"Deceptive pages" security issue: social engineering on your site
Your site "includes content that tricks visitors into doing something dangerous, such as revealing confidential information or downloading software." Google calls this social engineering. A page counts as deceptive when it pretends to be a trusted entity (the visitor's device or browser, a well-known company, or your own site) or tries to get people to do something they would only do for a trusted entity, such as entering a password, calling a support number or installing a program.
Safe Browsing warns people before they visit pages that consistently show deceptive content, so Chrome and other browsers using it put up a red warning page. Visits from search and from direct links both drop. On a WordPress site you did not build to deceive anyone, a hack is the usual explanation.
The issue details list sample URLs and the date the problem was first detected. The samples are not a complete list. If they all sit under one folder, the rest of that folder is almost certainly affected too, and if they are spread across normal posts, the deceptive element is probably an injected script rather than a separate page.
What deceptive content looks like on hacked WordPress sites
Attackers add social engineering pages or overlays to ordinary sites because a trusted domain makes the scam more believable:
- Phishing kits: a folder, often inside
wp-content/uploads/or a fake plugin directory, holding a copy of a bank, email provider or delivery company login page. - Fake browser or plugin update prompts injected over your real pages, asking visitors to download an "update" that is actually malware.
- Tech support scams: full-screen pages claiming the visitor's computer is infected and giving a phone number.
- Fake CAPTCHA or "verify you are human" screens that tell the visitor to paste and run a command.
- Clone login pages for your own site, collecting your users' credentials.
Sometimes the page is legitimate but badly designed: a download button styled to look like a system dialog, or a page imitating a well-known brand's look without permission. That still counts.
Confirming and removing it
Visit the example URLs from the report. Google suggests URL Inspection to see them in both mobile and desktop views, which is safer than a browser if the page also serves malware. If the examples point into a folder, list it:
find wp-content/uploads -type d -newer wp-config.php | head
find . -iname '*login*' -o -iname '*verify*' -o -iname '*secure*' | grep -v -E 'wp-admin|wp-includes|node_modules' | head -30
wp db search 'navigator.clipboard' --all-tables --one_line
Delete phishing folders entirely, and remove injected overlay scripts from the database and theme. Then treat it as a full compromise: change passwords, reinstall core, plugins and themes from clean sources, and close the entry point, as set out on Hacked: Malware. A phishing kit uploaded once can be uploaded again through the same hole.
If the page is your own design, redesign it so nothing imitates the browser, the operating system or another brand, and make every download button clearly labelled with what it gives.
When you think the flag is wrong
Google says that if you believe Safe Browsing has classified a page in error, you can report it; the Security issues report links to the form. Use this only when you are confident nothing on the page is deceptive, including third-party content. A common surprise is that the deceptive element comes from an ad or embedded widget rather than your own content; that is a separate issue type, deceptive embedded resources, and the fix is removing the resource.
Hydrogen SEO plays no part in how pages look to visitors beyond metadata and structured data, and it does not scan for phishing. You can use its Redirections screen afterwards to check nobody added rules pointing your URLs at a phishing domain.
Clearing the warning
When every example page and anything like it is gone, select Request Review in the Security issues report. State what the deceptive content was, where it lived and how it got there:
A phishing kit imitating a parcel delivery login was uploaded to
/wp-content/uploads/2024/03/dl/ through a vulnerable file manager
plugin. We deleted the folder and the plugin, reinstalled all plugins
and the theme, and changed every password. No other deceptive pages
remain (checked all upload folders and URL patterns in the report).
Google gives a range of a few days to a few weeks for the review. The browser warning comes off after a successful review; if you get a rejection, a leftover copy of the kit in another folder is the most common reason.
Common questions
What is social engineering in Google's terms?
Content that tricks visitors into doing something dangerous, like revealing confidential information, calling a fake support line or downloading software, usually by pretending to be a trusted entity.
I never created a phishing page. Why is my site flagged?
Attackers often upload phishing kits to hacked sites because a legitimate domain makes the scam more convincing. Look in uploads and unfamiliar folders, then clean the whole site.
Can I dispute a deceptive pages warning?
Yes. If you are sure the page is not deceptive, Google provides a way to report a Safe Browsing classification error. Fix any genuinely deceptive content first.