"Uncommon downloads": new files Safe Browsing has not seen yet
This is the mildest entry in the Security issues report. Your site "is offering a download that Google Safe Browsing hasn't seen before," so Chrome may warn that the file is uncommonly downloaded and could be dangerous. It is not a finding that the file is harmful, only that Safe Browsing has no history for it yet.
Google says two things that shape what you do next. The issue "will not prevent your page or site from appearing in Google Search results," and the warnings "are lifted automatically if Google Safe Browsing verifies that the files are safe." Example URLs are not always provided for this one.
That makes it very different from harmful downloads, where Safe Browsing has decided a file is malware or unwanted software and you must remove it. Read the issue title carefully before acting, because the two call for opposite responses: patience and a check for this one, removal for the other.
Why WordPress sites see it
Anything a visitor downloads can be new to Safe Browsing. Typical WordPress cases:
- Software you publish: a desktop app, a browser extension package, or a premium plugin or theme ZIP delivered to customers through WooCommerce, Easy Digital Downloads or a similar store.
- Frequent builds: a nightly or per-customer build produces a different file each time, so each one starts with no history.
- Generated files: invoices, reports or exports created on demand, when they are executables or archives rather than PDFs.
- Files attached to a new product launch, before many people have downloaded them.
PDFs, images and common document types are rarely the subject; the warning is aimed at files that can run code.
Checking your files against the download guidelines
Google's fix step is to find and confirm whether your downloads conform to its download guidelines. If a file breaks them, remove it. If it does not, Google says "you do not need to remove it."
Things worth confirming for each file you offer:
- It is the file you built, unchanged. Compare its checksum with your release build:
sha256sum wp-content/uploads/edd/2024/06/myapp-setup-2.4.1.exe
sha256sum ~/builds/myapp-setup-2.4.1.exe
- It does only what the download page says, with no bundled extras.
- It meets Google's Unwanted Software Policy, for example on disclosure and uninstalling.
If a checksum does not match, stop: someone replaced the file, and you are looking at a compromise, not an uncommon download. Remove it and read harmful downloads and Hacked: Malware. Hydrogen SEO does not host, sign or scan downloads, so none of this runs through it.
Reducing warnings for regular releases
Google does not publish a list of steps that speed up automatic verification, so be wary of anyone promising a guaranteed method. What you control is keeping downloads predictable:
- Publish releases at stable, descriptive URLs on your own domain, over HTTPS.
- Avoid producing a unique binary per customer when one build would do.
- Describe each download clearly on the page that offers it: what it is, its version and size, and what it installs.
- Do not host third-party installers or mirrors of other people's software.
None of that changes Google's criteria, but it avoids creating a stream of never-seen files, and it keeps you well inside the download guidelines if a reviewer does look.
Whether to request a review
Because this issue does not affect Search and clears on its own, a review is optional. Google says that even without a request, it will eventually evaluate most downloads and classify them as acceptable or harmful, but a review request "can help speed the evaluation process." It is worth filing when the warning is costing you customers, for example on a paid product's download page.
When you are finished removing files that break the guidelines, or have confirmed the ones you keep comply, select Request Review in the Security issues report:
The flagged file is our own installer, myapp-setup-2.4.1.exe, built
from our release pipeline (SHA-256 matches our build). It installs only
the app described on /download/ and uninstalls cleanly. No third-party
software is bundled.
Google's range for a security review is a few days to a few weeks. Keep in mind that the next release is a new file and may be flagged as uncommon again until it builds history.
Common questions
Does the uncommon downloads issue hurt my rankings?
Google says this issue will not prevent your page or site from appearing in Google Search results. It only affects the Chrome download warning.
Do I have to remove the file?
Only if it breaks Google's download guidelines. If it conforms, Google says you do not need to remove it.
Will the warning go away without a review?
Google says warnings are lifted automatically once Safe Browsing verifies the files are safe, and that it will eventually evaluate most downloads. A review request can speed that up.