Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Reputation and impersonation

Website flagged as dangerous

Whether your website (domain and “www”) is listed as possibly dangerous by Google Web Risk (malware, phishing), or your domain or any of its subdomains is on Phishing.Database. It only queries those lists; nothing else on your website is visited.

What it can report

Open each one to see what it means and how to fix it.

Website flagged as dangerous by Google

What it means

Google's Web Risk service lists example.com as a possibly dangerous website. Browsers and other products that use Google's lists may show a red warning screen to people who try to visit. Google can be wrong, so this needs checking before assuming the worst.

What could happen

Customers may be unable to open your website, search engines may hide it, and some emails that link to it may be blocked. It usually means the website was hacked or someone uploaded malicious content to it. It's serious because it hits your visitors immediately.

How an attacker would use it

Someone gets into your website through an old plugin or a stolen password and adds pages that try to steal data or install harmful programs. Your visitors see nothing at first, but Google notices and warns everyone who tries to open your site.

How to fix it

  1. Ask whoever maintains your website to check it right away for content you didn't put there.
  2. Restore a clean backup from before the infection, if there is one.
  3. Update the content system and all plugins and themes, and delete the ones you don't use.
  4. Change every password: website admin, hosting, database and FTP. Delete users you don't recognize.
  5. Once it's clean, request a review in Google Search Console (the “Security issues” section).The warning is usually removed in a day or two.

How to check it's fixed

Ward asks Google again. The result is dated, and an expired result isn't shown. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Your addresses on a phishing list

What it means

Phishing.Database, a community list of phishing websites, includes addresses that belong to example.com. Phishing sites imitate a trusted company to steal data. The list is made by volunteers and can contain mistakes.

What could happen

It may mean someone is using your name or your website to steal data from your customers, or that a page on your own site was hacked. If it's a mistake, it can still make some security tools distrust your domain. Check the addresses before assuming the worst.

How an attacker would use it

Someone gets into your website and hides a page that looks like a bank or login page. They email victims a link to your domain, which looks trustworthy, and those who enter their details hand them over, with your name attached to the fraud.

How to fix it

  1. Open the listed addresses carefully, from a device you don't use for anything important.The technical details show them. Don't enter any data.
  2. If they aren't yours, report them to your hosting provider and ask for their removal.
  3. If they are on your site, delete the content, find out how it got there and update the website.
  4. Change all passwords: website admin, hosting, database and FTP.
  5. Once clean, report the mistake to the list's maintainers if the page was legitimate.

How to check it's fixed

Ward compares your domain with the list again; the list is downloaded daily. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.