
How to fix the "This site may be hacked" warning in Google?
- Sajjad
- WordPress, Security
- 14 Sep, 2026
To fix the "This site may be hacked" warning in Google, verify your site in Google Search Console, open the Security issues report to see what Google detected, and then find and remove the hacked content, which is often spam pages, injected links, or cloaked redirects. Close the vulnerability that let attackers in, change your credentials, and submit a review request in Search Console. Once Google confirms the site is clean, the warning is removed, usually within a few days.
Seeing "This site may be hacked" under your site in Google search results is alarming, and it can quickly hurt your traffic because many people won't click through. This guide explains what the warning means, how it differs from other Google security warnings, how to track down the hacked content on a WordPress site, and how to get the label removed as quickly as possible.
What Does "This Site May Be Hacked" Mean?
Google shows this label in search results when its systems believe a third party has compromised your site and added content or changed pages without your permission. It's most often caused by spam hacks rather than malware that attacks visitors directly.
Typical causes include:
- Spam pages: Thousands of new pages created on your domain, often about pharmaceuticals, gambling, counterfeit goods, or in Japanese or other languages (the "Japanese keyword hack").
- Injected links: Hidden spam links added to existing posts, pages, or theme files.
- Cloaking: Showing spam content to Googlebot while showing normal content to regular visitors.
- Changed titles and descriptions: Search results for your pages show spammy titles that don't match your real content.
- Sneaky redirects: Visitors arriving from Google are redirected to other sites.
How It Differs From Other Warnings
This label is different from Google Safe Browsing warnings:
- "This site may be hacked": Appears in search results only. Visitors can still click and reach your site. Usually related to spam.
- "This site may harm your computer" and red browser interstitials like "Dangerous site" or "Deceptive site ahead": Come from Safe Browsing and relate to malware, phishing, or unwanted software. These are more severe and block visitors in browsers.
If you see a red interstitial in Chrome, you're dealing with a Safe Browsing flag, which follows a similar cleanup process but has its own review path in Search Console. This article focuses on the hacked-site label.
Step 1: Verify Your Site in Google Search Console
Search Console is where Google tells you exactly what it found and where you'll request a review.
- Go to Google Search Console: Sign in with a Google account.
- Add a property: A Domain property (verified through a DNS TXT record) covers all subdomains and protocols. A URL prefix property can be verified with an HTML file, a meta tag, Google Analytics, or Google Tag Manager.
- Verify ownership: Follow the instructions for your chosen method. If attackers previously verified themselves as owners, you'll see them under Settings > Users and permissions. Remove any owners you don't recognize, and remove their verification tokens (such as unfamiliar HTML verification files or meta tags) from your site.
A DNS TXT verification record looks like this:
example.com. 3600 IN TXT "google-site-verification=abc123yourtokenhere"
Add it in your DNS provider's dashboard, not in WordPress.
Step 2: Check the Security Issues Report
In Search Console, go to Security & Manual Actions > Security issues. Google lists the issue type, such as:
- Hacked: URL injection: New pages added to your site.
- Hacked: Content injection: Spam content or links added to existing pages.
- Hacked: Code injection: Code added to pages, often redirects or hidden spam.
The report often includes sample URLs. These examples are your starting point, but they aren't a complete list. Treat them as clues.
Also check Security & Manual Actions > Manual actions. Sometimes a hacked site also receives a manual action for spam, which requires its own reconsideration request.
Step 3: Find the Hacked Content
Search Google for Spam on Your Domain
Use a site: search to see what Google has indexed:
site:example.com viagra
site:example.com casino
site:example.com "cheap"
site:example.com japan
Replace the keywords with whatever spam topics appear in your case. Also search site:example.com alone and scroll through the results looking for pages you didn't create.
Use URL Inspection
Cloaking means you may not see the spam when you visit a page yourself. In Search Console, use the URL Inspection tool on a sample URL and click Test Live URL, then View Tested Page. This shows you the HTML Google actually receives, which may include spam content you can't see in your browser.
You can also fetch a page with a Googlebot user agent from the command line to check for user-agent-based cloaking:
curl -s -A "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" https://example.com/ | grep -iE "casino|viagra|loan|<a href" | head
Some hacks check Google's real IP addresses rather than the user agent, so the URL Inspection tool is the most reliable check.
Check the Sitemaps Report
Attackers sometimes submit their own sitemaps so Google finds spam pages faster. In Search Console, go to Indexing > Sitemaps and remove any sitemap you didn't add. Also check your server for unexpected sitemap files.
Look for Common WordPress Hack Patterns
On a WordPress site, spam content usually comes from one of these places:
- New files in the root or uploads: PHP files that generate spam pages on the fly.
- Modified
.htaccessrules: Rewrite rules that route spam URLs to a malicious script or redirect search visitors. - Injected theme code: Code in
header.php,footer.php, orfunctions.phpthat adds hidden links or cloaked content. - Database injections: Spam posts, links in existing posts, or malicious values in the
wp_optionstable. - Rogue plugins or mu-plugins: Malicious code disguised as a plugin.
Step 4: Clean the Site
Before you start, take a full backup of files and the database so you can undo mistakes.
Scan for Malware
Run a server-side scan with Wordfence, MalCare, or a similar plugin, plus a remote scan with Sucuri SiteCheck. Note every flagged file.
Replace Core, Plugins, and Themes
The most reliable way to remove injected code is to replace software with clean copies:
# Check and replace WordPress core files
wp core verify-checksums
wp core download --version=$(wp core version) --force --skip-content
# Check plugins against official checksums
wp plugin verify-checksums --all
Reinstall any plugin that fails verification, and download fresh copies of premium plugins and themes from their vendors.
Check .htaccess
Open .htaccess in your site root and look for unfamiliar rewrite rules, especially ones that check HTTP_REFERER or HTTP_USER_AGENT for search engines. A clean default WordPress .htaccess looks like this:
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress
Keep legitimate rules added by caching or security plugins, but remove anything you can't explain.
Remove Spam Content From the Database
Search for spam keywords and injected scripts. Replace wp_ with your table prefix, and adjust the keywords:
SELECT ID, post_title, post_status, post_date
FROM wp_posts
WHERE post_content LIKE '%casino%'
OR post_content LIKE '%viagra%'
OR post_content LIKE '%<script%'
ORDER BY post_date DESC;
Review each result, then delete spam posts or edit out injected links. WP-CLI is handy for removing spam posts in bulk once you've confirmed their IDs:
wp post delete 1501 1502 1503 --force
Remove Hidden Users and Backdoors
Check for administrator accounts you don't recognize and delete them. Look for PHP files in wp-content/uploads and unknown files in wp-content/mu-plugins. If the hack keeps returning, you likely have a backdoor, so check those hiding spots carefully.
Step 5: Fix the Root Cause
If you don't close the entry point, the hack will come back and Google may flag you again. Common causes include:
- Outdated plugins or themes with known vulnerabilities.
- Nulled plugins or themes.
- Weak or reused admin passwords.
- Compromised hosting or FTP credentials.
- Another infected site on the same hosting account.
Update WordPress core, plugins, and themes. Remove anything you don't use. Then change all passwords (WordPress, database, hosting, SFTP), enable two-factor authentication, and regenerate your security keys:
wp config shuffle-salts
Step 6: Handle the Spam URLs
After cleanup, spam URLs should return a 404 (Not Found) or 410 (Gone) status. Check a few with curl:
curl -I https://example.com/some-spam-page-url/
If they return 200 OK, something is still generating them. Don't redirect spam URLs to your homepage, since that can look like a soft 404 to Google. Let them return 404 or 410 naturally.
For urgent cases, you can use the Removals tool in Search Console to temporarily hide specific spam URLs from search results while Google recrawls. This hides them for about six months but doesn't remove them from the index permanently, so the pages must also return 404 or 410.
Don't block spam URLs in robots.txt. Google needs to crawl them to see that they're gone.
Step 7: Request a Review
Once the site is clean and secure:
- Go to Security & Manual Actions > Security issues in Search Console.
- Check the box confirming you've fixed the issues.
- Click Request Review.
- Describe what you found and what you did. Be specific: the type of hack, what you removed, how the attacker got in, and what you changed to prevent it happening again.
Google typically processes hacked-site reviews within a few days, though timing varies. If the review is rejected, Google will usually give you more details or sample URLs. Fix the remaining issues and submit again.
If you also had a manual action, submit a separate reconsideration request under Manual actions.
Step 8: Recover Your Search Presence
Removing the warning doesn't instantly restore rankings. To speed things up:
- Resubmit your real sitemap under Indexing > Sitemaps.
- Request indexing for your most important pages using URL Inspection.
- Monitor the Pages report to watch spam URLs drop out of the index over time.
- Check search result titles with
site:searches to confirm spam titles are gone.
Recovery is usually gradual. It depends on how long the hack was active and how many spam pages were indexed.
Preventing the Warning From Coming Back
- Keep everything updated and enable auto-updates for trusted plugins.
- Use a web application firewall like Wordfence, Sucuri, or Cloudflare.
- Monitor Search Console: Enable email notifications so you hear about security issues quickly.
- Scan regularly: Schedule malware scans and review the results.
- Use an activity log: Plugins like WP Activity Log help you spot new users and file changes.
- Take regular off-site backups so you can recover fast if something happens again.
FAQ: The This Site May Be Hacked Warning
After you clean the site and request a review in Search Console, Google usually processes it within a few days. Search results may take a little longer to update as Google recrawls your pages.
Not reliably. Search Console shows what Google detected and lets you request a review. Without it, you'd have to wait for Google to recrawl and reassess your site on its own, which can take much longer.
Many hacks use cloaking, showing spam only to search engines or visitors arriving from Google. Use the URL Inspection tool's live test in Search Console to see what Googlebot receives.
No. The hacked label appears only in search results and usually relates to spam. Red browser warnings come from Google Safe Browsing and indicate malware, phishing, or unwanted software, which blocks visitors more aggressively.
Google will usually provide more details or example URLs. Look for remaining spam pages, injected code, or backdoors, fix them, and submit another review with a clear explanation of what you changed.
No. Let spam URLs return a 404 or 410 status. Redirecting them can look like a soft 404 and slow down Google's cleanup of the index.
In most cases, yes, though it can take time. Resubmitting your sitemap, requesting indexing for key pages, and keeping the site clean all help speed up recovery.
Conclusion
The "This site may be hacked" warning is Google's way of telling searchers that someone has tampered with your site, usually by adding spam pages, links, or cloaked content. Fixing it starts in Google Search Console, where the Security issues report shows what Google found. From there, locate the hacked content, replace compromised files with clean copies, clean the database, and remove any hidden users or backdoors.
Before requesting a review, close the vulnerability that let the attacker in and change every credential. Then submit a clear, specific review request and give Google time to recrawl. With careful cleanup and a few preventive habits, such as updates, a firewall, regular scans, and Search Console alerts, you can remove the warning and keep it from coming back.


