Google ads: Malicious software / Compromised site

hi there

I’m reaching out regarding an ongoing issue with Google Ads and our BeTheme-powered site (morstonhall.com).


Google Ads continues to reject campaigns with the reason “Malicious software / Compromised site”, even though:

• We’ve enforced HTTPS with permanent 301 redirects (non-www → https).

• Blocked HTTP access to admin/login and enforced secure logins.

• Rotated the database user password and updated wp-config.

• Added modern security headers (HSTS, CSP, X-Frame-Options, Referrer-Policy, etc.).

• Removed plugins that were interfering with permalink/REST API routing (Hide My WP / WP Ghost).

• Verified clean results across multiple independent scans:

• VirusTotal – 0/97 vendors flagged.

• Sucuri SiteCheck – no malware, no blacklist.

• Qualys SSL Labs – A+ SSL rating.

• SecurityHeaders – Grade A.


All landing pages tested return 200 OK, and there are no signs of malware or compromise on the site. Despite this, Google’s Ads crawler still flags the site as “Compromised,” preventing us from running campaigns.


We want to rule out any theme-related factor. Could you please confirm:

1. Whether BeTheme has any known compatibility issues with Google Ads crawler or Googlebot?

2. Whether there are hidden scripts, demo assets, or theme features that could be misinterpreted as unsafe?

3. Any recommended steps from your side to ensure Google Ads recognises BeTheme-based sites as clean.


This is blocking ad campaigns, so any guidance or deeper checks from your team would be greatly appreciated.


Thank you,

Maciej


Comments

Sign In or Register to comment.
This website uses cookies

We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.

Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission. This means that cookies which are categorized as necessary, are processed based on GDPR Art. 6 (1) (f). All other cookies, meaning those from the categories preferences and marketing, are processed based on GDPR Art. 6 (1) (a) GDPR.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.