How to Fix “Deceptive Site Ahead” in WordPress (4 Steps)

unflagdomain Team·UPDATED June 19, 2026

If WordPress is showing a red "Deceptive site ahead" warning, your site has almost certainly been hacked — usually through an outdated plugin — and Google Safe Browsing flagged it. Fixing it takes four steps: scan with a security plugin, remove the injected files, harden your logins, then request a review in Google Search Console.

TL;DR: WordPress accounts for the vast majority of infected CMS sites Sucuri cleaned (Sucuri, 2023), and 93% of WordPress flaws come from plugins and themes (Patchstack, 2024) — not WordPress itself. To clear "Deceptive site ahead": scan, remove injected content, update and harden everything, then request a Safe Browsing review in Search Console. There's no instant fix.

This guide is written for WordPress owners, not developers. You don't need to touch code for most of it — a good security plugin does the heavy lifting. Let's clear the warning the right way so it doesn't come straight back.

Why does WordPress get the "deceptive site ahead" warning so often?

Because WordPress is the biggest target on the web. It runs about 43.4% of all websites (W3Techs, 2025), and Sucuri found that the vast majority of the infected CMS sites it cleaned were WordPress (Sucuri, 2023). When a site gets hacked, attackers inject spam or phishing pages, and Google Safe Browsing flags the domain — triggering the red screen.

The single biggest cause is out-of-date software. Patchstack reported that 93% of WordPress security flaws come from third-party plugins and themes, not WordPress core (Patchstack, 2024), and Sucuri found 39.1% of compromised sites were running outdated software at the time of infection (Sucuri, 2024). An abandoned plugin you forgot about is the most common way in.

So this isn't a sign you did something careless — it's the predictable result of running the world's most popular CMS. The warning is Google protecting visitors, and the page is still online underneath it. For the bigger picture on what the warning means across all platforms, see our pillar guide on the deceptive site ahead warning.

Step 1: Scan your WordPress site with a security plugin

Start by finding the infection, because you can't remove what you can't see. Install a reputable security plugin — Wordfence, Sucuri, or MalCare are the common choices — and run a full malware scan. With WordPress making up the vast majority of infected CMS sites (Sucuri, 2023), these scanners are tuned for exactly the injected files you're dealing with.

A scan typically flags injected PHP files, modified core files, suspicious redirects, and unfamiliar code in your theme's functions.php or header.php. Write down what it finds — you'll want a record of what you cleaned when you request the Google review later.

If you'd rather first confirm who's flagging you (Google may not be the only one), you can check your domain against the major blocklists for free before you start cleaning. Not sure the warning is even a hack versus something simpler? Our plain-language guide to what to do when your website is flagged as dangerous helps you tell the difference.

Step 2: Remove the injected files and bad users

Once the scan identifies the malicious content, remove it. A security plugin's cleanup feature can quarantine or delete injected files automatically; if you're comfortable in your hosting file manager, you can also delete flagged files manually. The goal is a site with zero injected pages, redirects, or scripts left behind.

While you're cleaning, check two things attackers leave behind:

  • Unknown admin users. Go to Users in your dashboard and delete any administrator account you don't recognize — a common backdoor.
  • Malicious redirects. Injected code often redirects visitors to spam or phishing sites. The scan will flag these; remove every one.

This is the step people rush, and rushing it is the number one reason the warning comes back. Google re-scans when you request a review — if any injected content remains, it simply re-flags you and you start over. Clean thoroughly now to avoid repeating the whole wait. If your site shows Google's "this site may be hacked" label in search results too, the same cleanup clears both.

Step 3: Harden WordPress so it doesn't get re-flagged

After cleaning, close the door the attacker used — otherwise you'll be back here in a month. Since 93% of WordPress flaws trace to plugins and themes (Patchstack, 2024), updating them is the highest-impact thing you can do. A clean site with the same outdated plugin is an open invitation.

Work through this hardening checklist:

  • Update everything. WordPress core, every plugin, and every theme to the latest version.
  • Delete what you don't use. Remove inactive plugins and themes entirely — dormant code still gets exploited.
  • Remove nulled (pirated) plugins. These are a frequent malware source; replace them with legitimate versions.
  • Reset all passwords. WordPress admins, hosting, FTP, and database. Use strong, unique ones.
  • Turn on two-factor authentication for every admin account — most security plugins include it.

Think of this as the part that actually keeps the warning gone. Cleaning removes today's infection; hardening prevents the next one. Skip it, and a re-flag is a matter of time.

Step 4: Request a Google Safe Browsing review

With the site clean and hardened, ask Google to re-check it. This is the only official way to clear the warning, and it's manual — there's no button that removes it instantly and no automated API. Open Google Search Console, find the Security Issues report, confirm you've fixed the problems, and submit the review request with a short note on what you cleaned.

Google re-crawls on its own schedule, usually within a few days for a clean site. We walk through the exact Search Console steps in how to remove your site from Google Safe Browsing.

One more thing worth knowing: a hacked WordPress site is often flagged by several security vendors at once, not just Google — and each has its own separate review process. In our experience running unflag, this is the part owners underestimate most: we scan a domain across 124 active security vendors (antivirus engines, web blocklists, and search-engine/RBL sources), and a compromised WordPress site frequently lights up far more than the one warning the owner actually noticed. Rather than chase every form by hand after you've cleaned up, you can have unflagdomain email every flagging vendor a removal request for €39, with your address as the reply-to so any vendor replies go straight to your inbox. Each request is written uniquely per vendor and dispatched over a roughly one-hour window — we've found that identical, blasted-out copy gets treated as spam, which is exactly what you don't want when you're asking to be trusted again. Vendors that only take a web form (like AVG or ESET) or a manual review (Google Safe Browsing, through Search Console) become guided cards in your dashboard instead, since there's no API to submit to. We don't scan or clean your site — this guide is the cleanup — but once it's done, the dashboard shows you the real sent, bounced, and failed count for every vendor, and we re-send anything that bounces. No one can guarantee a vendor will delist, but we guarantee the request is sent.

// FAQ
  • Your WordPress site was almost certainly hacked and Google Safe Browsing flagged it. WordPress runs ~43% of all sites and accounts for 96.2% of infected CMS sites Sucuri cleaned in 2024, usually via an outdated plugin or theme that let attackers inject spam or phishing pages.

  • Four steps: scan with a security plugin (Wordfence, Sucuri, MalCare), remove the injected files and any unknown admin users, update and harden everything, then request a review in Google Search Console under Security Issues. Google re-crawls and lifts the warning once the site is clean.

  • Reputable security plugins like Wordfence, Sucuri, or MalCare can scan for and remove injected malware. They're tuned for WordPress, which makes up 96.2% of infected CMS sites. Whichever you pick, run a full scan, clean what it finds, then update every plugin and theme.

  • Almost always because the original hole wasn't closed. With 93% of WordPress flaws coming from plugins and themes, a clean site with one outdated plugin gets re-infected and re-flagged. Update everything, delete unused and nulled plugins, reset passwords, and enable two-factor authentication.

  • Usually a few days after you request a review in Search Console, though Google sets its own pace. The main delay is requesting a review while injected content is still present, which restarts the process. Clean thoroughly first, then submit a clear request describing the fix.