"Harmful downloads": files on your site that Safe Browsing blocks

Your site "is offering users a download that Google Safe Browsing thinks is either malware or unwanted software." Chrome may warn visitors, and Google says you "must remove these downloads from your site to remove the warning." Google's first question is whether you meant to offer the file: if you did, remove it and request review; if you did not know it was there, you have probably been hacked.

Owners are often surprised to learn a file they chose to host counts as harmful. Google's malware policy notes that site owners sometimes do not realize their downloadable files are considered malware. Unwanted software, like a toolbar that changes browser settings or an app that leaks personal data without disclosure, also counts.

Expand the issue in the Security issues report to see sample pages and when the problem was first detected. The samples are the pages that offer the file, which may be a post with a download button or the file URL itself. Other pages linking to the same file are affected too, even if they are not listed, so plan to remove the file everywhere rather than editing only the sample pages.

Downloads you chose to host

If the flagged file is something you offer on purpose, look at why Safe Browsing might object:

  • Bundled installers that add toolbars, change the homepage or install extra programs, even with an opt-out checkbox.
  • "Free" versions of paid software, cracks, keygens and nulled WordPress themes or plugins, which very often carry malware.
  • Software from a third-party build or mirror rather than the vendor's own release.
  • Your own software that does something Google's Unwanted Software Policy disallows, such as collecting data without clear disclosure or being hard to uninstall.

Google's instruction here is blunt: remove them, then go straight to requesting review. Rebuilding your own program to comply with the policy is a separate project; do not re-upload it until it does. If you publish software for a living, give each release a clear name and description on the download page and say what the installer does, which is good practice regardless of this issue.

Downloads you did not know about

If you cannot account for the file, it was probably placed by an attacker. On WordPress, look for executables and archives in places they should not be:

bash
find wp-content/uploads -type f \( -iname '*.exe' -o -iname '*.msi' -o -iname '*.apk' -o -iname '*.dmg' -o -iname '*.scr' -o -iname '*.js' -o -iname '*.zip' \) -printf '%T+ %s %p\n' | sort -r | head -40
wp post list --post_type=attachment --post_mime_type=application --fields=ID,post_title,post_date,guid | head -40

Also check download manager plugins' own storage folders, which often sit outside the media library, and links in posts pointing to files on other domains (that is a separate issue, links to harmful downloads). A dropped file means someone had write access, so work through the full cleanup on Hacked: Malware after removing it. Hydrogen SEO does not scan uploads or classify files; you will need your host's malware scanner or a security service.

Scanning what remains

Google suggests antivirus software for the binaries and other content hosted on your site, while warning that antivirus tools find many kinds of malware and unwanted software but not all of them. It also mentions submitting software to an antivirus program or a consolidation service such as VirusTotal as an indicator of potential problems.

Treat a clean scan as a hint, not a verdict. Google says Safe Browsing applies its own criteria to decide whether a program is unwanted software or malware, so a file can pass an antivirus scan and still be flagged. If you intend to keep offering software, check it against the Unwanted Software Policy before putting it back.

Getting the warning removed

Once every flagged download is gone and the rest have been scanned and checked against the policy, select Request Review in the Security issues report:

text
The flagged file /downloads/pdf-tools-setup.exe was a third-party
installer we mirrored. It bundled an adware component. We removed it
and all other mirrored installers; we now link only to vendor download
pages. Remaining files in uploads are PDFs and images, scanned clean.

Google says the review can take from a few days to a few weeks. Chrome's warning stays in place until then. If you distribute software as part of your business, keeping the files on a separate download host or subdomain can limit how much of the main site a future flag affects, but it does not change the rules the files must meet.

Common questions

The file passed my antivirus scan. Why is it still flagged?

Google says antivirus tools do not catch every kind of malware or unwanted software, and Safe Browsing applies its own criteria. A clean scan is a useful signal but not the final word.

Can I keep the file if I add a warning?

No. Google says you must remove the flagged downloads from your site to remove the warning.

Is offering nulled WordPress themes a problem?

Nulled or cracked themes and plugins often contain malware, and hosting them can trigger this issue. They are also a common way sites themselves get hacked.