Google says your site may be hacked.
“This site may be hacked” is a label Google puts under your search result when it believes “a hacker might have changed some of the existing pages on the site or added new spam pages”. Visitors can still click through; it is a warning, not a block. Only you can get it removed: find the hacked pages in Search Console's Security issues report, close the hole the attacker used, and request a review once the whole site is clean. Google says reviews take several days or weeks.
Our scan can't see this label; Search Console is the only place Google shows it to you. What the scan shows is whether a hacked site has also landed on antivirus, web-filter or Safe Browsing lists, which keep blocking it after Google's label is gone.
Free, no signup. Shows which security vendors list the domain right now.
| What searchers see | “This site may be hacked” under your result in Google Search. The result still opens; it is a warning, not a block. |
|---|---|
| Why Google shows it | Google believes “a hacker might have changed some of the existing pages on the site or added new spam pages”. In Search Console it is usually reported as Hacked content. |
| Who can remove it | Only the site owner: Search Console → Security issues → Request review, “when your entire website is clean and secure”. |
| How long it takes | Google says most reviews take several days or weeks. It removes the label after checking that the site is fixed. |
| Can our scan see it? | No. It sees Safe Browsing (the red browser warning), antivirus engines and web filters. |
| What €39 covers | Not Google's review: that one is your click, and we prepare the text. It covers every other vendor that lists the domain: a separately written request to each that takes email, prepared text for the rest. |
// sources: Google Search Help: “This site may be hacked” · Search Console Help: Security issues report
Then Google's label is the only thing to fix, and you don't need us. The review is free, in Search Console. Follow the steps below and keep your €39.
If antivirus engines or web filters list the domain too, they keep blocking it on visitors' computers and company networks after Google lifts the label. Each has its own inbox or form. That part is what we do.
Steps 3 and 4 run in parallel. Google's review and the other vendors don't wait for each other.
- 01
Open the Security issues report.
Verify the site in Google Search Console, then open Security & Manual Actions → Security issues. Google lists the issue (usually Hacked content) with sample URLs.
- 02
Find everything the attacker added.
Injected pages are rarely linked from your menu. Start from Google's sample URLs, then look for spam words in a site: search, unknown admin users, and files changed on the server around the time it started.
- 03
Close the way in, then request the review.
Update the plugin, theme or CMS that was exploited, remove accounts you don't recognise, rotate every password and key. Google's own advice: fix the hole first, or the site is likely to be reinfected. Then request a review in Security issues once the whole site is clean.
- 04
Ask the other vendors at the same time.
A hacked site can end up on antivirus and web-filter lists too, and those don't follow Google. Each has its own inbox or form and decides on its own schedule. This is the step we do for €39.
// in detail: the full guide to the hacked label · cleaning a hacked website · signs your website was hacked
After you pay €39, once, for this domain: we re-scan it, cache ignored, and send a separately written plain-text removal request to every vendor that takes one by email, within 48 hours and in practice within the hour, with your address as Reply-To. Form-only vendors become dashboard cards with the text prepared. If Google Safe Browsing lists the domain too, that becomes a card with the exact text for Search Console. Replies go to your inbox, not ours.
It does not clean malware. It guarantees the dispatch, not the outcome. If the scan we run right after payment finds no vendor flagging your domain, we refund the full €39 automatically. No subscription, no account.
// free scan · payment only if vendors flag you and there are requests to send
pricing · refund policy · the vendors and how each is contacted
| Day 0 | 12 vendors flagging. Payment, re-scan, 12 separately written requests sent over one hour. |
|---|---|
| Day 3 | 8 of 12 vendors no longer returned the domain. |
| Day 7 | Still 8 of 12. The same eight. |
| Day 15 | All 12 cleared. The verdicts we read were last updated on day 15, so that is the latest day by which every vendor had cleared. |
One dispatch is one dispatch: a case, not a rate. It was a false-positive flag on a site that had never been hacked, which is not the situation most people arrive here in. Vendors re-scan when they review, so a hacked site has to be clean before any of this moves. The customer's own account of that order, in his words:
“ESET flagged our client's website even though it had never been hacked. I wasn't sure whether I could trust an online service with this, but I decided to give it a try. Two weeks later, all 12 vendors that had flagged the site, including ESET, had cleared it.”
// full readings: the case study · in our September 2026 data the median flagged domain carried 11 listings, Google's among them: the report, vendor by vendor
Yes. The label sits under your result in Google Search; it is a warning, not a block. If Google Safe Browsing lists the domain as well, browsers show a full-page red warning instead, and that is a different case.
Check that you are looking at a property that covers the whole domain. A Domain property includes every subdomain and both http and https; the hacked pages may sit on a subdomain your URL-prefix property doesn't cover.
Google says most reviews take several days or weeks, and it removes the label after it has checked that the site is fixed. We don't promise a date.
No one but the site owner can request Google's review; it is a manual step in Search Console. We prepare the text for it. The €39 covers the other security vendors that list the domain.
Then the way in was never closed: an old admin account, a leftover backdoor file, an unpatched plugin. The cleanup removed what the attacker added, not how they got in. Find that before the next review.
// related: the hack keeps coming back · the Search Console review, step by step