Why does my antivirus or Google flag my own website as "dangerous"?
What that red warning on your own site really means, why it appears even on a "normal" site, and how to clean it up and request a review.
You open your own website and, instead of your homepage, you get a red screen: "Deceptive site ahead" or "Dangerous site." Or your antivirus simply blocks access. It's an ugly feeling — like someone seized your business overnight.
The good news is that this is almost always fixable. The warning isn't a permanent punishment; it's a temporary label placed by an automated safety system. But to lift it you have to do things in the right order: first understand why it appeared, then clean the actual cause, and only at the end request a review. If you request the review before cleaning, you make it worse — and the next attempt takes longer. Let's go through it step by step.
What the warning actually means (and who shows it)
Behind the "Deceptive site ahead" or "Dangerous site" messages sits Google Safe Browsing — a shared safety list used not only by Chrome, but also by Firefox, Safari and many antivirus programs. It isn't a personal punishment from Google. It's a single database that several programs check at once.
When your site lands on that list, every visitor using those browsers sees the red screen before entering. The main categories:
- "Malware" — harmful code on your pages;
- "Deceptive / phishing" — pages that appear to steal data;
- "Unwanted software" — suspicious downloads.
Your antivirus can also block locally, independently of Google, if it detects a script. In both cases, the label lifts once you clean up and request a re-check.
Why your own site of all sites got flagged
In most cases the site really was compromised — even if it looks perfectly normal to you. The malicious code is often hidden, or only triggers for mobile visitors or people arriving from Google. Common causes:
- A hacked site: someone injected redirects, pharma spam or hidden phishing pages. This is the number-one cause.
- An outdated CMS, theme or plugins (an old WordPress is the classic target).
- An admin account with a weak or stolen password.
- An infected third-party script: an ad, a widget, a plugin from a developer who abandoned it.
- A download file flagged as malware.
- A false positive: sometimes the antivirus is simply wrong — especially on new sites, sites with a login form, or on shared hosting where an infected "neighbour" taints the shared IP.
How to diagnose the problem
Don't guess — look where the system tells you exactly what it found:
- Google Search Console → Security & Manual Actions → Security Issues. Here Google shows what it detected and sample pages. If you don't have an account, add it now (verify via DNS or a file — it's free).
- Google's Safe Browsing Site Status report, where you check your domain's current status.
- VirusTotal — paste the URL and see which engines flag it and why.
Then look at your code and files: strange redirects, hidden iframes, unknown admin users, recently modified files. Test the site from a phone and in an incognito window — the bad code often only shows under certain conditions, not while you're logged in on desktop.
How to clean the site, step by step
Do things in this order:
- Back up the current state (even infected) — as evidence, in case you break something.
- Change ALL passwords: CMS admin, hosting/cPanel, FTP, database, email.
- Update the CMS, themes and plugins; delete anything you don't use.
- Find and remove the injected code: scan with a tool (on WordPress — Wordfence, Sucuri, MalCare) or compare files against a clean version.
- Delete unknown admin users and suspicious cron jobs.
- If you have a clean backup from before the infection, restore it — often the fastest route.
Don't just hide the symptom (the redirect). If you don't find the entry point, the infection returns within days. If you're unsure, get a specialist involved before requesting a review — a rejected request slows you down.
How to request a review (and how long it takes)
Only after you're sure the site is clean:
- In Search Console → Security Issues → "Request Review." Briefly describe what you found and what you cleaned.
- For an antivirus false positive: each has a reporting form (Google Safe Browsing, Norton, McAfee, Avast, etc.). Submit the URL and explain briefly.
As for timing, Google's re-check for malware or deceptive content usually takes a few days. Don't send repeated requests — you reset the queue and delay the answer.
The most important warning: if the site is still infected when you request the review, the request is rejected, and next time the process takes longer. Clean everything first, verify again, then submit.
How to stop it from happening again
Once it's clean, keep it that way:
- Keep the CMS, themes and plugins always updated — or choose a platform that doesn't depend on dozens of plugins.
- Automatic backups, stored off the server.
- Strong passwords plus two-factor authentication.
- A valid SSL certificate and HTTPS everywhere, with no mixed content.
- Fewer plugins means fewer doors in.
Many small-business sites hit this precisely because they run on a WordPress with dozens of plugins left untouched for years. At MPO Web Studio we build fast sites with a small attack surface and maintenance included, delivered remotely across the country — and we build you a free demo first, so you see the result before paying anything. If you're stuck right now with a red screen on your own site, message us on WhatsApp and we'll help you clean it and request the review.
Frequently asked questions
Google flagged my site, but it looks perfectly normal to me. Why?+
Because many infections are hidden or conditional: the bad code only shows to mobile visitors, people arriving from Google, or from certain countries — not to you when you're logged in on desktop. That's why you must check in Search Console and incognito, not just with the naked eye.
How long until the warning disappears?+
Once the site is clean and you request a review, Google usually responds within a few days. The red screen goes away when the re-check passes. If you request it before cleaning fully, the request is rejected and everything drags out.
Does this hurt my Google ranking (SEO)?+
While you're on the list, traffic drops because people see the warning and leave. After cleaning and a review, the situation recovers, but rebuilding visitor trust can take longer than lifting the technical label itself.
I'm sure it's a false positive. What do I do?+
First check objectively in Search Console and on VirusTotal — sometimes what looks like a false positive is a real backdoor. If it truly is an error, submit the URL through the antivirus's or Safe Browsing's reporting form and briefly explain the situation.
I cleaned it, but the infection keeps coming back. Why?+
You almost certainly didn't close the entry point: a stolen password, a vulnerable plugin, or a backdoor left in a file. You removed the symptom, not the cause. Change all passwords, update everything and scan deeply — or get help from someone who finds the source.
7 mistakes that drive clients away from your website
Leave your email and get the guide right here, instantly. No spam.
Want to see what your business's website could look like?
Message us on WhatsApp and we'll prepare a FREE demo website with your business name. See it first — decide after.