Manual actions
Google Manual Actions and Security Issues
Every Google manual action and security issue in Search Console: what triggers it, how to fix it, and how to file a reconsideration request.
Manual actions 17
- "AMP content mismatch" manual action on WordPress AMP pagesYour AMP pages don't match their canonical pages. Why WordPress AMP templates drift, how to compare the two versions, and whether to fix AMP or retire it.
- "Back button hijacking" manual action: scripts that trap visitorsGoogle found pages that stop visitors going back to the page they came from. Find the history-manipulating script in WordPress, remove it and request review.
- "Cloaked images" manual action: when Google Images shows something elseYour images look different in Google results than on your site, often from hotlink protection or overlays. Fix it in WordPress, or opt out of inline linking.
- "Cloaking and/or sneaky redirects" manual action on a WordPress siteGoogle saw different content than your visitors, or users were redirected elsewhere. How to reproduce it with curl, find the code in WordPress and fix it.
- "Hidden text and/or keyword stuffing" manual action: finding and fixing itGoogle found text only crawlers can see, or pages crammed with repeated keywords. Where it hides in WordPress themes, widgets and alt text, and how to fix it.
- "Major spam problems" manual action: what it means and whether to rebuildGoogle's harshest spam action, once called pure spam, for scaled content abuse, cloaking or repeat offenses. What cleanup takes and how to ask for review.
- Manual action or algorithmic drop: how to tell which hit your siteA manual action is listed in Search Console; an algorithmic drop never is. How to read the reports, the traffic graph and update dates to find the real cause.
- "News and Discover policy violations" manual actions for publishersManual actions for breaking Google News and Discover content policies, from transparency to manipulated media: what each asks for and the evidence to show.
- "Site abused with third-party spam": internal search, uploads and open sectionsThird parties are using your site's search pages, uploads or open sections to host spam. Find the entry points on WordPress, close them and request review.
- "Site reputation policy" manual action: third-party content on your domainThird-party pages hosted to ride your domain's ranking signals, such as coupon or casino sections. Your options, the EEA difference, and requesting review.
- "Sneaky mobile redirects" manual action: phones sent somewhere elsePhone visitors get redirected to content Google never sees, often by an ad script or a hack. How to test on a phone, find the source and request review.
- "Spammy free host" manual action: when a hosting service is judged as a wholeGoogle can act on a whole free hosting service when many of its sites are spam. Who receives it, what WordPress Multisite owners should check, and the fix.
- "Structured data issue" manual action: lost rich results and how to fix the markupGoogle found markup outside its structured data guidelines, such as fake reviews or hidden content. Fix the JSON-LD in WordPress and request review.
- "Thin content with little or no added value": the manual action and the fixGoogle flagged thin affiliate pages, scraped posts or doorways on your site. Find them in WordPress, improve, merge or remove them, and file for review.
- "Unnatural links from your site" manual action: fixing outbound linksGoogle found paid or exchanged outbound links on your pages. Find them in WordPress, qualify or remove them with rel attributes, and request a review.
- "Unnatural links to your site" manual action: audit, removal and disavowGoogle found paid or manipulative backlinks pointing at you. How to export links, contact site owners, build a disavow file and document it for review.
- "User-generated spam" manual action: comments, forums and profilesVisitors posted spam in your comments, forums or user profiles. Clear it out of WordPress, tighten registration and discussion settings, then request review.
Security issues 12
- "Deceptive embedded resources": when an ad or widget is the scamDeceptive ads or widgets on your pages trick visitors, and the host page takes the blame. How to catch rotating ads and pop-unders, then clear the flag.
- "Deceptive pages" security issue: social engineering on your siteSafe Browsing found pages that trick visitors into giving up passwords, calling fake support or installing software. Where they hide on WordPress and the fix.
- "Hacked: Code injection": tracing injected scripts in WordPressA hacker is injecting code into your pages, such as redirects or crypto miners. How to fetch pages safely, where the code hides in WordPress, and the review.
- "Hacked: Content injection": pharma links and spam text in your pagesA hacker added spam links or text, often pharmaceutical, to your existing pages. Find it in WordPress posts, widgets and themes, remove it and request review.
- "Hacked: Malware" in Search Console: cleaning an infected WordPress siteGoogle found malware on your site and Chrome warns visitors away. A WordPress cleanup order, from backup to reinstall to salts, and the security review.
- "Hacked: URL injection": spam pages you never createdHackers created spam pages on your domain, as in the Japanese keyword or gibberish hacks. Find and remove them and the code behind them, then request review.
- "Harmful downloads": files on your site that Safe Browsing blocksYour site offers a download Safe Browsing treats as malware or unwanted software. Find it in uploads or download plugins, remove it and request review.
- "Links to harmful downloads": outbound links Safe Browsing objects toYour pages link to sites whose downloads Safe Browsing classes as malware or unwanted software. Find the links across WordPress, remove them, request review.
- "Possible phishing detected on user login": Chrome's password reuse warningA visitor typing a saved password on your pages set off Chrome's password reuse warning. What it means, fake WordPress logins, and how to request review.
- "Suspected deceptive pages": a possible social engineering flagSafe Browsing flagged pages as potentially deceptive. How this differs from Deceptive pages, legitimate designs that trip it, and what to check before review.
- "Unclear mobile billing": charges users cannot see before they payGoogle found pages that don't make mobile charges clear, so Chrome may warn first. What billing pages must show, and how to fix them and request review.
- "Uncommon downloads": new files Safe Browsing has not seen yetChrome warns that a file from your site is rarely downloaded. Why new releases trigger this, why it doesn't affect search, and when a review is worth filing.