Seeing "This site may be hacked" under your site in Google results is alarming, and it costs clicks every day it stays. The good news is that it is fixable. Here is what it means and the order to work in.
The steps below use WordPress as the example, but Google shows this warning for any kind of website. On other platforms, the same order applies: change passwords, find the changed files or templates, remove the injected code, update the platform and its extensions, then ask Google for a review.
What the label means
Google adds the warning when it believes a third party has changed your site without your permission, usually to inject spam content or links. It is different from the red "Deceptive site ahead" screen (a Safe Browsing warning about phishing or malware), but the cleanup is similar and the two can appear together.
Google groups hacks into types such as content injection (hidden spam links or text), URL injection (new spam pages on your domain) and code injection (malicious scripts or malware). Knowing which type you have tells you where to look.
Step 1: Confirm in Search Console
Sign in to Google Search Console for your domain and open Security & Manual Actions → Security issues. It names the problem type and lists example URLs. If you have not verified your site yet, do that first: it is free and it is the only way to request a review later.
Step 2: Take a backup, then contain the damage
- Back up the site as it is now, for reference.
- If your host offers it, switch on maintenance mode while you work so visitors are not sent to spam or malware.
- Change passwords for WordPress admins, hosting, FTP/SFTP and the database straight away, and remove any admin users you do not recognise.
Step 3: Find what was changed
- Run Test live URL in URL Inspection on the example pages and compare what Google sees with what you see. Differences point to cloaking.
- Search the page source for hidden links (
display:none,left:-9999px) and unfamiliar scripts. - Look for new or changed files, especially PHP in
wp-content/uploads, unknown files in the site root and odd rules in.htaccess. - Check the database (
wp_posts,wp_options) for injected content and unknown users. - Run a security scanner for a second opinion on malware signatures and file integrity. UrKavach's free check can spot spam, hidden links and malicious scripts on public pages in about 30 seconds.
Step 4: Clean it properly
- Replace WordPress core, plugins and themes with clean copies from official sources. Delete anything you no longer use, and anything you downloaded from an unofficial site.
- Remove injected code, spam pages and spam users. Do not just hide the symptom.
- Update everything to the latest version, since an old plugin is the most likely way in.
- Reset the security keys in
wp-config.phpand make sure file permissions are sensible. - Return a proper 404 or 410 status for spam URLs, then re-check the live pages in URL Inspection.
Step 5: Ask Google to review
When the site is clean, return to Security issues in Search Console, tick the box confirming you fixed the problem and choose Request review. Explain briefly what you found and what you changed. Reviews can take from a day or two up to a couple of weeks, and a request made before the site is really clean will be rejected and slow you down.
If the spam pages are still in search results, submit your updated sitemap and use the Removals tool for URLs you deleted.
Step 6: Make sure it does not return
- Turn on automatic updates for plugins and themes you trust, and review them weekly.
- Use two-factor login for every admin.
- Keep tested off-site backups so a future clean-up is a restore, not a hunt.
- Monitor continuously for new admin accounts, changed files, hidden links and downtime, with alerts to your email or Slack. The sooner you know, the less Google sees.
If you are stuck, a good WordPress host or a security specialist can finish the cleanup, and it is worth the cost compared with weeks of lost traffic.
