Understanding the Red Phishing Warning
If visitors to your WordPress site are greeted with a terrifying red screen that says "Deceptive site ahead," your website has been compromised and is being used to host phishing pages. Hackers are using your server to host fake login pages (like a fake PayPal or bank login) to steal credentials from unsuspecting victims.
This is a severe violation, and Google Chrome will block all access to your site until it is resolved.
Need immediate help?
If your site is currently hacked or showing warnings, our incident response team can help right now.
Step 1: Locate the Phishing Pages
Unlike SEO spam which alters your homepage, phishing pages are usually hidden deep in subdirectories that you would never normally check. For example: yoursite.com/wp-includes/css/paypal-login/index.php.
Check your Google Search Console. Navigate to the Security Issues tab. Google will often provide a few sample URLs of where the deceptive content was found. This gives you a starting point.
Upgrade to Nexura Pro
Get enterprise-grade protection. Block zero-day exploits, advanced malware, and brute-force attacks instantly.
LIMITED TIME LAUNCH OFFER
Step 2: Clean the Infection
Phishing files are usually standalone HTML or PHP files uploaded via a backdoor.
- Access your server via FTP or SSH.
- Navigate to the directories mentioned in Google Search Console and delete the fraudulent folders entirely.
- However, manual deletion is rarely enough. Run a deep scan with Nexura Security to locate the backdoor that allowed the files to be uploaded in the first place.
Step 3: Check for Malicious Redirects
Sometimes, your site isn't hosting the phishing page directly, but rather your legitimate pages are redirecting users to an external phishing site. Check your .htaccess file and your theme's header.php for unauthorized JavaScript redirects.
Step 4: Request a Review
Once you have completely removed the phishing pages, deleted the backdoors, and updated all your plugins, it's time to get the warning removed.
- Go to Google Search Console > Security Issues.
- Click Request a Review.
- Provide a detailed explanation of the steps you took to clean and secure the site (e.g., "Removed fraudulent directories in wp-includes, updated all plugins, installed Nexura WAF, and changed all FTP passwords.").
Google typically processes phishing reviews within 24 to 72 hours. Once cleared, the red warning screen will vanish.
