"Links to harmful downloads": outbound links Safe Browsing objects to

The files are not on your server; your pages point to them. Google's description is that your site "is linking to sites that offer downloads that are either malware or unwanted software, according to Google Safe Browsing." Chrome may still warn people visiting your site, and Google says you must remove the links to the harmful sites to lift the warning.

The Security issues report lists sample pages carrying the links, plus the date the issue was first detected. The samples show which destinations are involved, but other pages may link to the same places, so the fix has to cover the whole site. Google says fixing the issue on only some pages does not earn a partial return.

Google's next question is whether you placed those links. If you did, remove them and request review. If you did not recognize them, you may have been hacked, and Google points out that attackers can hide such links when they think the visitor is the site owner.

Ordinary WordPress sites pick these up in predictable ways:

  • Old software roundups and "best free tools" posts linking to download portals or mirrors that later started bundling adware.
  • Links to a vendor's download page where the vendor was later compromised or changed hands.
  • Links to free theme or plugin sites offering nulled versions of premium products.
  • Resource pages and link lists built years ago and never rechecked.
  • Comments and forum posts from visitors pointing to "cracked" versions of software.

Affiliate and sponsored posts deserve a look too. A software affiliate program that sends visitors through several redirects can end on a download host you never chose.

None of these need bad intent on your part. A site you linked to in good faith can change later, and the Safe Browsing verdict follows the destination.

The example pages tell you which destinations are involved. Search the whole database for each domain, since the same link may sit in posts, widgets, menus, custom fields and comments:

bash
wp db search 'badsoftware-mirror.example' --all-tables --one_line
wp comment list --search='badsoftware-mirror.example' --fields=comment_ID,comment_post_ID
# All outbound hosts in published posts, most linked first
wp post list --post_status=publish --field=post_content | grep -oE 'href="https?://[^/"]+' | sort | uniq -c | sort -rn | head -50

For any destination you are unsure of, Google's Transparency Report has a Safe Browsing site status lookup that shows its current verdict for a URL. Google also suggests viewing the example pages with URL Inspection, while logged out, or from another computer, because attackers sometimes hide injected links from the owner.

Removing, replacing and checking for a hack

Work through the list in order of how many links point at each destination, starting with sitewide places like menus, footers and sidebars, where one edit removes hundreds of links at once. For each link to a harmful download site, delete it or replace it with the vendor's official page. Unlinking the anchor text is enough; there is no need to delete the post. Remove comments that link to cracked software, and consider tighter comment moderation if this is a pattern; see user-generated spam.

If you find links you never added, stop and treat the site as compromised. The cleanup is the same as for content injection: locate where the links are stored or printed, remove them, and close the entry point. Hydrogen SEO's Nofollow External Links setting does not help here; a nofollowed link to a harmful download is still a link that sends visitors there.

Asking for the review

Google's final check is that your site conforms to the Unwanted Software Policy. When no page links to the flagged destinations, select Request Review in the Security issues report:

text
Three old posts from 2016-2018 linked to a freeware mirror that now
bundles adware. We removed those links and 41 links to the same domain
in comments. A full database search finds no remaining links. We have
no signs of compromise; the links were added by our own authors.

According to Google, a review takes anywhere from a few days to a few weeks. Afterwards, schedule a periodic check of outbound links in older posts, since the sites you link to keep changing. A broken link checker helps catch dead destinations, although it will not tell you whether a live one has turned harmful.

Common questions

The harmful files are on another site. Why is my site flagged?

Google treats linking to sites that offer malware or unwanted software as a risk to your visitors. You need to remove the links to clear the warning.

Is adding nofollow to the link enough?

No. Nofollow affects ranking signals, not where the link sends people. Google asks you to remove links to the harmful sites.

How do I know if a site I link to is flagged?

Google's Transparency Report offers a Safe Browsing site status check for any URL. It reflects Google's current classification of that destination.