Type something to search...
How to fix the "This site may be hacked" warning in Google?

How to fix the "This site may be hacked" warning in Google?

To fix the "This site may be hacked" warning in Google, verify your site in Google Search Console, open the Security issues report to see what Google detected, and then find and remove the hacked content, which is often spam pages, injected links, or cloaked redirects. Close the vulnerability that let attackers in, change your credentials, and submit a review request in Search Console. Once Google confirms the site is clean, the warning is removed, usually within a few days.

Seeing "This site may be hacked" under your site in Google search results is alarming, and it can quickly hurt your traffic because many people won't click through. This guide explains what the warning means, how it differs from other Google security warnings, how to track down the hacked content on a WordPress site, and how to get the label removed as quickly as possible.

What Does "This Site May Be Hacked" Mean?

Google shows this label in search results when its systems believe a third party has compromised your site and added content or changed pages without your permission. It's most often caused by spam hacks rather than malware that attacks visitors directly.

Typical causes include:

  • Spam pages: Thousands of new pages created on your domain, often about pharmaceuticals, gambling, counterfeit goods, or in Japanese or other languages (the "Japanese keyword hack").
  • Injected links: Hidden spam links added to existing posts, pages, or theme files.
  • Cloaking: Showing spam content to Googlebot while showing normal content to regular visitors.
  • Changed titles and descriptions: Search results for your pages show spammy titles that don't match your real content.
  • Sneaky redirects: Visitors arriving from Google are redirected to other sites.

How It Differs From Other Warnings

This label is different from Google Safe Browsing warnings:

  • "This site may be hacked": Appears in search results only. Visitors can still click and reach your site. Usually related to spam.
  • "This site may harm your computer" and red browser interstitials like "Dangerous site" or "Deceptive site ahead": Come from Safe Browsing and relate to malware, phishing, or unwanted software. These are more severe and block visitors in browsers.

If you see a red interstitial in Chrome, you're dealing with a Safe Browsing flag, which follows a similar cleanup process but has its own review path in Search Console. This article focuses on the hacked-site label.

Step 1: Verify Your Site in Google Search Console

Search Console is where Google tells you exactly what it found and where you'll request a review.

  1. Go to Google Search Console: Sign in with a Google account.
  2. Add a property: A Domain property (verified through a DNS TXT record) covers all subdomains and protocols. A URL prefix property can be verified with an HTML file, a meta tag, Google Analytics, or Google Tag Manager.
  3. Verify ownership: Follow the instructions for your chosen method. If attackers previously verified themselves as owners, you'll see them under Settings > Users and permissions. Remove any owners you don't recognize, and remove their verification tokens (such as unfamiliar HTML verification files or meta tags) from your site.

A DNS TXT verification record looks like this:

example.com.  3600  IN  TXT  "google-site-verification=abc123yourtokenhere"

Add it in your DNS provider's dashboard, not in WordPress.

Step 2: Check the Security Issues Report

In Search Console, go to Security & Manual Actions > Security issues. Google lists the issue type, such as:

  • Hacked: URL injection: New pages added to your site.
  • Hacked: Content injection: Spam content or links added to existing pages.
  • Hacked: Code injection: Code added to pages, often redirects or hidden spam.

The report often includes sample URLs. These examples are your starting point, but they aren't a complete list. Treat them as clues.

Also check Security & Manual Actions > Manual actions. Sometimes a hacked site also receives a manual action for spam, which requires its own reconsideration request.

Step 3: Find the Hacked Content

Search Google for Spam on Your Domain

Use a site: search to see what Google has indexed:

site:example.com viagra
site:example.com casino
site:example.com "cheap"
site:example.com japan

Replace the keywords with whatever spam topics appear in your case. Also search site:example.com alone and scroll through the results looking for pages you didn't create.

Use URL Inspection

Cloaking means you may not see the spam when you visit a page yourself. In Search Console, use the URL Inspection tool on a sample URL and click Test Live URL, then View Tested Page. This shows you the HTML Google actually receives, which may include spam content you can't see in your browser.

You can also fetch a page with a Googlebot user agent from the command line to check for user-agent-based cloaking:

curl -s -A "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" https://example.com/ | grep -iE "casino|viagra|loan|<a href" | head

Some hacks check Google's real IP addresses rather than the user agent, so the URL Inspection tool is the most reliable check.

Check the Sitemaps Report

Attackers sometimes submit their own sitemaps so Google finds spam pages faster. In Search Console, go to Indexing > Sitemaps and remove any sitemap you didn't add. Also check your server for unexpected sitemap files.

Look for Common WordPress Hack Patterns

On a WordPress site, spam content usually comes from one of these places:

  • New files in the root or uploads: PHP files that generate spam pages on the fly.
  • Modified .htaccess rules: Rewrite rules that route spam URLs to a malicious script or redirect search visitors.
  • Injected theme code: Code in header.php, footer.php, or functions.php that adds hidden links or cloaked content.
  • Database injections: Spam posts, links in existing posts, or malicious values in the wp_options table.
  • Rogue plugins or mu-plugins: Malicious code disguised as a plugin.

Step 4: Clean the Site

Before you start, take a full backup of files and the database so you can undo mistakes.

Scan for Malware

Run a server-side scan with Wordfence, MalCare, or a similar plugin, plus a remote scan with Sucuri SiteCheck. Note every flagged file.

Replace Core, Plugins, and Themes

The most reliable way to remove injected code is to replace software with clean copies:

# Check and replace WordPress core files
wp core verify-checksums
wp core download --version=$(wp core version) --force --skip-content

# Check plugins against official checksums
wp plugin verify-checksums --all

Reinstall any plugin that fails verification, and download fresh copies of premium plugins and themes from their vendors.

Check .htaccess

Open .htaccess in your site root and look for unfamiliar rewrite rules, especially ones that check HTTP_REFERER or HTTP_USER_AGENT for search engines. A clean default WordPress .htaccess looks like this:

# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress

Keep legitimate rules added by caching or security plugins, but remove anything you can't explain.

Remove Spam Content From the Database

Search for spam keywords and injected scripts. Replace wp_ with your table prefix, and adjust the keywords:

SELECT ID, post_title, post_status, post_date
FROM wp_posts
WHERE post_content LIKE '%casino%'
   OR post_content LIKE '%viagra%'
   OR post_content LIKE '%<script%'
ORDER BY post_date DESC;

Review each result, then delete spam posts or edit out injected links. WP-CLI is handy for removing spam posts in bulk once you've confirmed their IDs:

wp post delete 1501 1502 1503 --force

Remove Hidden Users and Backdoors

Check for administrator accounts you don't recognize and delete them. Look for PHP files in wp-content/uploads and unknown files in wp-content/mu-plugins. If the hack keeps returning, you likely have a backdoor, so check those hiding spots carefully.

Step 5: Fix the Root Cause

If you don't close the entry point, the hack will come back and Google may flag you again. Common causes include:

  • Outdated plugins or themes with known vulnerabilities.
  • Nulled plugins or themes.
  • Weak or reused admin passwords.
  • Compromised hosting or FTP credentials.
  • Another infected site on the same hosting account.

Update WordPress core, plugins, and themes. Remove anything you don't use. Then change all passwords (WordPress, database, hosting, SFTP), enable two-factor authentication, and regenerate your security keys:

wp config shuffle-salts

Step 6: Handle the Spam URLs

After cleanup, spam URLs should return a 404 (Not Found) or 410 (Gone) status. Check a few with curl:

curl -I https://example.com/some-spam-page-url/

If they return 200 OK, something is still generating them. Don't redirect spam URLs to your homepage, since that can look like a soft 404 to Google. Let them return 404 or 410 naturally.

For urgent cases, you can use the Removals tool in Search Console to temporarily hide specific spam URLs from search results while Google recrawls. This hides them for about six months but doesn't remove them from the index permanently, so the pages must also return 404 or 410.

Don't block spam URLs in robots.txt. Google needs to crawl them to see that they're gone.

Step 7: Request a Review

Once the site is clean and secure:

  1. Go to Security & Manual Actions > Security issues in Search Console.
  2. Check the box confirming you've fixed the issues.
  3. Click Request Review.
  4. Describe what you found and what you did. Be specific: the type of hack, what you removed, how the attacker got in, and what you changed to prevent it happening again.

Google typically processes hacked-site reviews within a few days, though timing varies. If the review is rejected, Google will usually give you more details or sample URLs. Fix the remaining issues and submit again.

If you also had a manual action, submit a separate reconsideration request under Manual actions.

Step 8: Recover Your Search Presence

Removing the warning doesn't instantly restore rankings. To speed things up:

  • Resubmit your real sitemap under Indexing > Sitemaps.
  • Request indexing for your most important pages using URL Inspection.
  • Monitor the Pages report to watch spam URLs drop out of the index over time.
  • Check search result titles with site: searches to confirm spam titles are gone.

Recovery is usually gradual. It depends on how long the hack was active and how many spam pages were indexed.

Preventing the Warning From Coming Back

  • Keep everything updated and enable auto-updates for trusted plugins.
  • Use a web application firewall like Wordfence, Sucuri, or Cloudflare.
  • Monitor Search Console: Enable email notifications so you hear about security issues quickly.
  • Scan regularly: Schedule malware scans and review the results.
  • Use an activity log: Plugins like WP Activity Log help you spot new users and file changes.
  • Take regular off-site backups so you can recover fast if something happens again.

FAQ: The This Site May Be Hacked Warning

After you clean the site and request a review in Search Console, Google usually processes it within a few days. Search results may take a little longer to update as Google recrawls your pages.

Not reliably. Search Console shows what Google detected and lets you request a review. Without it, you'd have to wait for Google to recrawl and reassess your site on its own, which can take much longer.

Many hacks use cloaking, showing spam only to search engines or visitors arriving from Google. Use the URL Inspection tool's live test in Search Console to see what Googlebot receives.

No. The hacked label appears only in search results and usually relates to spam. Red browser warnings come from Google Safe Browsing and indicate malware, phishing, or unwanted software, which blocks visitors more aggressively.

Google will usually provide more details or example URLs. Look for remaining spam pages, injected code, or backdoors, fix them, and submit another review with a clear explanation of what you changed.

No. Let spam URLs return a 404 or 410 status. Redirecting them can look like a soft 404 and slow down Google's cleanup of the index.

In most cases, yes, though it can take time. Resubmitting your sitemap, requesting indexing for key pages, and keeping the site clean all help speed up recovery.


Conclusion

The "This site may be hacked" warning is Google's way of telling searchers that someone has tampered with your site, usually by adding spam pages, links, or cloaked content. Fixing it starts in Google Search Console, where the Security issues report shows what Google found. From there, locate the hacked content, replace compromised files with clean copies, clean the database, and remove any hidden users or backdoors.

Before requesting a review, close the vulnerability that let the attacker in and change every credential. Then submit a clear, specific review request and give Google time to recrawl. With careful cleanup and a few preventive habits, such as updates, a firewall, regular scans, and Search Console alerts, you can remove the warning and keep it from coming back.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper