WordPress

”This site may be hacked” on Google — what to do now

The warning under your site in Google's results scares visitors away instantly. Here's how to get rid of it — and the underlying cause — step by step.

Few things damage a site as fast as the text ”This site may be hacked” under your link in Google’s search results. It means Google found signs of malicious code — and visitors don’t click. The good news: it can be removed. The bad news: only by fixing the cause, in the right order.

Why the warning appears

Google Safe Browsing continuously scans the web for harmful content. If it finds injected code, hidden redirects or spam pages on your WordPress site, it sets a flag. So the warning is a symptom — the infection itself sits in your files or database. Simply asking Google to remove the warning doesn’t work; if the site is still infected, it gets flagged again immediately.

Two versions of the flag

There are effectively two levels. ”This site may be hacked” means Google suspects content has been manipulated (often spam injections). A stronger warning — a red full-screen page saying the site may harm your computer — means Google found directly harmful content like malware or phishing. Both require the same thing: actually removing the underlying code.

How to remove it — in the right order

  • Clean first. Remove all malicious code, backdoors and unauthorized accounts. Request a review before the site is clean and it gets flagged again — and repeated flags make Google slower to trust the site.
  • Verify in Search Console. Under Security Issues you’ll see what Google found and example affected URLs — use them to confirm the cleanup hit the mark.
  • Request a re-review. Once the site is clean, ask Google to check again. It usually takes up to a few days before the warning disappears.

After the warning is gone

Getting rid of the flag isn’t the same as being protected. If the site gets infected again, the warning comes back — and the second time it often takes longer to remove. So rotate all passwords and keys, update core, themes and plugins, and close the entry point the attacker used. Otherwise you’ll soon be back in the same place.

Don’t let the guesswork cost days

The hard part is being sure the site is truly clean — miss a single backdoor and everything gets flagged again and you start over. We run a full WordPress cleanup with a blocklist check against Google Safe Browsing and request removal for you. Want to keep the site off blocklists in future? Managed WordPress hosting with monitored updates is the simplest way.

Bygg på ett moln du faktiskt äger.

Ingen bindningstid. En körande VM innan du betalar en krona.