WPSecureOps

Glossary · Malware

The site is flagged by Google Safe Browsing

Wordfence type
checkGSB
Category
Malware
Severity
Critical

Google's Safe Browsing service lists the site as unsafe, so browsers will warn visitors away.

The alert usually reads
Your site is listed on Google's Safe Browsing list.

What Wordfence found

Wordfence queried Google Safe Browsing and the domain is on the list. This is an external verdict, independent of anything found on the server.

Why it matters

This is the most commercially damaging finding in the set. Chrome, Firefox and Safari all show a full-page interstitial, search results carry a warning, and traffic stops. It also usually means the compromise has been live long enough for Google to crawl it.

How to fix it

  1. 1Find and remove the actual malware first — requesting a review before cleaning gets the request rejected and slows everything down.
  2. 2Check Google Search Console under Security Issues for the specific URLs Google objected to.
  3. 3Once genuinely clean, request a review through Search Console. Reviews typically take a day or two.
  4. 4Tell the site owner before they hear it from a customer.

Common questions

Browsers show a red warning page before my site. Is that this?
Yes — Chrome, Firefox, Safari and Edge all consume Safe Browsing, so a listing puts an interstitial in front of essentially all your traffic, and Google Ads will suspend campaigns pointing at the domain. Of everything in a scan report, this is the finding with the most immediate business impact.
The scan found nothing else. Can the listing be wrong?
It happens — a previously compromised page that was cleaned, a flagged resource loaded from a third party, or shared infrastructure. Register the site in Google Search Console and read the Security Issues report: it names the exact URLs Google objects to, which either points you at what the scanner missed or gives you grounds for a review request.
How long does delisting take once the site is clean?
After you request a review in Search Console, typically between a few hours and a couple of days. Do not request review before actually cleaning — a failed review lengthens the next one. Verify the specific flagged URLs are fixed, then submit once.

Findings that often appear with this one

How WPSecureOps treats it

The connector reports this as checkGSB. WPSecureOps files it under Malware and bands it by the numeric severity Wordfence assigns, so findings of this kind from every site you manage arrive in one queue rather than one email per site. Titles and descriptions are stripped of HTML and the site's absolute path is replaced before anything leaves the server.

Primary references

Product behaviour and remediation guidance were checked against these primary sources.

  1. Wordfence: How to interpret scan results
  2. Wordfence: If your site is hacked
  3. Google Search Console: Security Issues report

See this finding in context