Dangerous site

What Chrome's "Dangerous site" Warning Means

Shoppers and owners
The short answer

It means Google Safe Browsing has flagged that site as unsafe, and Chrome is blocking it before it loads. Chrome now uses the single heading Dangerous site for malware, phishing and unwanted software, so the paragraph underneath the heading is what tells you which threat was actually detected. Do not click through, and do not enter any details on the site.

Seeing this on a site? Check it now.

Paste the address and we will tell you exactly which check is failing, and why. Free, and you do not have to open the site yourself.

If you were just trying to buy something

Click Back to safety and close the tab. Do not click Details and then proceed. The warning is there because Google found something harmful, not because the site is slow or unfinished.

Read the paragraph under the heading before you do anything else. It tells you whether Chrome expects the site to steal your details, install something on your device, or change how your browser behaves.

If you were trying to reach a shop you actually use, do not trust the link that brought you here. Search for the business yourself, or type the address in directly. If you want to know whether the site is genuinely flagged, use the checker above. It asks Safe Browsing for you so you never have to open the page.

If this is your site

Your site is being blocked in Chrome, and almost certainly in other browsers too. Traffic will collapse while this is live. In most cases the site was compromised and is now serving something it did not serve last week.

Work out which threat was found first. Open Search Console, then Security & Manual Actions, then Security Issues. Clean the site properly, then request a review. Requesting a review on a site that is still infected just restarts the clock.

One heading now, three different meanings

This is the part most guides get wrong.

Chrome used to show three separate red warnings depending on what Safe Browsing found. Deceptive site ahead for phishing, The site ahead contains malware, and The site ahead contains harmful programs for unwanted software. Those three headings no longer exist in current Chromium.

They have been replaced by a single heading: Dangerous site. The threat type did not go away. It moved. The difference now lives entirely in the paragraph printed below the heading, which is still worded differently for each of the three cases.

So if you want to know what Chrome actually detected, stop looking at the heading and read the paragraph.

The three paragraphs, word for word

These are the exact strings Chrome shows. Match the one on your screen to work out which threat was flagged.

Phishing and social engineering:

Attackers on the site you tried visiting might trick you into installing
software or revealing things like your passwords, phone, or credit card
numbers.

This is the old "Deceptive site ahead" case. Safe Browsing thinks the site is built, or has been altered, to fool you into handing something over.

The malware paragraph

If Chrome shows this text instead, the flag is for malware:

Attackers on the site you tried visiting might install harmful software
that steals or deletes things like your passwords, photos, messages, or
credit card numbers.

This is the old "The site ahead contains malware" case. Something on the site is trying to put software onto your device.

The unwanted software paragraph

And this third version is the unwanted software case:

Attackers on the site you tried visiting might trick you into installing
harmful software that affects the way you browse.

This is the old "The site ahead contains harmful programs" case. Think hijacked search settings, injected ads, and downloads that quietly bundle extras. The buttons on all three versions are "Back to safety" and "Details".

Why you still see the old wording everywhere

Because it is still out there.

Older versions of Chrome still show the original headings, and so do a number of other Chromium based browsers that have not picked up the change. People also still search for the old phrasing, because that is what they saw the last time it happened to them.

Google is inconsistent about it too. Google's own Search Central documentation still refers to Deceptive site ahead, even though current Chrome does not show that string. So you can read Google's guidance and see one thing, then look at your browser and see another. Both are real.

We keep the legacy pages up for that reason. If you saw the older wording, read "Deceptive site ahead" or "The site ahead contains malware".

Why a site gets flagged in the first place

A red warning is not a judgement about the business. It is a statement about what was found on the site at the time it was checked. Usually one of these:

  • The site was hacked and now serves harmful content the owner knows nothing about. This is by far the most common case for a real business.
  • A third-party script was compromised, so the site loads something harmful it does not host itself. Ad tags, chat widgets and analytics snippets are all candidates.
  • Downloads on the site were tampered with, so an installer that used to be clean now carries something extra.
  • The site is a deliberate scam, built to impersonate a real business.
  • Deceptive elements were added, such as fake download buttons or ads dressed up as system warnings.

Getting the warning lifted, in order

The sequence matters more than the speed. Every step below is wasted if the site is still infected when Google looks at it.

  1. 1.Verify ownership in Google Search Console if you have not already, then open Security & Manual Actions and then Security Issues. Google lists the specific URLs it objected to and the category it assigned.
  2. 2.Check for unauthorised users on the property. Google specifically tells owners to look, because attackers often add themselves to Search Console to keep visibility and control. Remove anyone you do not recognise.
  3. 3.Remove the harmful content at the exact URLs Google named. Check recently modified files, unfamiliar admin accounts, and any script you did not add yourself.
  4. 4.Close the way in. Update your platform and plugins, rotate every password and key, and turn on two-factor authentication. Skipping this gets you reinfected within days.
  5. 5.Request a review from the Security Issues report and describe your fixes. Google asks for a description of what you actually did.

What happens next

Google's stated timeline is that a review can take from a few days to a few weeks to complete. There is no queue to jump and no way to escalate it.

Resubmitting repeatedly does not help. If anything it hurts, because each submission you make before the site is genuinely clean ends in a rejection.

While you wait, keep monitoring. Reinfection during a pending review is common, and it is the single most likely reason a review comes back with the warning still in place. A scheduled check on your own site catches it early. That is what TrustedOrigin is built to do.

Frequently asked questions

Which Chrome version changed the wording?

We are not going to name a version, because the exact milestone is not something we have confirmed. What we can say is that current Chromium string files use "Dangerous site" for all three threat types, and no longer contain the three older headings. If you are seeing an old heading, you are on an older build or a different Chromium browser.

How do I tell whether it is malware or phishing now?

Read the paragraph under the heading. Phishing says attackers might trick you into revealing things like passwords or card numbers. Malware says attackers might install harmful software that steals or deletes your data. Unwanted software says harmful software that affects the way you browse. The heading is identical in all three cases.

Can I click through the warning?

You should not. Safe Browsing flagged the page because of what is on it, and proceeding gives that content the chance to run. If you need something from the business, find them another way. If you only want to know whether the flag is real, use the checker on this page instead of opening the site.

My site is flagged but I cannot see anything wrong. What now?

Injected content is usually hidden from you. It is often served only to logged-out visitors, or only to people arriving from a search engine, or only on mobile. Go to the exact URLs listed in the Security Issues report rather than browsing your own site normally, and check the raw files rather than the rendered page.

Will fixing it restore my search rankings?

The warning is lifted once the review passes, and the block in Chrome goes with it. Rankings usually recover as Google recrawls, but that is a separate process with its own pace. The faster you clean and pass review, the less ground there is to make up.

Related errors

See all errors explained →

Stop guessing what is wrong.

Run a free check on any site and see every trust and security signal at once, in plain English.

Run a free check Browse the fixes