Security Monitoring

The Google Search Console Report Every Website Owner Should Check Monthly

Google often knows your site is compromised before you do — and it tells you for free. Here is how to read the Google Search Console security report and the traffic signals that precede a warning.

Get Shielded
19 Jul 2026 5 min read
The Google Search Console Report Every Website Owner Should Check Monthly

There is a free service that scans your website for malware, checks it against known threat databases, and emails you when something is wrong. Most business owners have it set up already and have never opened it.

The Google Search Console security report is not a substitute for real monitoring, but it is genuinely useful, costs nothing, and it is often how compromises get discovered.

Set it up properly first

Two things worth checking even if you think you already have it.

Verify both address forms. A domain property covers every variation — www, non-www, http, https, and subdomains. A URL-prefix property covers only one exact form, which means problems on the version you did not add stay invisible.

Check who receives the emails. Search Console alerts frequently go to a developer who left, or an agency you stopped working with. Add your own address and confirm you actually receive mail from it.

An alert nobody reads is worth nothing, and this is the single most common failure with this tool.

The Security Issues report

This is the one to check. Open Search Console and look under Security & Manual Actions.

Ideally it says no issues detected. If it does not, the category tells you what Google found:

  • Hacked content — injected spam, added pages, or code Google identified as malicious
  • Malware — software on your site that could harm visitors
  • Deceptive pages — phishing content, usually fake login or payment pages uploaded to your hosting
  • Harmful downloads — files that trigger security software
  • Uncommon downloads — a milder warning, often affecting legitimate but unrecognised files

Crucially, the report usually lists sample URLs. That list is your map — it shows where the problem is rather than just telling you there is one.

The signals that come before a warning

Here is where the report earns its place in a monthly routine. Several things visible in Search Console indicate a compromise before Google formally flags anything.

Pages you never published

Check the Pages report and your indexed URLs. Injected spam pages appear here — often selling pharmaceuticals, replica goods or gambling, and frequently in another language.

You can also search site:yourdomain.com in Google directly. If unfamiliar results appear, that is a compromise, not an SEO curiosity.

Search queries that make no sense

The Performance report shows what people searched before seeing your site. If a landscaping business is appearing for pharmaceutical terms, spam content is being served to Google.

This is one of the earliest reliable signals available.

A sudden crawl or impression change

A sharp unexplained rise in indexed pages usually means injected content. A sharp fall in impressions can mean Google has started distrusting the site.

Odd crawl errors

Server errors on pages that work fine for you can indicate cloaking — content behaving differently for search engines than for logged-in visitors.

If you find something

Resist the urge to click "Request Review" straight away. The order matters.

  1. Read the sample URLs and understand what Google found
  2. Clean the site properly — files, database, and the backdoor behind it
  3. Verify it is genuinely clean by checking the same URLs and searching your site in Google
  4. Then request a review, describing honestly what you found and what you removed
  5. Wait. Reviews typically take up to 72 hours, often less
A rejected review costs you days and slows the next attempt. Cleaning thoroughly before asking is faster than asking twice.

Our guide to removing malware from WordPress covers the clean-up, and the deceptive site ahead warning guide covers what happens when Google shows the full red interstitial.

Be honest about the limits

This is a useful free signal, not a security system. Three limitations matter.

It is reactive. Google usually flags a site after the damage is under way — sometimes weeks after the initial compromise.

It misses plenty. Google looks for things that harm search users. A backdoor sitting quietly, or a site being used to send spam email, may never appear here at all.

It cannot see your server. It reads your public pages. Server-side infections, database injections and modified files are invisible to it.

That is precisely the gap real monitoring fills: file integrity checks and server-side scanning catch things days or weeks before Google would, and often before there is any public symptom. Our security monitoring service covers that layer.

A five-minute monthly routine

  1. Open the Security Issues report — confirm it is clear
  2. Scan the Performance report for search terms unrelated to your business
  3. Check the indexed page count for an unexplained jump
  4. Search site:yourdomain.com and skim for pages you did not publish
  5. Confirm alert emails are still going to someone who reads them

Five minutes a month, and it is free. Add it to your website maintenance checklist and it becomes routine rather than something you remember during a crisis.

If something looks wrong

Unfamiliar pages in the index or nonsense search terms are worth acting on quickly — both usually mean the site is already compromised.

Our WordPress security and error fixing service cleans the site properly, removes the backdoor, and handles the Google review. Send us your web address and what you are seeing, and we will tell you what we find.

Get Shielded

We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.

Keep reading

Chat on WhatsApp