Restore / Research / Security Issues vs Manual Action Search Console Surfaces Security Issues versus Manual Actions. Two reports, two surfaces, two remediation paths.
Security Issues covers hacking detection on the site infrastructure. Manual Actions covers quality-policy violations on the site's content. The two reports live in separate Search Console surfaces, run on separate detection signals, and require separate remediation workflows.
The two reports, as a structural read
The Security Issues report covers detection of hacking events on the site's infrastructure. The subcategories: hacked content (injected pages or modified existing pages serving spam), social engineering (fake-login or deceptive pages), harmful downloads (malware-serving binaries), unwanted software, deceptive embedded content. The signal feed comes from Google Safe Browsing infrastructure plus separate crawl-time detection at the page level.
The Manual Actions report covers manual review team decisions on quality-policy violations. The category set evolves; current categories include thin content, unnatural links to site, unnatural links from site, user-generated spam, pure spam, sneaky redirects, cloaking, hidden text, scaled content abuse, site reputation abuse, expired domain abuse. The signal feed is from human reviewers, not from automated detection alone.
How the two interact
A site can carry both at the same time. The common pattern: a compromised site (Security Issues notice for hacked content) where the injected content also violates a quality policy (Manual Action for the injected content's pattern, e.g., scaled spam). The two reports point at the same underlying compromise from different surfaces; remediation needs both.
The order of work: stabilize the security side first. The hacking event is ongoing if not remediated, which means new violations keep landing while remediation work runs. Lock down the infrastructure, remove the injected content, restore the original surface, request the Security Issues review. Then move to the Manual Action remediation: scope the affected pages, rebuild against the quality policy, author the reconsideration in the three-element shape. Sites arriving with both notices active are a recurring intake shape for the seo penalty removal company workflow; the security-side stabilization runs to a partner before the Manual Action work begins.
The response processes
Security Issues: request a review after remediation. Google's Safe Browsing infrastructure re-runs the detection on a tight cycle; the response usually lands within days. The signal that the response is in: the warning interstitials disappear from Chrome (Safe Browsing data flow), and the Security Issues report clears in Search Console.
Manual Actions: reconsideration request authored to the three-element shape (acknowledge the violation, document the remediation with file paths and commit references, state the prevention). Response window is typically two to six weeks because the request goes back to the manual-review queue. The Restore engagement that runs this is manual-action removal work. The reconsideration authoring engagement is reconsideration authoring. The diagnostic in front of both runs at the overview.
Adjacent reference: reconsideration request response time for the Manual Action response window detail. Google's disavow tool for the inbound-link side that pairs with unnatural-links Manual Actions.
What operators ask when a notice lands.
- 01.
What does the Security Issues report cover?
Hacking detection. Subcategories: hacked content (injected pages or modified existing pages serving spam), social engineering (fake-login or deceptive pages), harmful downloads (malware-serving binaries), unwanted software, deceptive embedded content. The signal originates from Google Safe Browsing infrastructure plus separate crawl-time detection.
- 02.
What does the Manual Actions report cover?
Quality-policy violations on the site's own content. Categories: thin content, unnatural links to or from site, user-generated spam, pure spam, sneaky redirects, cloaking, hidden text, scaled content abuse, site reputation abuse, expired domain abuse. The signal originates from Google's manual review team.
- 03.
Can a site have both at the same time?
Yes. A compromised site can carry a Security Issues notice (the hacking event) plus a Manual Action (if the injected content also violates a quality policy). Remediation runs both surfaces in parallel: file-side cleanup against the security issue, then the reconsideration for the manual action if applicable.
- 04.
How is the response process different?
Security Issues: request a review after remediation; the response usually lands within days because Safe Browsing re-runs the detection on a tight cycle. Manual Actions: reconsideration request authored in the three-element shape; response window is typically two to six weeks. Reconsideration request response time covers the Manual Action side.
If your Search Console carries a Security Issues notice or a Manual Action and you need the remediation routing, book the diagnostic.
We read both reporting surfaces, scope the security-side stabilization first if a hacking event is active, then route the Manual Action remediation to the correct workflow with the reconsideration authored in the three-element shape.