[wp-trac] [WordPress Trac] #58130: Google has detected harmful content on wp-login.php page

WordPress Trac noreply at wordpress.org
Fri Apr 14 13:31:40 UTC 2023


#58130: Google has detected harmful content  on wp-login.php page
-------------------------------+------------------------------
 Reporter:  thomask            |       Owner:  (none)
     Type:  defect (bug)       |      Status:  new
 Priority:  normal             |   Milestone:  Awaiting Review
Component:  General            |     Version:
 Severity:  normal             |  Resolution:
 Keywords:  reporter-feedback  |     Focuses:
-------------------------------+------------------------------
Changes (by costdev):

 * keywords:   => reporter-feedback


Old description:

> Google just marked my web as potentially harmful, but it marked the
> default wp-login.php page (there is no change on that page by any plugin
> or virus as far as i can say). The only changes I see in the code
> comparing to blank wordpress are from Site Kit by Google 1.98.0 plugin -
> so plugin made by Google himself (from unknown reason it ads <meta
> name="generator" content="Site Kit by Google 1.98.0"> what is btw stupid
> wtf)
>
> I know this is probably more a Google bug, but i guess there might be
> some reason why it triggers, that might be improved.
>
> the reported url is https://exteriery.cz/wp-
> login.php?redirect_to=https://exteriery.cz/wp-admin/&reauth=1
>
> the Learn more link goes to
> https://support.google.com/webmasters/answer/9044101#phising

New description:

 Google just marked my web as potentially harmful, but it marked the
 default wp-login.php page (there is no change on that page by any plugin
 or virus as far as i can say). The only changes I see in the code
 comparing to blank wordpress are from Site Kit by Google 1.98.0 plugin -
 so plugin made by Google himself (from unknown reason it ads <meta
 name="generator" content="Site Kit by Google 1.98.0"> what is btw stupid)

 I know this is probably more a Google bug, but i guess there might be some
 reason why it triggers, that might be improved.

 the reported url is https://exteriery.cz/wp-
 login.php?redirect_to=https://exteriery.cz/wp-admin/&reauth=1

 the Learn more link goes to
 https://support.google.com/webmasters/answer/9044101#phising

--

Comment:

 Hi @thomask,

 Is there a verified or suggested issue with WordPress Core? If not, then
 this needs to be explored further to determine the root cause.

 Side note: Trac, like all public WordPress communication channels, is
 family friendly, so I've removed an acronym that was included in the
 original ticket's summary.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/58130#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list