# Domain serving injected “/aes.js” + “\_\_test” challenge (OpenResty) — Google flagged as deceptive sit

**URL:** https://forum.infinityfree.com/t/domain-serving-injected-aes-js-test-challenge-openresty-google-flagged-as-deceptive-sit/117317
**Category:** Hosting Support
**Created:** [January 22, 2026, 2:33pm UTC](https://forum.infinityfree.com/t/domain-serving-injected-aes-js-test-challenge-openresty-google-flagged-as-deceptive-sit/117317 "2026-01-22T14:33:08Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![dan3008](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/dan3008/32/53336_2.png) [@dan3008](https://forum.infinityfree.com/u/dan3008)
#### Post date: [January 22, 2026, 2:42pm UTC](https://forum.infinityfree.com/t/domain-serving-injected-aes-js-test-challenge-openresty-google-flagged-as-deceptive-sit/117317/2 "2026-01-22T14:42:26Z")

</div>

> [@Giomar.marchisio](#):
>
> Confirm if InfinityFree adds any **OpenResty/Nginx security challenge** that injects `/aes.js` + `__test` cookie, and if so, how can it be disabled for my domain?

This is part of the security system. This helps explain it further:

> [@Why do I see ?i=1 at the end of a URL](https://forum.infinityfree.com/t/why-do-i-see-i-1-at-the-end-of-a-url/49356):
>
> Don’t worry, this is normal! When you visit your website, you might notice ?i=1 added to the end of your URL. Here’s what’s happening and why. What is the ?i=1 suffix? The ?i=1 is a security check that protects your website from bots and malicious traffic. Our system needs to verify you’re using a real web browser before letting you access your site. Why does it appear? When you first visit your website, our security system: Sends a small test to your browser Checks if your browser can store…

That said, this shouldn’t trigger the deceptive site warning from google safe search  
The more likely reason this is showing is because your sites home page is a fairly generic login page, with no details as to what the site is or what you’re logging into.

I’d recommend adding a landing page with some details about your site, that then links to a login page. I know it seems excessive, but there’s a reason most sites you visit online don’t have their homepage as just a “log in” page

This article may help you too:

> [@Why Do I See a "Deceptive Site Ahead" Warning on My Website?](https://forum.infinityfree.com/t/why-do-i-see-a-deceptive-site-ahead-warning-on-my-website/99495):
>
> If you’re trying to access your website and encounter a bright red warning page that looks something like this: Deceptive site ahead Firefox blocked this page because it may trick you into doing something dangerous like installing software or revealing personal information such as passwords or credit cards. Advisory provided by [Google Safe Browsing](https://developers.google.com/safe-browsing/v4/advisory). Don’t worry - you’re not alone. This article will explain what this warning means, why it appears, and what steps you can take to fix it. What…

---

_[View the full topic](https://forum.infinityfree.com/t/domain-serving-injected-aes-js-test-challenge-openresty-google-flagged-as-deceptive-sit/117317)._
