Most site owners can list the links they meant to publish. Fewer can say the list is complete. This article sets out what Google’s documentation says about hidden links, cloaking and injected content, and how Google suggests a site owner looks for them. Where we add our own reading, we label it.
Hidden text and links as Google defines them
Google’s spam policies for web search describe hidden text or link abuse as placing content on a page solely to manipulate search engines and not to be easily viewable by human visitors. The examples it lists include white text on a white background, text hidden behind an image, text positioned off-screen with CSS, a font size or opacity of 0, and hiding a link by linking only one small character, such as a hyphen in the middle of a paragraph.
The policy is explicit about what is not a problem: accordion or tabbed content, sliders, tooltips and screen-reader-only text. Our reading: the test is purpose, not the CSS property. A hidden element is not automatically spam; one that exists to put links in front of a crawler and not people is.
Cloaking: a different page for the crawler
The same document defines cloaking as presenting different content to users and search engines with the intent to manipulate search rankings and mislead users. Its examples are a page about travel destinations shown to search engines while users see discount drugs, and text or keywords inserted into a page only when the requesting user agent is a search engine.
Google adds that content search engines find hard to access, such as JavaScript or images, has separate recommendations for making it accessible without cloaking, and that it does not treat a paywall as cloaking when Google can see the full content a person with access would.
How links nobody wrote get onto a site
Google’s policy on hacked content is the relevant one here. It defines hacked content as any content placed on a site without permission, due to vulnerabilities in a site’s security, and lists several forms. Code injection adds malicious code, often JavaScript, to existing pages. Page injection adds new pages with spammy or malicious content. Content injection subtly changes existing pages to add content that search engines can see but people may not, which the policy says can involve hidden links or hidden text added with CSS or HTML, or more complex changes such as cloaking. Injected redirects can depend on the referrer, user agent or device, so a click from Google Search might behave differently from a direct visit.
On how sites get compromised, Google’s guide to the top ways sites get hacked by spammers lists compromised passwords, missed security updates, insecure themes and plugins, social engineering, security policy holes and data leaks. It calls outdated or unpatched themes and plugins a major source of vulnerabilities, and says adding malicious code to free versions of paid plugins or themes is a common tactic.
Why it matters for search
The spam policies say pages that violate them may rank lower or not appear in results at all, and that violations are detected by automated systems and, as needed, human review that can result in a manual action. Google’s Manual actions report help says that when a site has a manual action, some or all of it will not be shown in Google search results. Its list includes hidden text and/or keyword stuffing, cloaking and sneaky redirects, and unnatural links from your site.
Our reading, not a Google claim: the link spam policy covers links to or from a site, so an injected outbound link is a problem even though the owner did not choose it.
Looking for them: source, rendered page and what Google fetched
Google’s own guidance gives a few concrete checks.
- Compare views of the page. The URL Inspection tool can show the crawled page’s raw HTML, HTTP headers, JavaScript console output and loaded resources, and a rendered screenshot in a live test. Google’s guide to JavaScript problems says the tool, and the Rich Results Test, show the rendered DOM. Our reading: view source, the browser’s rendered page and Google’s rendered page are three different things, and a link present in one but not another is a lead.
- View the page as Google does. The Security Issues report help advises URL Inspection because many hackers make changes visible only to Google’s machines, such as links added only when the referrer is Google.
- Check for hidden text directly. For the hidden text manual action, Google suggests using URL Inspection to find content visible to its crawler but not to a person, selecting all text on the page to reveal text that matches the background colour, and checking text hidden by CSS styling or positioning.
- Search the site. Google suggests a
site:search on the root URL to find pages a hacker may have added.
Google’s guide to knowing whether your site was hacked adds a warning: if you cannot see hacked content on the URLs Search Console provides, it might be cloaked, and its cloaked keywords and links guide says a 404 message can be a trick when the page is still hacked.
What the Search Console reports can and cannot tell you
The Security Issues report shows Google’s findings if its evaluation determines a site was hacked or behaves in a way that could harm a visitor. Its hacked categories include code injection, content injection (a hacker adding spammy links or text to a site’s pages) and URL injection. The sample URLs it lists are not necessarily complete, and an issue with no example URLs does not mean no pages are affected. Google says to treat the report as the source of truth, since browser warnings vary with context.
The limit matters. Google’s description of the URL Inspection live test says it does not check conformance to quality and security guidelines or manual actions. A clean live test is therefore not a clean bill of health. Our reading: the reports show what Google has flagged; the inspection tool shows what Google fetched.
Where this fits at Cultured Digital: seeing what the crawler sees
The gap between what a person sees and what a crawler receives sits within the rendering part of our technical SEO work, which covers rendered versus raw HTML. Whether a page can be fetched and what status it returns belongs to crawling and indexing. Both sit under the technical SEO service, where our starting question is whether the content is really there when Google looks.
One of our tools reads this from the outbound side. Link Signals detects hidden links using seven CSS techniques, along with cloaked links and script-written links. It says how each finding was reached and marks keyword-only or model-only flags as “Needs review”, so a person makes the call. It also states its limit: links built only while scripts run may be missed. For a confirmed hack, follow Google’s hacked-site guidance and involve a security professional.
Hidden and injected links are a separate problem from links that go stale. For that, see our earlier articles on expired domains in outbound links, false broken links caused by bot protection and why one-off link audits go stale.