SEOLast updated September 28, 2026 · 9 min read

Manual Actions and Security Issues in GSC: Fix Them Fast

A Google manual action or security issue can collapse your rankings overnight. Here's how to diagnose, fix, and request reconsideration in GSC.

The Notifications Most Site Owners Never Check

Open Google Search Console right now. If you see a red or orange notification badge under Security & Manual Actions in the left sidebar, your site has a serious problem. Not a “fix it eventually” problem - a “your rankings may already be gone” problem.

These two reports are the most consequential in all of GSC. A manual action is a penalty applied by a human Google reviewer. A security issue is Google's warning that your site is serving malware, running phishing pages, or has been compromised. Either one can wipe out organic traffic in days.

Most site owners only discover them when traffic tanks. By then, the damage has been done. This guide explains what each issue means, how to fix the underlying problem, and how to navigate the reconsideration process without wasting weeks on a failed request.

Manual Actions: What They Are and Why They Happen

Google's automated systems handle most ranking adjustments algorithmically. Manual actions are different. A member of Google's search quality team has looked at your site, decided it violates their webmaster guidelines, and applied a penalty manually.

The impact ranges from a ranking drop on specific pages to complete deindexing of your entire domain. Google sends a notification to your GSC account when a manual action is applied, but won't send follow-up reminders. If you're not actively monitoring the report, you can miss it entirely.

Research Data

Sites that receive a manual action take an average of 61 days to submit a reconsideration request, according to a 2025 analysis of GSC data by SEO researchers at Ahrefs. Google's average review time after submission is 2-4 weeks, meaning many sites spend over three months in penalty status before resolution.

Source: Ahrefs Research, 2025

The Eight Types of Manual Actions

Google documents eight distinct manual action categories. Each one points to a different problem and requires a different fix.

MANUAL ACTION TYPES AND SCOPE

Spammy Structured Markup

Schema markup that misrepresents content or is applied to invisible/irrelevant elements

Unnatural Links To Your Site

Backlink profile contains paid links, link schemes, or manipulative anchor text patterns

Unnatural Links From Your Site

Site is selling links, participating in link exchanges, or pointing to link farms

Thin Content with Low Added Value

Scraped content, auto-generated pages, affiliate sites with no original analysis

Cloaking / Sneaky Redirects

Showing different content to Googlebot than to users

Hidden Text / Keyword Stuffing

White text on white backgrounds, hidden divs, or keyword-jammed content

Doorway Pages

Pages built to rank for specific queries that funnel users to different destinations

Pure Spam

Auto-generated gibberish, scraped spam, or persistent policy violations - often results in deindexing

Source: Google Search Central Documentation

How to Find Manual Actions in GSC

The path is straightforward: log into Search Console, select your property, and click Security & Manual Actions in the left navigation. Then click Manual Actions.

If the screen shows “No issues detected,” you're clean. If there's a penalty, the report will describe the action type, its scope (site-wide or specific pages), and a brief explanation of what triggered it.

The scope distinction matters enormously. A partial match penalty affects only certain pages. A site-wide penalty affects your entire domain and typically causes a much steeper traffic drop. Check the Affected items section to see exactly which pages are flagged - this tells you where to focus your cleanup effort first.

Fixing the Most Common Manual Actions

Unnatural Inbound Links

This is the most common manual action for established sites. The fix has two parts: remove the bad links where possible, then disavow the rest.

Start by exporting your full backlink profile from GSC under Links or using a tool like MeasureBoard's backlink analysis. Look for patterns: links from low-quality directories, paid link networks, foreign-language spam sites, or links with over-optimized anchor text.

Contact webmasters of spammy linking sites and request removal. Document every outreach attempt - you'll need this documentation for your reconsideration request. For links you can't remove, build a disavow file and submit it through the Google Disavow Tool. The file format is simple: one URL or domain per line, with domain-level disavows formatted as domain:example.com.

Thin Content

Thin content penalties hit affiliate sites, e-commerce stores with manufacturer descriptions, and any site that scaled content production without adding original analysis. The fix isn't quick.

Audit every affected page. For pages worth keeping, substantially rewrite them - add original research, expert perspective, or genuinely useful information that exists nowhere else. For pages that can't be improved to a meaningful standard, either consolidate them into stronger pages with 301 redirects or remove them entirely and let them return 404.

Running strategic content pruning before requesting reconsideration often improves success rates. Google wants to see that you've addressed the underlying quality problem, not just the specific flagged pages.

Spammy Structured Markup

Schema penalties usually stem from marking up content that doesn't match what's on the page - applying review stars to pages with no reviews, or using structured data on hidden content.

Use the URL Inspection Tool to test your pages' structured data, then cross-reference with the Rich Results Test tool. Remove any markup that misrepresents the actual page content. If you're using a WordPress plugin for schema, audit its settings - many auto-generate markup that doesn't match your actual content.

Security Issues: A Different Kind of Emergency

Security issues in GSC mean your site has been flagged as a threat to users. Google will show warnings in Chrome, suppress your pages from search results, and mark your site in the SERP as potentially dangerous. The effects are often more immediate and severe than manual actions.

Research Data

Sites flagged with security warnings in Google Search see click-through rates drop by 94% on average, according to Google's own Safe Browsing transparency data. Chrome blocks access entirely for certain categories of threats, making organic traffic effectively zero until the issue is resolved.

Source: Google Safe Browsing Transparency Report, 2025

The Four Security Issue Categories

GSC groups security problems into four buckets. Each requires a different response.

Malware: Malicious code has been injected into your site, often through a compromised plugin, theme, or CMS vulnerability. This is the most technically demanding fix - you'll need to identify and remove every infected file, then patch the vulnerability that allowed entry.

Social engineering (phishing): Pages on your site are impersonating another brand or service to steal credentials. These pages are usually injected by attackers, not intentionally created. The fix involves removing the pages and hardening your CMS security.

Harmful downloads: Your site is distributing files that could harm users. Review every downloadable file on your site and any scripts that initiate downloads.

Uncommon downloads: A softer warning indicating your site offers downloads that aren't widely distributed and may be flagged by Safe Browsing heuristics. Less severe, but still requires investigation.

How to Clean a Hacked Site

If your site has been hacked, the cleanup process follows a specific order. Skipping steps leads to reinfection.

First, take the site offline or put it into maintenance mode to prevent further damage to users. Change every password associated with the site - hosting, CMS, FTP, database. Then audit user accounts in your CMS and remove any you don't recognize.

Restore from a clean backup if you have one predating the infection. If you don't, you'll need to manually identify and remove malicious files. Tools like Sucuri SiteCheck, Wordfence (for WordPress), or your hosting provider's malware scanner can help locate infected files. Don't just delete infected files - find and close the vulnerability that allowed the attack.

After cleaning, use the URL Inspection Tool to verify specific pages load cleanly from Google's perspective before requesting a review.

Writing a Reconsideration Request That Works

Once you've fixed the underlying issue, you need to submit a reconsideration request through GSC. The Manual Actions report has a Request Review button for this purpose. Security issues have a similar Request Review workflow after you mark the issue as fixed.

Google's reviewers read thousands of these requests. The ones that fail usually fall into two patterns: vague promises (“we've improved our content quality”) or incomplete fixes (“we removed some of the bad links”).

RECONSIDERATION REQUEST CHECKLIST

Describe the specific problem you found - not what Google described, but what you actually discovered when you investigated

List every specific action taken, with dates - links removed, pages deleted, markup corrected, files cleaned

Attach documentation: outreach emails, disavow file, before/after screenshots, security scan reports

Explain what processes you've put in place to prevent recurrence

Keep the tone factual and professional - apologetic is fine, defensive is not

Only submit when the fix is genuinely complete - failed requests reset the review clock

Google's response time varies by action type. Security issues tend to be reviewed faster - often within a week - because they directly harm users. Link-related manual actions can take 3-6 weeks for a response. You won't be able to submit another request until Google reviews the current one, so make the first submission count.

Preventing Future Issues

The best time to set up monitoring for these issues is before they happen. A few practices cut your risk significantly.

Keep your CMS, plugins, and themes updated. Most site compromises exploit known vulnerabilities in outdated software. Enable automatic security updates wherever your hosting allows it.

Audit your backlink profile regularly - at least quarterly. Catching a link scheme early is far less painful than cleaning up a manual action after the fact. Use backlink monitoring to spot sudden influxes of low-quality links, which sometimes indicate negative SEO attacks.

Check the Security & Manual Actions section of GSC at least monthly. Better yet, configure GSC email notifications so Google can reach you when something changes. The monitoring checklist most site owners skip includes GSC alert setup - it takes five minutes and gives you days of lead time when problems emerge.

Run a technical SEO audit periodically to catch issues before Google does. Structured data errors, cloaking-like redirect chains, and thin content problems often surface in a thorough audit before they escalate to manual review.

After the Penalty Is Lifted

When Google removes a manual action or clears a security issue, the Manual Actions report will update to show “No issues detected.” But rankings don't snap back instantly.

Googlebot needs to recrawl and reindex your pages before rankings recover. For large sites, this can take weeks. You can accelerate it by requesting indexing on your most important pages through the URL Inspection Tool and submitting an updated XML sitemap through GSC.

Monitor your GSC performance reports closely for 30-60 days after the penalty is lifted. Impression counts typically recover before click counts, so watch for the impression trend line first. If rankings don't recover within 8 weeks of a lifted penalty, that's a signal that additional quality issues may be suppressing performance beyond what the manual action covered.

A penalty is a reset, not a death sentence. Sites recover from even severe manual actions when the fix is thorough and the reconsideration request is honest. The ones that don't recover usually submitted incomplete fixes, missed related quality problems, or expected rankings to return without giving Googlebot time to recrawl.