Blog · 6 min read

Google shows 'This site may be hacked': how to fix it

Published 2026-10-08

Seeing "This site may be hacked" under your site in Google results is alarming, and it costs clicks every day it stays. The good news is that it is fixable. Here is what it means and the order to work in.

The steps below use WordPress as the example, but Google shows this warning for any kind of website. On other platforms, the same order applies: change passwords, find the changed files or templates, remove the injected code, update the platform and its extensions, then ask Google for a review.

What the label means

Google adds the warning when it believes a third party has changed your site without your permission, usually to inject spam content or links. It is different from the red "Deceptive site ahead" screen (a Safe Browsing warning about phishing or malware), but the cleanup is similar and the two can appear together.

Google groups hacks into types such as content injection (hidden spam links or text), URL injection (new spam pages on your domain) and code injection (malicious scripts or malware). Knowing which type you have tells you where to look.

Step 1: Confirm in Search Console

Sign in to Google Search Console for your domain and open Security & Manual Actions → Security issues. It names the problem type and lists example URLs. If you have not verified your site yet, do that first: it is free and it is the only way to request a review later.

Step 2: Take a backup, then contain the damage

Step 3: Find what was changed

Step 4: Clean it properly

  1. Replace WordPress core, plugins and themes with clean copies from official sources. Delete anything you no longer use, and anything you downloaded from an unofficial site.
  2. Remove injected code, spam pages and spam users. Do not just hide the symptom.
  3. Update everything to the latest version, since an old plugin is the most likely way in.
  4. Reset the security keys in wp-config.php and make sure file permissions are sensible.
  5. Return a proper 404 or 410 status for spam URLs, then re-check the live pages in URL Inspection.

Step 5: Ask Google to review

When the site is clean, return to Security issues in Search Console, tick the box confirming you fixed the problem and choose Request review. Explain briefly what you found and what you changed. Reviews can take from a day or two up to a couple of weeks, and a request made before the site is really clean will be rejected and slow you down.

If the spam pages are still in search results, submit your updated sitemap and use the Removals tool for URLs you deleted.

Step 6: Make sure it does not return

If you are stuck, a good WordPress host or a security specialist can finish the cleanup, and it is worth the cost compared with weeks of lost traffic.