Available for projects & agency overflow · Quick reply, from the person who does the work

My antivirus or browser is blocking my own site

Chrome shows a red "dangerous site" screen, or your visitors' antivirus cuts access to your store: this isn't a Google mistake, it's a database of compromised sites that now includes yours.

Describe my issue Send a message

The shapes the block can take

  • A full-screen red warning in Chrome, Firefox or Edge reading "Dangerous site" or "Deceptive site ahead" before any access to the page
  • A consumer antivirus (Norton, Avast, Kaspersky, Bitdefender) cuts the connection or shows an alert when loading the site
  • The site looks fine to you internally, but customers report a full block, often from different networks or devices than yours
  • Google Search Console shows a security message about hacked or deceptive content detected on the site
  • Searching your store's name in Google shows "This site may be hacked" directly under the result

How a site ends up on a blacklist

The warnings shown by browsers and by consumer antivirus software rely on shared blacklists, the best known being Google Safe Browsing. A site is added automatically as soon as one of Google's automated crawls detects malicious code or a suspicious redirect on one of its pages. It isn't a manual decision made against a particular merchant: it's a scan that found a signal matching a known compromise pattern, and the listing happens automatically.

Other browsers, and most consumer antivirus tools, check that same list, or equivalent lists built on the same principle, which is why the block often appears simultaneously across several different tools used by different visitors.

A very frequent cause behind this kind of detection is an outdated component. According to Sucuri's 2023 Hacked Website & Malware Threat Report, 39.1% of infected content management applications were out of date at the time of infection: a minority, then, but a large enough share to make it the first thing to check. A plugin, theme or CMS core version left without updates remains a common entry point.

The process for lifting the warning

  1. Confirm the blacklist listing

    Google Search Console's "Security Issues" section shows whether Google has detected a problem on the site and gives an overview of the type of content flagged.

  2. Fix the actual cause before requesting a review

    A review request submitted before the cause is fixed gets rejected, or worse, the site is flagged again shortly after if the infection is still active.

  3. Check every page, not just the homepage

    The automated scan may have detected an issue on a deep page of the site, invisible from the homepage and therefore easy to miss during a quick check.

  4. Submit a review request

    Once cleanup is confirmed, the request is made directly through Google Search Console. It triggers a new crawl by Google, which then decides whether to lift the warning.

Related pages

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

symptomes
depuis-quand
sauvegarde
acces-admin (facultatif)
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

Why don't I see the warning when I open the site myself?
Some browsers and antivirus tools cache their own verdict, or your device may be temporarily excluded from detection. Not seeing a warning on your end doesn't mean the site is clean.
How long until the warning disappears once the site is cleaned?
That depends on how Google processes the review request; I can't commit to a specific timeframe since it's outside my control.
Can I request a review before finishing the cleanup?
It's not advisable: a rejected request can delay the next review, and the site stays blocked for your visitors in the meantime.
Does the block also affect my emails and adverts?
Potentially yes, a blacklist listing can hurt email deliverability and get ad campaigns rejected by some ad networks while the site is flagged.
Is keeping an extension up to date enough to avoid this kind of block?
It significantly lowers the risk without eliminating it entirely. According to the 2023 Sucuri report, a large share of compromised sites had an outdated component, but other causes exist too, such as a compromised password.