Skip to content
weballin

weballin DIGIWIKI

Security Issues

Security issues are items that appear when Search Console detects hacking, malware, or phishing on your site. You should check for CMS plugin vulnerabilities immediately upon detection and submit a review request, as search results will display a warning label and a blocking screen will appear in Chrome.

weballin

Google Safe Browsing scans billions of URLs to detect malware, unwanted software, phishing, and social engineering content. If this system detects a problem on your site, it will appear in the Search Console security issues report, a 'This site may be unsafe' warning label will appear in Google search results, and a red warning screen will appear when accessing the Chrome browser.

The most common cause is hacking through third-party plugins or theme vulnerabilities. Hacked sites are abused for automatically creating spam pages, distributing malware, and stealing user data. For WordPress and other CMS-using sites, the key to prevention is keeping plugins and themes up to date and regularly changing administrator account passwords.

Search Console navigation: → Security & Manual Actions → Security issues. If there are no problems, ‘No problems detected’ is displayed. If detected, the problem type and example URL are displayed, and after correction, re-confirmation is requested through 'Request for Review'.

Key takeaways

  • Detects four types of security problems: hacking, malware, phishing, and social engineering.
  • When a problem is detected, a warning label is displayed in Google search results and click-through rates plummet.
  • When accessing the Chrome browser, a red warning screen (Safe Browsing blocked) may be displayed.
  • After fixing the security issue, you can request a rescan from Google by submitting a ‘Review Request’.
  • Although it's in the same menu as Manual Actions, it's a different issue.

References

Frequently asked questions

I've detected a security issue. Where do I start?

Check the Search Console Security Issues report for example URLs and visit those URLs directly to see what content was injected. WordPress users scan with security plugins such as Wordfence or Sucuri, and update plugins, themes, and WordPress core to the latest versions. Another option is to check the server files directly via FTP or contact the hosting company's security team.

I removed the malware, but when will the Google warning disappear?

The warning will be cleared once Google completes the rescan after submitting your review request. This usually takes several days to several weeks. You can check the current status in real time by searching the domain in Google Safe Browsing Transparency Report (transparencyreport.google.com).