Google Ads "Compromised site" disapproval: how to fix it and get your ads approved
Google Ads disapproves ads with "Compromised site" when it finds malware or hacked content on the landing page or on the domain. The ads cannot run again until the site is clean, so an appeal sent before cleaning it is rejected. Clean the site first, confirm it in Google Search Console, and then request the review from the Policy manager in Google Ads.
What Google found
The policy covers sites that were hacked to add malware, unwanted redirects, spam pages or code that harms visitors. Google may detect it on the exact landing page or on another page of the same domain, so a landing page that looks fine can still be disapproved.
Steps to get the ads running again
- Check Google Search Console under Security issues for the URLs and the type of problem Google reported.
- Clean the whole site, not only the landing page: files, database and any redirect.
- Change every password and update WordPress, plugins and themes.
- Request a review in Search Console once the site is clean.
- In Google Ads, open the Policy manager, select the disapproved ads and request a review.
While you wait
If the business depends on those ads, you can point the campaigns to a clean landing page on a different domain or subdomain that is not affected, as long as it is a real page of your business and complies with Google Ads policies.
Frequently asked questions
Can I just appeal without cleaning the site?
The appeal is rejected if Google still finds the problem, and repeated rejections only delay the ads. Clean first, then appeal.
How long does the review take?
It varies. Google often answers within a few days once the site is clean.
Hacked WordPress site · Fixed price: from 59 USD. You get the price in writing before any work starts.