My antivirus or browser is blocking my own site
Chrome shows a red "dangerous site" screen, or your visitors' antivirus cuts access to your store: this isn't a Google mistake, it's a database of compromised sites that now includes yours.
The shapes the block can take
- A full-screen red warning in Chrome, Firefox or Edge reading "Dangerous site" or "Deceptive site ahead" before any access to the page
- A consumer antivirus (Norton, Avast, Kaspersky, Bitdefender) cuts the connection or shows an alert when loading the site
- The site looks fine to you internally, but customers report a full block, often from different networks or devices than yours
- Google Search Console shows a security message about hacked or deceptive content detected on the site
- Searching your store's name in Google shows "This site may be hacked" directly under the result
How a site ends up on a blacklist
The warnings shown by browsers and by consumer antivirus software rely on shared blacklists, the best known being Google Safe Browsing. A site is added automatically as soon as one of Google's automated crawls detects malicious code or a suspicious redirect on one of its pages. It isn't a manual decision made against a particular merchant: it's a scan that found a signal matching a known compromise pattern, and the listing happens automatically.
Other browsers, and most consumer antivirus tools, check that same list, or equivalent lists built on the same principle, which is why the block often appears simultaneously across several different tools used by different visitors.
A very frequent cause behind this kind of detection is an outdated component. According to Sucuri's 2023 Hacked Website & Malware Threat Report, 39.1% of infected content management applications were out of date at the time of infection: a minority, then, but a large enough share to make it the first thing to check. A plugin, theme or CMS core version left without updates remains a common entry point.
The process for lifting the warning
-
Confirm the blacklist listing
Google Search Console's "Security Issues" section shows whether Google has detected a problem on the site and gives an overview of the type of content flagged.
-
Fix the actual cause before requesting a review
A review request submitted before the cause is fixed gets rejected, or worse, the site is flagged again shortly after if the infection is still active.
-
Check every page, not just the homepage
The automated scan may have detected an issue on a deep page of the site, invisible from the homepage and therefore easy to miss during a quick check.
-
Submit a review request
Once cleanup is confirmed, the request is made directly through Google Search Console. It triggers a new crawl by Google, which then decides whether to lift the warning.
Related pages
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.