Security 問題 レポート

暫定日本語訳:何 Google 検索 Console's Security 問題 レポート flags — hacked コンテンツ, malware, と social engineering — どのように it differs から 手動 actions, と どのように へ clean up と リクエスト review.

初回公開:2026年6月23日 · 最終更新:2026年8月4日 · Advanced
言語

暫定日本語訳:Security 問題 レポート in Google 検索 Console flags ユーザー-safety 問題, ない ランキング penalties: hacked コンテンツ (malware, code, コンテンツ, または URL injection), deceptive ページ, harmful または uncommon downloads, と social engineering (phishing と deceptive コンテンツ) are all 現在の 問題 types, grouped 下で hacked コンテンツ, malware と unwanted software, と social engineering. It's surfaced 通じて Google Safe Browsing — affected サイト できる 表示 'この サイト 可能性がある be hacked' label in results または red 'Deceptive サイト ahead' interstitial in Chrome と other ブラウザー, though ない すべての 問題 blocks すべての surface 同じ way. It is ない 同じ as 手動 action: 手動 Actions mostly concern attempts へ manipulate Google's インデックス登録 (usually no visible warning); Security 問題 concern hacking または ユーザー harm (できる 表示 labels または interstitials) — separate レポート, separate review queues, と それら できる overlap. あなた clear it by fixing vulnerability 全体で すべての affected ページ, then requesting security review — 現在の guidance says review できる take anywhere から few days へ few weeks, と passed review doesn't guarantee すべての ブラウザー または 検索 surface clears at once.

暫定日本語案: TL;DR — Security 問題 レポート flags ユーザー-safety 問題, ない ランキング 暫定日本語案: penalties. Google groups them 下で hacked コンテンツ (malware, code, コンテンツ, 暫定日本語案: または URL injection — SQL injection is 一般的な 方法), malware と unwanted 暫定日本語案: software (which できる be installed by hacker または サイト owner), と 暫定日本語案: social engineering (phishing と deceptive コンテンツ) — ただし 現在の レポート 暫定日本語案: また lists more specific 問題 like deceptive ページ, harmful と “uncommon” 暫定日本語案: downloads, と unclear mobile billing prompts. Sample URLs are 例, ない 暫定日本語案: 完全な list — some 問題 表示 none at all. Warning surfaces are separate 暫定日本語案: signals ( 検索 label, Chrome interstitial, download warning) と don’t 暫定日本語案: 常に move together — uncommon-download warning, 向けに instance, できる 表示される 暫定日本語案: in Chrome なしで removing ページ から 検索. Fix vulnerability, ない 暫定日本語案: just symptom, 全体で すべての affected ページ, then リクエスト Review once; 暫定日本語案: Google’s 現在の guidance is few days へ few weeks へ プロセス, とともに no 暫定日本語案: guarantee すべての ブラウザー または 検索 surface clears simultaneously. この is 暫定日本語案: ない 手動 action: 手動 Actions mostly concern 検索-インデックス登録 暫定日本語案: manipulation (usually no visible warning), while Security 問題 concern 暫定日本語案: hacking または ユーザー harm (できる 表示 labels または interstitials) — separate レポート, 暫定日本語案: separate review queues, と それら できる overlap. 暫定日本語案: Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report Evidence for this claim Site owners should fix the issue across the site and request a security review; security reviews are separate from manual-action reconsideration requests. Scope: Current Google hacked-site recovery and review workflow. Confidence: high · Verified: Google Search Central: Request a security review

何 レポート actually is

暫定日本語案: Security 問題 レポート sits in Google 検索 Console alongside 暫定日本語案: パフォーマンス, インデックス登録, と enhancement レポート. Google’s framing is について ユーザー 暫定日本語案: safety, と その single fact is 大半の useful mental model on この ページ. As 暫定日本語案: Google puts it in its 説明 of difference から 手動 actions, 暫定日本語案: レポート “lists indications that your site was hacked, or behavior on your site that could potentially harm a visitor or their computer.” It is ない verdict on 暫定日本語案: あなた SEO.

問題 categories Google flags

暫定日本語案: Google groups everything 下で three top-level headings in its own ドキュメント, 暫定日本語案: ただし その’s organizing frame, ない full list of 問題 types レポート できる 暫定日本語案: actually 表示 あなた. Treat three headings below as buckets, と 現在の 暫定日本語案: 問題 list beneath them as 何 へ expect in practice.

暫定日本語案: 1. Hacked コンテンツ. Google’s own definition: “This is any content placed on your site without your permission because of security vulnerabilities in your site.” 現在の レポート できる flag several specific 問題 下で この heading, 暫定日本語案: including:

  • 暫定日本語案: Code injection“A hacker has compromised your site and is injecting malicious code in your pages.”
  • 暫定日本語案: コンテンツ injection“A hacker has added spammy links or text to your site’s pages.”
  • 暫定日本語案: URL injection“A hacker has created new pages on your site, often containing spammy words or links.”
  • 暫定日本語案: Hacked malware — malicious code または files placed on サイト 通じて 暫定日本語案: 同じ kind of unauthorized access as injection types above.

暫定日本語案: SQL injection is 一般的な 方法 behind これらの — hacker exploits database 暫定日本語案: クエリ vulnerability へ insert コンテンツ または code. labels above are 何 暫定日本語案: レポート 表示 あなた; SQL injection is one of ways attacker got in.

暫定日本語案: 2. Malware と unwanted software. Google distinguishes two. Malware is 暫定日本語案: “any software or mobile application specifically designed to harm a computer, a mobile device, the software it’s running, or its users.” Unwanted software is 暫定日本語案: “an executable file or mobile application that engages in behavior that is deceptive, unexpected, or that negatively affects the user’s browsing or computing experience.” Importantly, この category isn’t だけ third-party hack: malware または 暫定日本語案: unwanted software on サイト できる be installed by hacker または by サイト owner 暫定日本語案: (大半の 多くの場合 unknowingly, via compromised plugin, theme, または ad script). レポート 暫定日本語案: また separates:

  • 暫定日本語案: Harmful downloads — files Google Safe Browsing believes are malware または 暫定日本語案: unwanted software その 訪問者 is prompted へ download.
  • 暫定日本語案: Uncommon downloads — download Safe Browsing simply hasn’t seen enough of 暫定日本語案: へ vouch 向けに yet; この できる trigger Chrome download warning even though 暫定日本語案: ページ itself isn’t necessarily malicious (more on warning-surface distinction 暫定日本語案: below).

暫定日本語案: Confirm exact 現在の label wording against あなた own レポート — Google has 暫定日本語案: adjusted これらの labels 超えて time.

暫定日本語案: 3. Social engineering. Google: “A social engineering attack is when a web user is tricked into doing something dangerous online.” Sub-types 含む:

  • 暫定日本語案: Phishing“The site tricks users into revealing their personal information (for example, passwords, phone numbers, or social security numbers).” Google’s 現在の レポート できる また flag suspected phishing ページ 暫定日本語案: detected specifically around login flows.
  • 暫定日本語案: Deceptive コンテンツ / deceptive ページ — コンテンツ その tries へ trick あなた へ 暫定日本語案: doing something あなた’d だけ do 向けに trusted entity, such as sharing password, 暫定日本語案: calling tech support, または downloading software — including deceptive embedded 暫定日本語案: resources (ads または widgets) on otherwise legitimate ページ.
  • 暫定日本語案: Unclear mobile billing — subscription または billing flow, usually on mobile, 暫定日本語案: その doesn’t clearly disclose 価格 または terms 前に charging ユーザー.

暫定日本語案: Operating サイト on behalf of another party なしで making その relationship clear 暫定日本語案: できる また be flagged as social engineering — worth knowing if あなた run white-label 暫定日本語案: または affiliate ページ.

どこ warning 表示 up — と なぜ Safe Browsing matters

暫定日本語案: Affected ページ don’t just sink in rankings. Google: “Pages or sites affected by a security issue can appear with a warning label in search results or an interstitial warning page in the browser when a user tries to visit them.”

暫定日本語案: Two surfaces, then:

  • 暫定日本語案: In 検索, hacked サイト できる 表示 “This site may be hacked” label 下で 暫定日本語案: result.
  • 暫定日本語案: In ブラウザー, Chrome 可能性がある 表示 full-ページ interstitial. Google: “If Google detects that your website contains social engineering content, the Chrome browser may display a ‘Deceptive site ahead’ warning when visitors view your site.” 暫定日本語案: Malware triggers similar “the site ahead contains malware” interstitial.
Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report

暫定日本語案: ブラウザー warnings are powered by Google Safe Browsing, と その’s part 暫定日本語案: 人々 miss. Firefox, Safari, と other ブラウザー consume Safe Browsing API, so 暫定日本語案: red warning できる 表示される 全体で ブラウザー — ない just in Chrome, と ない だけ via 暫定日本語案: 検索 Console.

暫定日本語案: Don’t assume すべての 問題 type produces すべての warning, または その surfaces move in 暫定日本語案: lockstep. 検索 warning labels, ブラウザー interstitials, Chrome’s download 暫定日本語案: warnings, と whether ページ できる 表示される in 検索 at all are separate, 暫定日本語案: independently-updated signals. good 例: uncommon-download warning 暫定日本語案: できる 表示 up as Chrome download prompt なしで necessarily preventing ページ 暫定日本語案: itself から 表示される in Google 検索 — it’s ない 同じ as full interstitial 暫定日本語案: または de-インデックス登録. Because これらの surfaces update independently, と Safe Browsing 暫定日本語案: behavior できる また depend on browsing context, treat Security 問題 レポート 暫定日本語案: itself as authoritative record of 何 Google has recorded と fixed 向けに あなた 暫定日本語案: サイト — don’t assume warning あなた personally できる’t reproduce in one ブラウザー means 暫定日本語案: nothing is 誤った, と don’t assume clearing レポート means すべての consuming 暫定日本語案: ブラウザー または 商品 has caught up yet.

Evidence for this claim Search warning labels and browser interstitial/download warnings are separate surfaces. Not every issue blocks Search: uncommon-download warnings, for example, can appear in Chrome without preventing the page or site from appearing in Google Search. Scope: web UI and Google Search reporting Confidence: high · Verified: Security issues report

Security 問題 vs. 手動 Actions

暫定日本語案: この is distinction その trips up 大半の 人々, so let’s 使用 Google’s own 暫定日本語案: boundary rather than simplified cause split.

Security 問題手動 Actions
何 it meansサイト is hacked, または hosts コンテンツ/behavior その できる harm 訪問者reviewer determined サイト attempted へ manipulate Google’s 検索 インデックス登録
Typical causeHacking, deceptive コンテンツ, または malware/unwanted software — which できる be installed by hacker または, sometimes unknowingly, by サイト ownerあなた own SEO practices (unnatural links, thin コンテンツ, cloaking, sneaky リダイレクト)
Type of 問題ユーザー safety検索-インデックス登録 manipulation
ユーザー-facing warningできる 表示 検索 label または ブラウザー interstitialUsually no visible warning — affected ページ are just ranked lower または omitted
レポートSecurity 問題 レポート手動 Actions レポート
Review queueSecurity review手動-action reconsideration

暫定日本語案: それら are separate レポート とともに separate review queues — サイト できる have 暫定日本語案: one, both, または neither, と it’s possible 向けに two へ overlap ( hacked ページ 暫定日本語案: その gets stuffed とともに spammy links, 向けに 例, できる eventually surface in 暫定日本語案: both レポート). Don’t reduce この へ “someone else hacked me” versus “I did my own spam” — real dividing line Google draws is 何 レポート is protecting 暫定日本語案: against (ユーザー, versus integrity of 検索 インデックス登録), ない who caused it.

Triage と remediation

暫定日本語案: Front-load triage; understand categories second.

  1. 暫定日本語案: Confirm it in レポート. Read exactly which category と which sample URLs 暫定日本語案: Google lists — ただし treat それらの URLs as 例, ない full inventory. Google 暫定日本語案: is explicit その list isn’t necessarily 完全な, と some 問題 できる 表示 暫定日本語案: no sample URLs at all, which doesn’t mean nothing is affected. 使用 URL 暫定日本語案: Inspection on samples へ see 何 Google actually fetched, then look 向けに 暫定日本語案: 同じ vulnerability または injected pattern elsewhere on サイト.
  2. 暫定日本語案: Limit damage. Depending on severity, take サイト (または affected 暫定日本語案: section) offline または behind maintenance mode so あなた stop serving malware または 暫定日本語案: phishing へ real ユーザー while あなた 機能. 避ける directly opening suspected 暫定日本語案: infected ページ in normal ブラウザー — some attacks cloak コンテンツ based on 暫定日本語案: browsing context, so 何 あなた see 可能性がある ない match 何 Google recorded; 使用 暫定日本語案: isolated tooling ( scanner, sandboxed environment, または URL Inspection) 暫定日本語案: instead.
  3. 暫定日本語案: Find と 削除 injected コンテンツ. Spam ページ, injected scripts, 暫定日本語案: rogue admin アカウント, modified core files.
  4. 暫定日本語案: Close vulnerability. この is 手順 その decides whether あなた review 暫定日本語案: passes. Patch out-of-date plugin/CMS, rotate credentials, fix insecure 暫定日本語案: directory または input その 許可 injection. 削除 symptom 暫定日本語案: entry point, または あなた get reinfected と review fails.
  5. 暫定日本語案: Handle leftover インデックス登録 URLs. Injected spam ページ その got インデックス登録 暫定日本語案: すべき return 404 または 410 so Google drops them 超えて time (410 is touch 暫定日本語案: faster as signal). Don’t leave them resolving とともに 200.
  6. 暫定日本語案: CMS notes. On WordPress, usual suspects are outdated plugins/themes と 暫定日本語案: weak admin credentials — update everything, audit ユーザー, と consider security 暫定日本語案: plugin scan. On other stacks, principle is identical even if tooling 暫定日本語案: isn’t: patch, rotate, と close input その was exploited.

Requesting security review

暫定日本語案: Once すべての flagged 問題 is fixed 全体で all ページ, 使用 リクエスト Review in 暫定日本語案: レポート. Google: “When all issues listed in the report are fixed in all pages, select Request Review in the Security Issues report.”

暫定日本語案: Document 何 あなた did. Google asks あなた へ “provide more information on what you did to clean your site. For each category of hacked spam, include a brief explanation of how the site was cleaned.” Google’s own 例 of good wording: “For Content injection hacked URLs, I removed the spam content and corrected the vulnerability by updating an out-of-date plugin.” Note どのように it names both cleanup と closed 暫定日本語案: hole.

暫定日本語案: On timing: Google’s 現在の guidance is その security review できる take 暫定日本語案: anywhere から few days へ few weeks へ プロセス. Earlier guidance 暫定日本語案: (published separately から レポート’s own ドキュメント) broke この down by 暫定日本語案: 問題 type — phishing faster, hacked-spam ケース slower — と promised warnings 暫定日本語案: clear 以内に 72 hours of approval. その per-type breakdown と fixed 72-hour 暫定日本語案: figure are ない 何 レポート’s 現在の ドキュメント states, so treat them as 暫定日本語案: outdated rather than schedule あなた できる rely on. 何’s consistent: warning 暫定日本語案: does ない disappear instant あなた fix things — it clears だけ 後に 暫定日本語案: review passes, と even then propagation 全体で すべての ブラウザー, 検索結果, と 暫定日本語案: Google 商品 isn’t instant または guaranteed へ happen at 同じ moment 暫定日本語案: everywhere. passed review また isn’t promise of restored rankings, トラフィック, または 暫定日本語案: AI-検索 visibility — それらの are separate outcomes review プロセス doesn’t 暫定日本語案: cover.

暫定日本語案: few rules of road: submit once, fully fixed と documented — re-submitting 暫定日本語案: 前に あなた’ve actually closed everything just wastes review cycle. Don’t 設定 暫定日本語案: hard internal deadline around specific number of hours または days; 監視 暫定日本語案: レポート と あなた サイト’s status instead of repeatedly resubmitting.

Preventing reinfection

暫定日本語案: cleanup is だけ half job. 保つ CMS core, plugins, と themes patched; enforce 暫定日本語案: least-privilege on アカウント と rotate any credentials その 可能性がある have leaked; turn on 暫定日本語案: 2FA 向けに admin logins; 監視 向けに unexpected 新しい files または ユーザー; と periodically 暫定日本語案: 確認 あなた サイト’s status in Google’s Safe Browsing サイト-status ツール. vulnerability 暫定日本語案: その let them in 最初 time is one それら’ll try again.

Add an expert note

Pin an expert quote

New person? Create their unclaimed profile at /admin/experts/ → Pin a quote first.