Security Các vấn đề Báo cáo

Điều gì Google Search Console's Security Các vấn đề báo cáo flags — hacked nội dung, malware, và social engineering — cách điều này differs từ manual actions, và cách sạch lên và yêu cầu một review.

Xuất bản lần đầu: 23 thg 6, 2026 · Cập nhật lần cuối: 8 thg 8, 2026 · Advanced
Ngôn ngữ

Đó Security Các vấn đề báo cáo trong Google Search Console flags người dùng-safety các vấn đề, không xếp hạng penalties: hacked nội dung (malware, code, nội dung, hoặc URL injection), deceptive các trang, harmful hoặc uncommon downloads, và social engineering (phishing và deceptive nội dung) là all hiện tại vấn đề types, grouped dưới hacked nội dung, malware và unwanted software, và social engineering. đây là surfaced qua Google Safe Browsing — affected các trang có thể cho thấy một 'Này site có thể là hacked' label trong kết quả hoặc một red 'Deceptive site ahead' interstitial trong Chrome và other các trình duyệt, though không mỗi vấn đề chặn mỗi surface cùng cách. Điều này không phải đó giống nhau as một manual hành động: Manual Actions mostly concern attempts để manipulate Google chỉ mục (thường không visible warning); Security Các vấn đề concern hacking hoặc người dùng harm (có thể cho thấy labels hoặc interstitials) — tách biệt các báo cáo, tách biệt review queues, và they có thể overlap. Bạn clear điều này by sửa đó vulnerability trên mỗi affected trang, thì requesting một security review — hiện tại hướng dẫn says review có thể take anywhere từ vài days để vài weeks, và một đã truyền review không bảo đảm mỗi trình duyệt hoặc tìm kiếm surface clears tại khi.

Tóm tắt — Security Các vấn đề báo cáo flags người dùng-safety các vấn đề, không xếp hạng penalties. Google groups them dưới hacked nội dung (malware, code, nội dung, hoặc URL injection — SQL injection là phổ biến phương thức), malware và unwanted software (mà có thể là installed by hacker hoặc trang web owner), và social engineering (phishing và deceptive nội dung) — nhưng hiện tại báo cáo cũng lists nhiều hơn cụ thể các vấn đề như deceptive các trang, harmful và “uncommon” downloads, và unclear mobile billing prompts. Sample các URL là các ví dụ, không hoàn tất list — some các vấn đề hiển thị none tại all. Warning surfaces là tách biệt các tín hiệu ( Tìm kiếm label, Chrome interstitial, download warning) và không luôn move together — uncommon-download warning, chẳng hạn, có thể xuất hiện trong Chrome không có removing trang từ Tìm kiếm. khắc phục vulnerability, không chỉ symptom, trên mỗi affected trang, sau đó yêu cầu Review sau khi; Google hiện tại hướng dẫn là một vài days để một vài weeks để xử lý, với không bảo đảm mỗi trình duyệt hoặc tìm kiếm surface clears simultaneously. Đây là không manual hành động: Manual Actions mostly concern tìm kiếm-chỉ mục manipulation (thường không visible warning), trong khi Security Các vấn đề concern hacking hoặc người dùng harm (có thể hiển thị labels hoặc interstitials) — tách biệt các báo cáo, tách biệt review queues, và họ có thể overlap.

Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report Evidence for this claim Site owners should fix the issue across the site and request a security review; security reviews are separate from manual-action reconsideration requests. Scope: Current Google hacked-site recovery and review workflow. Confidence: high · Verified: Google Search Central: Request a security review

Điều gì báo cáo thực ra là

Đó Security Các vấn đề báo cáo sits trong Google Search Console alongside đó performance, lập chỉ mục, và enhancement các báo cáo. Google cách diễn đạt là về người dùng safety, và đó single fact là đó hầu hết hữu ích mental model on này trang. As Google diễn đạt điều này trong của nó mô tả of đó khác biệt từ manual actions, đó báo cáo “lists indications that your site was hacked, or behavior on your site that could potentially harm a visitor or their computer.” (bản dịch) «lists indications đó trang web của bạn đã là hacked, hoặc behavior trên trang web của bạn đó có thể potentially harm một khách truy cập hoặc của họ computer.» Điều này không phải một verdict on của bạn SEO.

vấn đề categories Google flags

Google groups mọi thứ dưới three top-cấp độ headings trong của nó own tài liệu, nhưng đó organizing frame, không đầy đủ list của vấn đề types báo cáo có thể thực ra hiển thị bạn. Treat three headings dưới as buckets, và hiện tại vấn đề list beneath them as Điều gì để expect trên thực tế.

1. Hacked nội dung. Google own definition: “This is any content placed on your site without your permission because of security vulnerabilities in your site.” (bản dịch) «Này là bất kỳ nội dung placed trên trang web của bạn không có của bạn permission làm security vulnerabilities trong trang web của bạn.» Đó hiện tại báo cáo có thể flag several cụ thể các vấn đề dưới này heading, including:

  • Code injection“A hacker has compromised your site and is injecting malicious code in your pages.” (bản dịch) «MỘT hacker có compromised trang web của bạn và là injecting malicious code trong của bạn các trang.»
  • Nội dung injection“A hacker has added spammy links or text to your site’s pages.” (bản dịch) «MỘT hacker có đã thêm spammy links hoặc text để trang web của bạn các trang.»
  • URL injection“A hacker has created new pages on your site, often containing spammy words or links.” (bản dịch) «MỘT hacker có đã tạo new các trang trên trang web của bạn, thường containing spammy words hoặc links.»
  • Hacked malware — malicious code hoặc files placed on đó site qua đó giống nhau kind of chưa được ủy quyền access as đó injection types trên.

SQL injection là phổ biến phương thức behind những điều này — hacker exploits database query vulnerability để insert nội dung hoặc code. labels trên là Điều gì báo cáo hiển thị bạn; SQL injection là một của ways attacker đã nhận trong.

2. Malware và unwanted software. Google distinguishes đó hai. Malware là “any software or mobile application specifically designed to harm a computer, a mobile device, the software it’s running, or its users.” (bản dịch) «bất kỳ software hoặc mobile application cụ thể designed để harm một computer, một mobile device, đó software đây là đang chạy, hoặc của nó người dùng.» Unwanted software là “an executable file or mobile application that engages in behavior that is deceptive, unexpected, or that negatively affects the user’s browsing or computing experience.” (bản dịch) «an executable file hoặc mobile application đó engages trong behavior đó là deceptive, unexpected, hoặc đó negatively ảnh hưởng người dùng browsing hoặc computing experience.» Importantly, này category không chỉ một bên thứ ba hack: malware hoặc unwanted software on một site có thể là installed by một hacker hoặc by đó chủ trang web (hầu hết thường unknowingly, qua một compromised plugin, theme, hoặc quảng cáo script). Đó báo cáo cũng separates:

  • Harmful downloads — files Google Safe Browsing believes là malware hoặc unwanted software đó khách truy cập là prompted để download.
  • Uncommon downloads — download Safe Browsing đơn giản hasn’t seen đủ của để vouch cho tuy vậy; điều này có thể trigger Chrome download warning mặc dù trang itself không phải nhất thiết malicious (nhiều hơn on warning-surface phân biệt dưới).

xác nhận chính xác hiện tại label wording so với của bạn own báo cáo — Google có adjusted những điều này labels theo thời gian.

3. Social engineering. Google: “A social engineering attack is when a web user is tricked into doing something dangerous online.” (bản dịch) «MỘT social engineering attack là khi một web người dùng là tricked vào đang làm điều gì đó dangerous online.» Sub-types bao gồm:

  • Phishing“The site tricks users into revealing their personal information (for example, passwords, phone numbers, or social security numbers).” (bản dịch) «Đó site tricks người dùng vào revealing của họ personal information (ví dụ, passwords, phone numbers, hoặc social security numbers).» Google hiện tại báo cáo có thể cũng flag suspected phishing các trang detected cụ thể khoảng login luồng.
  • Deceptive nội dung / deceptive các trang — nội dung đó tries để trick bạn vào đang làm điều gì đó bạn’d chỉ làm cho một trusted entity, such as sharing một password, calling tech hỗ trợ, hoặc downloading software — including deceptive embedded các tài nguyên (quảng cáo hoặc widgets) on an nếu không legitimate trang.
  • Unclear mobile billing — một subscription hoặc billing flow, thường on mobile, đó không rõ ràng tiết lộ price hoặc terms trước charging người dùng.

Operating trang web on behalf của một party không có đang làm đó mối quan hệ clear có thể cũng là flagged as social engineering — worth knowing nếu bạn chạy white-label hoặc affiliate các trang.

nơi warning hiển thị lên — và Vì sao Safe Browsing matters

Affected các trang không chỉ sink trong thứ hạng. Google: “Pages or sites affected by a security issue can appear with a warning label in search results or an interstitial warning page in the browser when a user tries to visit them.” (bản dịch) «Các trang hoặc các trang affected by một security vấn đề có thể xuất hiện với một warning label trong kết quả tìm kiếm hoặc an interstitial warning trang trong đó trình duyệt khi một người dùng tries để visit them.»

Hai surfaces, sau đó:

  • Trong Tìm kiếm, hacked các trang có thể cho thấy một “This site may be hacked” (bản dịch) «Này site có thể là hacked» label dưới đó kết quả.
  • Trong đó trình duyệt, Chrome có thể cho thấy một đầy đủ-trang interstitial. Google: “If Google detects that your website contains social engineering content, the Chrome browser may display a ‘Deceptive site ahead’ warning when visitors view your site.” (bản dịch) «Nếu Google detects đó của bạn website contains social engineering nội dung, đó Chrome trình duyệt có thể display một ‘Deceptive site ahead’ warning khi khách truy cập view trang web của bạn.» Malware triggers một similar “the site ahead contains malware” (bản dịch) «đó site ahead contains malware» interstitial.
Evidence for this claim Search Console's Security Issues report identifies hacked content, malware, unwanted software, and social-engineering issues detected on a site. Scope: Current Search Console Security Issues report. Confidence: high · Verified: Google Search Console: Security Issues report

trình duyệt warnings là powered by Google Safe Browsing, và đó part mọi người miss. Firefox, Safari, và khác các trình duyệt consume Safe Browsing API, so red warning có thể xuất hiện trên các trình duyệt — không chỉ trong Chrome, và không chỉ qua Search Console.

không assume mỗi vấn đề loại produces mỗi warning, hoặc đó surfaces move trong lockstep. Tìm kiếm warning labels, trình duyệt interstitials, Chrome download warnings, và liệu trang có thể xuất hiện trong Tìm kiếm tại all là tách biệt, independently-đã cập nhật các tín hiệu. good ví dụ: uncommon-download warning có thể hiển thị lên as Chrome download prompt không có nhất thiết preventing trang itself từ appearing trong Google Search — nó không giống nhau as đầy đủ interstitial hoặc de-lập chỉ mục. vì những điều này surfaces cập nhật independently, và Safe Browsing behavior có thể cũng phụ thuộc on browsing context, treat Security Các vấn đề báo cáo itself as có thẩm quyền record của Điều gì Google có recorded và fixed cho của bạn trang web — không assume warning bạn personally có thể’t reproduce trong một trình duyệt có nghĩ là không có gì là sai, và không assume clearing báo cáo có nghĩ là mỗi consuming trình duyệt hoặc sản phẩm có caught lên tuy vậy.

Evidence for this claim Search warning labels and browser interstitial/download warnings are separate surfaces. Not every issue blocks Search: uncommon-download warnings, for example, can appear in Chrome without preventing the page or site from appearing in Google Search. Scope: web UI and Google Search reporting Confidence: high · Verified: Security issues report

Security Các vấn đề so với. Manual Actions

Đây là phân biệt đó trips lên phần lớn mọi người, so let sử dụng Google own boundary thay vì simplified nguyên nhân split.

Security Các vấn đềManual Actions
Ý nghĩtrang web là hacked, hoặc hosts nội dung/behavior đó có thể harm khách truy cậpreviewer determined trang web attempted để manipulate Google tìm kiếm chỉ mục
Typical nguyên nhânHacking, deceptive nội dung, hoặc malware/unwanted software — mà có thể là installed by hacker hoặc, đôi khi unknowingly, by trang web ownercủa bạn own SEO practices (unnatural links, thin nội dung, cloaking, sneaky các chuyển hướng)
Loại của vấn đềNgười dùng safetyTìm kiếm-chỉ mục manipulation
Người dùng-facing warningcó thể hiển thị Tìm kiếm label hoặc trình duyệt interstitialthường không visible warning — affected các trang là chỉ được xếp hạng thấp hơn hoặc omitted
Báo cáoSecurity Các vấn đề báo cáoManual Actions báo cáo
Review queueSecurity reviewManual-hành động reconsideration

They là tách biệt các báo cáo với tách biệt review queues — một site có thể có một, cả hai, hoặc neither, và đây là có thể cho đó hai để overlap (một hacked trang đó nhận stuffed với spammy links, ví dụ, có thể eventually surface trong cả hai các báo cáo). không reduce này để “someone else hacked me” (bản dịch) «ai đó khác hacked me» versus “I did my own spam” (bản dịch) «I đã làm my own spam» — đó real dividing line Google draws là điều gì đó báo cáo là protecting so với (người dùng, versus đó integrity of đó tìm kiếm chỉ mục), không ai gây ra điều này.

Triage và remediation

Front-load triage; understand categories thứ hai.

  1. xác nhận nó trong báo cáo. đọc chính xác mà category và mà sample các URL Google lists — nhưng treat những điều đó các URL as các ví dụ, không đầy đủ inventory. Google là rõ ràng đó list không phải nhất thiết hoàn tất, và some các vấn đề có thể hiển thị không sample các URL tại all, mà không có nghĩa là không có gì là affected. sử dụng URL Inspection on samples để see Điều gì Google thực ra fetched, sau đó look cho giống nhau vulnerability hoặc injected pattern elsewhere on trang web.
  2. Limit damage. Depending on severity, take trang web (hoặc affected section) offline hoặc behind maintenance chế độ so bạn dừng serving malware hoặc phishing để thực người dùng trong khi bạn hoạt động. tránh trực tiếp opening suspected infected trang trong thông thường trình duyệt — some attacks cloak nội dung dựa trên browsing context, so Điều gì bạn see có thể không match Điều gì Google recorded; sử dụng isolated tooling ( scanner, sandboxed environment, hoặc URL Inspection) thay vì.
  3. tìm và xóa injected nội dung. Spam các trang, injected scripts, rogue admin accounts, modified cốt lõi files.
  4. Close vulnerability. Đây là step đó decides liệu của bạn review truyền. Patch out-của-date plugin/CMS, rotate credentials, khắc phục insecure directory hoặc input đó được phép injection. Xóa symptom entry point, hoặc bạn nhận reinfected và review fails.
  5. Xử lý leftover được lập chỉ mục các URL. Injected spam các trang đó đã nhận được lập chỉ mục nên trả về 404 hoặc 410 so Google drops them theo thời gian (410 là touch nhanh hơn as tín hiệu). không leave them resolving với 200.
  6. CMS notes. On WordPress, thông thường suspects là outdated plugin/themes và yếu admin credentials — cập nhật mọi thứ, audit người dùng, và cân nhắc security plugin scan. On khác stacks, principle là giống hệt ngay cả nếu tooling không phải: patch, rotate, và close input đó là exploited.

Requesting security review

Khi mỗi flagged vấn đề là fixed trên all các trang, dùng Yêu cầu Review trong đó báo cáo. Google: “When all issues listed in the report are fixed in all pages, select Request Review in the Security Issues report.” (bản dịch) «Khi all các vấn đề listed trong đó báo cáo là fixed trong all các trang, select Yêu cầu Review trong đó Security Các vấn đề báo cáo.»

Document điều gì bạn đã làm. Google asks bạn để “provide more information on what you did to clean your site. For each category of hacked spam, include a brief explanation of how the site was cleaned.” (bản dịch) «cung cấp hơn information on điều gì bạn đã làm để sạch trang web của bạn. Cho mỗi category of hacked spam, bao gồm một brief lời giải thích of cách đó site đã là cleaned.» Google own ví dụ of good wording: “For Content injection hacked URLs, I removed the spam content and corrected the vulnerability by updating an out-of-date plugin.” (bản dịch) «Cho Nội dung injection hacked URLs, I đã xóa đó spam nội dung và corrected đó vulnerability by updating an out-of-date plugin.» Note cách điều này names cả hai đó cleanup và đó closed lỗ hổng.

On timing: Google hiện tại hướng dẫn là đó security review có thể take anywhere từ một vài days để một vài weeks để xử lý. Trước đó hướng dẫn (published riêng từ báo cáo own tài liệu) broke điều này xuống by vấn đề loại — phishing nhanh hơn, hacked-spam cases chậm hơn — và promised warnings clear trong 72 hours của approval. đó theo-loại breakdown và fixed 72-hour hình không phải Điều gì báo cáo hiện tại tài liệu trạng thái, so treat them as outdated thay vì schedule Bạn có thể rely on. Điều gì consistent: warning làm không disappear instant bạn khắc phục điều — nó clears chỉ sau khi review truyền, và ngay cả sau đó propagation trên mỗi trình duyệt, tìm kiếm kết quả, và Google sản phẩm không phải instant hoặc guaranteed để happen tại giống nhau moment mọi nơi. đã truyền review cũng không phải promise của restored thứ hạng, traffic, hoặc AI-khả năng hiển thị trên tìm kiếm — những điều đó là tách biệt outcomes review xử lý không cover.

một vài rules của road: submit sau khi, fully fixed và được ghi lại — re-submitting trước khi bạn’ve thực ra closed mọi thứ chỉ wastes review cycle. không đặt hard internal deadline khoảng cụ thể number của hours hoặc days; monitor báo cáo và của bạn trang web status thay vì repeatedly resubmitting.

Preventing reinfection

cleanup là chỉ half job. giữ CMS cốt lõi, plugin, và themes patched; enforce least-privilege on accounts và rotate bất kỳ credentials đó có thể có leaked; turn on 2FA cho admin logins; monitor cho unexpected new files hoặc người dùng; và periodically kiểm tra của bạn trang web status trong Google Safe Browsing trang web-status tool. vulnerability đó let them trong đầu tiên time là một họ’ll try again.

Add an expert note

Pin an expert quote

New person? Create their unclaimed profile at /admin/experts/ → Pin a quote first.