My website is clean but Google still shows a security warning: what should I do?

Your website has been cleaned but Google still shows a warning? Learn why it stays, how to request a review properly and what else to check before it clears.

Open a support ticket

Your website was infected, the malware has been removed, and the site looks normal again. Yet Google still shows a red warning page, a "This site may be hacked" label in search results, or a message in Search Console.

This is a common situation, and it does not necessarily mean the cleanup failed. Google does not remove a security warning automatically when the website changes. In most cases, someone has to tell Google that the problem is fixed and ask it to check.

There are also other reasons a warning can remain: the cleanup may be incomplete, a different service may be blocking the site, or the warning may concern only some pages or a subdomain.

This guide explains why the warning stays, how to request a review that is likely to succeed, and what else to check. If the warning has just appeared and the site has not been cleaned yet, start with our guide on why Google has marked a website as dangerous.

Why does Google still show the warning?

Google flags a website when its systems detect hacked content, malware, phishing or other harmful behavior. Removing the cause on your side does not immediately change Google's assessment. Several things can keep the warning in place.

Nobody has requested a review

For most security issues, the warning stays until a review is requested in Google Search Console and Google confirms the problem is gone. If nobody did this after the cleanup, the warning may remain for a long time.

The cleanup was not complete

Google checks the whole website, not just the pages it listed as examples. If some infected files, spam pages or redirects remain, the review will be rejected and the warning will stay.

Malware can also return soon after a cleanup if the entry point was not closed. See why malware keeps coming back for the common reasons.

Some pages are still affected

The warning may concern only specific URLs, a folder or a subdomain. The homepage may be clean while old spam pages or an infected subdomain are still active.

The warning comes from another service

Google is not the only service that blocks websites. Other browsers, antivirus software, security filters on business networks and email providers use their own lists. These are separate from Google, and each has its own process.

Search results have not been updated yet

Even after Google clears a security issue, search results may show old titles or descriptions for a while, until Google recrawls the affected pages.

How do you know which warning you are dealing with?

Before acting, identify exactly where the warning appears.

  • A full red page in Chrome before the site loads usually comes from Google Safe Browsing.
  • A "This site may be hacked" note below your Google search result is a search result label.
  • A warning in Microsoft Edge may come from Microsoft Defender SmartScreen, which is separate from Google.
  • A block from antivirus software or a company firewall comes from that vendor's own list.
  • Emails bouncing or going to spam may relate to email blocklists, which are different again.

Take a screenshot of each warning, note the browser or tool, the device and the exact URL. This tells you which service needs to be contacted.

What is the most important check?

If you have access to Google Search Console, open your property and go to:

Security & Manual Actions → Security Issues

This report is the most reliable reference for what Google currently thinks. It shows:

  • whether a security issue is still active
  • the type of issue, such as malware, hacked content or social engineering
  • example URLs
  • whether a review has been requested and its outcome

If the report says no issues were detected but users still see a warning, the problem may concern another property (for example, a subdomain) or a different service.

If you do not have access to Search Console, find out who manages it: your agency, developer or marketing team. You can also verify ownership of the website yourself.

How do you request a review properly?

A review request is a short statement to Google explaining what happened and what you did about it.

Before requesting the review

Make sure that:

  • every issue listed in the report has been addressed, not only the example URLs
  • the entry point has been found and closed
  • spam pages return a "not found" (404) or "gone" (410) status
  • unknown users, backdoors and malicious scheduled tasks have been removed
  • WordPress, plugins and themes are up to date
  • the website has been scanned again after the cleanup
  • other subdomains and websites in the same account have been checked

Requesting a review too early is the most common reason for a rejection.

What to write

Keep the description clear and factual. Explain:

  • what the problem was
  • how the website was compromised, if known
  • what was removed or repaired
  • what was done to prevent it happening again
  • how you verified that the site is clean

A request saying only "the site is clean now" gives Google nothing to work with.

After submitting

Google may take from a few days to several weeks, depending on the type of issue. Avoid submitting new requests while one is pending. If the request is rejected, Search Console usually includes examples of what is still detected. Fix those, check the whole site again, and only then request another review.

What about other blocklists?

If the Google report is clear but warnings persist elsewhere, check other services.

Common sources include:

  • Microsoft Defender SmartScreen, used by Microsoft Edge and Windows
  • antivirus and internet security vendors, many of which offer a way to report a site that is no longer dangerous
  • network security filters used by companies and schools
  • email blocklists, if your domain sent spam during the compromise

Each provider has its own lookup and delisting process. Most require the same thing as Google: a clean site and a clear explanation.

Google's Transparency Report also includes a Safe Browsing site status check, which shows Google's current assessment of a URL without needing Search Console.

What if the warning only affects some URLs?

This is common. Google may flag:

  • a specific page with malicious code
  • a folder of spam pages
  • a subdomain such as a shop, a blog or an old test site
  • a file available for download

Check the example URLs in the Security Issues report, then look at the rest of the site for similar patterns. If you use a Search Console property that covers only one version of the site, such as https://www.example.com, problems on other subdomains may not appear there. A Domain property covers all subdomains.

What should you avoid?

Avoid:

  • requesting a review before the cleanup is complete
  • submitting repeated review requests while one is pending
  • assuming the warning is a mistake without checking
  • cleaning only the URLs listed as examples
  • ignoring subdomains or other websites in the same hosting account
  • telling customers to click past the warning
  • confusing Google warnings with antivirus or email blocklists

When should you ask for support?

Ask for help when:

  • the review request was rejected
  • you are not sure the cleanup was complete
  • the warning came back after being removed
  • you cannot access Search Console
  • warnings appear in several browsers or security tools
  • the website handles orders or personal data and is losing customers

A rejected review usually means something specific is still present. Finding it is often faster with experience of how these infections hide.

How D4Hub can help

D4Hub can:

  • check Search Console and identify exactly what Google is still flagging
  • verify that the cleanup is complete across files, database and subdomains
  • find and remove remaining malware, spam pages or backdoors
  • close the entry point to reduce the risk of reinfection
  • prepare a clear review request and submit it on your behalf
  • check other blocklists and handle delisting requests
  • test that the website works correctly after the cleanup

You can ask for support at any stage, including after a review has been rejected.

Open a support ticket

For hands-on users: confirming the site is clean and requesting a review

These checks are for people comfortable with Search Console, a hosting file manager or SFTP, and WP-CLI.

Before making any further changes, take a full backup of the files and database. The checks below are mostly read-only.

Read the Security Issues report carefully

In Search Console, go to Security & Manual Actions → Security Issues. For each issue, note:

  • the issue type
  • the example URLs
  • the detection date
  • whether a previous review was rejected, and why

Open each example URL with the URL Inspection tool and use Test live URL to see what Google receives now. If the live test still shows spam or injected code, the cleanup is not finished.

Check for remaining spam pages

Search Google with site:example.com combined with terms unrelated to your business, and check the subdomains you use, for example site:shop.example.com. Confirm that former spam URLs now return a 404 or 410 status:

curl -sI https://example.com/suspicious-url/

The first line of the output shows the status code.

Re-scan the website

Run the security checks again after the cleanup:

wp core verify-checksums
wp plugin verify-checksums --all
find wp-content/uploads -type f -name "*.php"
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
wp cron event list

Plugin checksums only work for plugins from the WordPress.org directory. Any unexpected result deserves attention before requesting the review.

Check other subdomains and properties

List the subdomains you use, such as www, shop, blog or staging, and check each one. If you have a Domain property in Search Console, its Security Issues report covers them all. If you only have URL-prefix properties, check each one.

Check Google Safe Browsing status

Use the Safe Browsing site status check in Google's Transparency Report to see Google's current assessment of your domain. It is a useful second opinion alongside Search Console.

Request the review

When everything is resolved, return to the Security Issues report and select Request Review. Write a short, factual description, for example:

The site was compromised through an outdated plugin. We removed injected
files from wp-content/uploads and the theme, deleted spam pages (now 404),
removed an unknown administrator, updated all plugins, changed all
passwords and security keys, and verified files against official checksums.

Adapt it to what actually happened. Then wait for the result without submitting new requests.

If a review is rejected and you cannot see why, stop. D4Hub can review the situation and help find what is still flagged.

FAQFrequently asked questions

After a review is requested, Google states that it can take from a few days to several weeks, depending on the type of issue. The warning will not normally disappear before the review is completed.

In some cases Google may recrawl the site and clear the issue on its own, but this is not guaranteed and can take much longer. Requesting a review is the recommended approach.

Usually because Google still detects a problem somewhere on the site. Check the report for example URLs, look for similar pages, and verify subdomains. Malware may also have returned after the cleanup.

No. Google, browser vendors, antivirus companies and email providers keep separate lists. Being cleared by Google does not automatically clear the others.

Once the warning is removed, rankings often recover over time, but this cannot be guaranteed. Spam pages that were indexed may also need to be removed from search results.

You can verify ownership of the website, or ask whoever manages it. D4Hub can help identify who has access and set it up if needed.

Yes. With the right access, D4Hub can check the cleanup, prepare the description and submit the review request.