The heading you are looking at may already be retired
Chrome used to show three separate red warnings, one per threat type. The site ahead contains malware was the malware one. There was also Deceptive site ahead for phishing and The site ahead contains harmful programs for unwanted software.
Current Chromium has consolidated all three into one heading, Dangerous site. The malware wording still exists, but it is now the paragraph below the heading rather than the heading itself.
Both are worth knowing about. Older Chrome versions and other Chromium browsers still show the original heading, and Google's own Search Central documentation still uses the old phrasing in places. Our page on the current "Dangerous site" warning covers the newer version, and "Deceptive site ahead" covers the phishing case.
What Chrome actually says about malware
Whichever heading you get, this is the paragraph that identifies the threat as malware:
Attackers on the site you tried visiting might install harmful software
that steals or deletes things like your passwords, photos, messages, or
credit card numbers.The buttons are "Back to safety" and "Details". Compare this against the phishing and unwanted software paragraphs, which are worded differently. Since Chrome consolidated the headings, this paragraph is the main way to tell which threat was detected.
Why a trusted shop can suddenly serve malware
This is the part shoppers find hardest to believe, and it is the most important thing on this page. A site can be completely legitimate and still be flagged for malware.
The site does not have to be malicious. It only has to be compromised. And when it is, the people it serves malware to are its own customers.
- →The site was hacked. Someone got in through an outdated plugin, a stolen password, or a vulnerable theme, and injected code into pages that were previously clean.
- →A third-party script was compromised. The site loads a widget, ad tag or analytics snippet from somewhere else, and that somewhere else was breached. The site is serving the harmful code without hosting it.
- →Downloads were tampered with. An installer or document that used to be clean now carries something extra. Everyone who downloads it is affected.
- →An old, forgotten part of the site was targeted. A staging copy, an abandoned subdirectory, or a legacy install nobody has updated in years.
- →The hosting account was compromised rather than the site itself, so several sites on the same account get flagged at once.
Checking a site without opening it
The safest way to find out whether a site is genuinely flagged is to never load it in the first place.
Paste the address into the checker on this page. We query Safe Browsing on your behalf and report what it says, along with the rest of the site's trust and security signals. You get the answer, your browser never touches the page.
This matters for owners too. If you are trying to confirm whether the flag has lifted after a review, checking from outside is more reliable than loading your own site while logged in, because injected content is frequently hidden from administrators.
If it is your site: clean first, then ask
Google reviews the site as it finds it. If the malware is still there when the reviewer looks, the warning stays and you have burned days.
- 1.Open Search Console, verify ownership if you have not, then go to Security & Manual Actions and then Security Issues. Google names the specific URLs and the category it detected. Work from that list, not from guesswork.
- 2.Check for unauthorised users on the property. Google explicitly warns owners to look. Attackers often add themselves to Search Console so they can watch the recovery and keep access. Remove anyone you do not recognise, and revoke any verification method you did not set up.
- 3.Remove the malware. Check recently modified files, unfamiliar admin accounts, scheduled tasks you did not create, and every third-party script in your templates. Restoring a known-good backup from before the infection is usually faster than cleaning by hand.
- 4.Close the way in. Update the platform, themes and plugins. Rotate every password, database credential, API key and FTP login. Turn on two-factor authentication. If you skip this you will be reinfected, often within a day.
- 5.Request a review from the Security Issues report, and describe your fixes. Google asks you to explain what you changed rather than just clicking a button, and a vague request is more likely to come back rejected.
How long the review takes
Google's own wording is that a review can take from a few days to a few weeks to complete. That is the whole answer. There is no priority queue, no support line, and no way to make it faster.
Do not resubmit while a review is pending. It does not speed anything up, and repeated requests on a site that is still infected simply produce repeated rejections.
The one thing that does shorten the outage is being clean the first time you ask. Spend the extra day on the clean-up. It is cheaper than a second review cycle with a red warning live on your storefront.
Frequently asked questions
Is it safe to visit if I am careful?
No. Do not visit a site while Safe Browsing has it flagged for malware, and do not click through the warning to check for yourself. The warning exists because loading the page is the risk. If you need to know its status, use the checker on this page, which queries Safe Browsing without opening the site.
Why does Chrome say "Dangerous site" instead?
Chrome consolidated its three red warnings into one heading. Malware, phishing and unwanted software now all appear under "Dangerous site", with the explanatory paragraph underneath describing the specific threat. Older Chrome versions and some other Chromium browsers still show the original per-threat headings.
I already downloaded a file from the site. What should I do?
Do not open or run it. Delete it, empty the recycle bin or trash, then run a scan with the security software on your device. If you entered any passwords on the site, change them, starting with your email account.
My host says the site is clean but Google still flags it.
Go back to the Security Issues report and check the exact URLs Google lists. Malware is often served conditionally, only to visitors arriving from search, only to logged-out users, or only on mobile, so a normal look at your own site shows nothing. Test the specific URLs Google names, from a browser you are not logged in to.
Can I get flagged again after the warning is removed?
Yes, and it happens often, because the clean-up removed the malware but not the way in. Update everything, rotate all credentials, and keep an eye on the site after the warning lifts. Monitoring is the difference between catching a reinfection in hours and finding out from a customer.