← All guides

Deceptive site ahead: what it means and the fix order

Chrome is not warning about your design. Google Safe Browsing found phishing or malware on your domain. Here is what the red screen means, how to find the cause, and how to get the flag removed without it coming back.

16 September 2026, 4 min read. From two cleanups where the owner found out from a customer, not from Google.

The red screen has two versions, and they mean different things. “Deceptive site ahead” means Google Safe Browsing classed your site as social engineering: a page on your domain is pretending to be something else, usually a login form or a fake update prompt. “The site ahead contains malware” means it found code that pushes downloads or redirects visitors. Both come from the same list, both block most of your visitors in Chrome, Firefox, Safari and Edge, and both tend to appear a week or two after the actual break-in.

What Google actually saw

Safe Browsing does not flag a site for being ugly, slow or out of date. It flags an address it crawled and found doing one of these:

  • A phishing page inside your uploads folder or a random new folder, dressed up as a bank or a mail provider
  • A redirect that sends some visitors, often on mobile or arriving from Google, to another site
  • Injected script that loads from a domain you have never heard of
  • Spam pages in a language your site does not use

Search Console tells you the exact addresses. Open it, go to Security issues, and write those addresses down before you touch anything. That list is your map.

The order that works

We have seen people clean the visible page, request a review the same hour, get denied, and start again. The order matters.

  1. Take a snapshot first. Files and database, as they are, infected. If something goes wrong during the cleanup you want to be able to look back at what was there. Most hosts do this in one click.
  2. Find how they got in. Not the symptom, the door. Nearly always it is one of: an admin account with a weak or reused password, a plugin with a known hole that was never updated, or a second site on the same hosting account that was already infected. Check the last login times in your users list, the modification dates of files in wp-content, and whether every plugin is on its current version.
  3. Clean, or restore, then patch. If you have a clean backup from before the break-in and little has changed since, restoring it is faster and more certain than hunting. Either way, update WordPress, every plugin and every theme immediately after, and delete anything you do not use.
  4. Change every password. All admin users, the database password in wp-config.php, the hosting panel, SFTP, and the secret keys in wp-config.php. Skipping this is the most common reason a site is flagged again a month later: the attacker still has a key.
  5. Check the addresses from step one. Every one should now return a normal page or a “not found”. Open them in a private window and from a phone, because some redirects only fire for mobile visitors.
  6. Request a review. Back in Search Console, under Security issues, confirm you have fixed the problem and describe what you did in two or three plain sentences. Reviews usually clear within a few days. A denied review means the crawler still found something, and Search Console will say what.

What we check that most guides skip

  • The uploads folder, for PHP files. wp-content/uploads should hold images and documents, never a .php file. Any .php in there is a backdoor.
  • Scheduled tasks. WordPress has its own task scheduler. Attackers add a task that reinfects the site every few hours, so the cleanup looks done for a day and then it is back.
  • The database, not only the files. Injected script in the options table and in post content, and a changed site address value, live in the database and survive a file restore.
  • Other sites on the same account. One infected site on a shared account can reinfect the others from the inside. Clean them all, or move the clean one.

After the flag is gone

The flag goes, the traffic comes back over a week or so, and the temptation is to stop there. The site was flagged because something was open. Put a firewall in front of it, turn on the automatic security updates, add two-factor login for every admin, and have something check the site every day for changes. That is the difference between a cleanup and a fix.

If you are not sure whether your site is currently flagged, or what is exposed, run it through our scanner. It checks Safe Browsing and the outdated software that usually caused the problem.

See where your own site stands.

The scanner checks the things this guide talks about, in about ten seconds, no signup.

Tell us about the site.

A straight answer and a fixed quote, usually the same day.