagian people miss. Firefox, Safari, dan lainnya browser consume Safe Browsing API, so red warning dapat appear di seluruh browser — not hanya di Chrome, dan not hanya via Search Console.

Don’t assume setiap issue jenis produces setiap warning, atau itu surfaces move di lockstep. Search warning labels, browser interstitials, Chrome’s download warnings, dan whether sebuah halaman dapat appear di Search di semua adalah separate, independently-updated signals. sebuah baik contoh: sebuah uncommon-download warning dapat tampilkan up sebagai sebuah Chrome download prompt without necessarily preventing halaman itself dari appearing di Google Search — ini adalah not yang sama sebagai sebuah full interstitial atau sebuah de-pengindeksan. Because ini surfaces update independently, dan Safe Browsing perilaku dapat juga depend pada browsing context, treat Security Issues report itself sebagai authoritative record dari what Google memiliki recorded dan fixed untuk Anda situs — don’t assume sebuah warning Anda personally dapat’t reproduce di one browser berarti nothing adalah wrong, dan don’t assume clearing report berarti setiap consuming browser atau product memiliki caught up yet.

Evidence for this claim Search warning labels and browser interstitial/download warnings are separate surfaces. Not every issue blocks Search: uncommon-download warnings, for example, can appear in Chrome without preventing the page or site from appearing in Google Search. Scope: web UI and Google Search reporting Confidence: high · Verified: Security issues report

Security Issues vs. Manual tindakan

ini adalah distinction itu trips up paling people, so let’s gunakan Google’s own boundary alih-alih sebuah simplified cause split.

Security IssuesManual tindakan
What ini berartisitus adalah hacked, atau hosts konten/perilaku itu dapat harm sebuah pengunjungsebuah reviewer determined situs attempted untuk manipulate Google’s search indeks
Typical causeHacking, deceptive konten, atau malware/unwanted software — which dapat menjadi installed oleh sebuah hacker atau, sometimes unknowingly, oleh situs ownerAnda own SEO practices (unnatural tautan, thin konten, cloaking, sneaky redirects)
jenis dari masalahpengguna safetySearch-indeks manipulation
pengguna-facing warningdapat tampilkan sebuah Search label atau sebuah browser interstitialbiasanya no terlihat warning — affected halaman adalah hanya diperingkatkan lower atau omitted
ReportSecurity Issues reportManual tindakan report
Review queueSecurity reviewManual-tindakan reconsideration

mereka adalah separate reports dengan separate review queues — sebuah situs dapat memiliki one, both, atau neither, dan ini adalah mungkin untuk two untuk overlap (sebuah hacked halaman itu gets stuffed dengan spammy tautan, misalnya, dapat eventually surface di both reports). Don’t reduce ini untuk “someone else hacked me” (terjemahan) “someone else hacked me” versus “I did my own spam” (terjemahan) “I melakukan my own spam” — nyata dividing line Google draws adalah what report adalah protecting terhadap (pengguna, versus integrity dari search indeks), not who caused ini.

Triage dan remediation

Front-muat triage; memahami categories kedua.

  1. Confirm ini di report. Read exactly which category dan which sample URLs Google lists — tetapi treat itu URLs sebagai contoh, not sebuah full inventory. Google adalah explicit itu list isn’t necessarily complete, dan beberapa issues dapat tampilkan no sample URLs di semua, which tidak berarti nothing adalah affected. gunakan URL Inspection pada samples untuk see what Google actually fetched, lalu cari yang sama vulnerability atau injected pattern elsewhere pada situs.
  2. Limit damage. Depending pada severity, take situs (atau affected bagian) offline atau behind maintenance mode so Anda stop serving malware atau phishing untuk pengguna nyata while Anda berfungsi. hindari directly opening sebuah suspected infected halaman di sebuah normal browser — beberapa attacks cloak konten berdasarkan browsing context, so what Anda see dapat not match what Google recorded; gunakan isolated tooling (sebuah scanner, sebuah sandboxed environment, atau pemeriksaan URL) instead.
  3. temukan dan hapus injected konten. Spam halaman, injected scripts, rogue admin accounts, modified core files.
  4. Close vulnerability. ini adalah langkah itu decides whether Anda review passes. Patch out-dari-date plugin/CMS, rotate credentials, fix insecure directory atau input itu allowed injection. hapus symptom dan entry poin, atau Anda get reinfected dan review fails.
  5. Handle leftover terindeks URLs. Injected spam halaman itu got terindeks seharusnya kembalikan 404 atau 410 so Google drops them di atas time (410 adalah sebuah touch faster sebagai sebuah signal). Don’t leave them resolving dengan sebuah 200.
  6. CMS notes. pada WordPress, usual suspects adalah outdated plugins/themes dan weak admin credentials — update everything, audit pengguna, dan pertimbangkan sebuah security plugin scan. pada lainnya stacks, principle adalah identical bahkan jika tooling isn’t: patch, rotate, dan close input itu adalah exploited.

Requesting sebuah security review

Once setiap flagged issue adalah fixed di seluruh semua halaman, gunakan permintaan Review di report. Google: “When all issues listed in the report are fixed in all pages, select Request Review in the Security Issues report.” (terjemahan) “When semua issues listed di report adalah fixed di semua halaman, select permintaan Review di Security Issues report.”

Document what Anda melakukan. Google menanyakan Anda untuk “provide more information on what you did to clean your site. For each category of hacked spam, include a brief explanation of how the site was cleaned.” (terjemahan) “menyediakan more informasi pada what Anda melakukan untuk clean Anda situs. untuk setiap category dari hacked spam, sertakan sebuah brief explanation dari how situs adalah cleaned.” Google’s own contoh dari baik wording: “For Content injection hacked URLs, I removed the spam content and corrected the vulnerability by updating an out-of-date plugin.” (terjemahan) “untuk konten injection hacked URLs, I dihapus spam konten dan corrected vulnerability oleh updating sebuah out-dari-date plugin.” Note how ini names both cleanup dan closed hole.

pada timing: Google’s saat ini guidance adalah itu sebuah security review dapat take anywhere dari sebuah few days untuk sebuah few weeks untuk process. Earlier guidance (published separately dari report’s own documentation) broke ini down oleh issue jenis — phishing faster, hacked-spam cases slower — dan promised warnings jelas di dalam 72 hours dari approval. itu per-jenis breakdown dan fixed 72-hour figure adalah not what report’s saat ini documentation states, so treat them sebagai outdated alih-alih sebuah schedule Anda dapat rely pada. What’s consistent: warning melakukan not disappear instant Anda fix things — ini clears hanya setelah review passes, dan bahkan lalu propagation di seluruh setiap browser, search hasil, dan Google product isn’t instant atau guaranteed untuk happen di yang sama moment everywhere. sebuah passed review juga isn’t sebuah promise dari restored rankings, traffic, atau AI-search visibilitas — itu adalah separate outcomes review process doesn’t cover.

sebuah few aturan dari road: submit once, fully fixed dan documented — re-submitting sebelum Anda’ve actually closed everything hanya wastes sebuah review cycle. Don’t set sebuah hard internal deadline sekitar sebuah spesifik angka dari hours atau days; monitor report dan Anda situs’s status alih-alih repeatedly resubmitting.

Preventing reinfection

cleanup adalah hanya half job. pertahankan CMS core, plugins, dan themes patched; enforce least-privilege pada accounts dan rotate apa pun credentials itu dapat memiliki leaked; turn pada 2FA untuk admin logins; monitor untuk unexpected baru files atau pengguna; dan periodically periksa Anda situs’s status di Google’s Safe Browsing situs-status alat. vulnerability itu let them di pertama time adalah one mereka’ll try again.

Add an expert note

Pin an expert quote

New person? Create their unclaimed profile at /admin/experts/ → Pin a quote first.