Technical SEO · Analysis

Hidden links, cloaking and injected links: what Google’s spam policies say

A page can contain links that its owner never wrote and its visitors never see. Google's spam policies define hidden links, cloaking and hacked content, and its Search Console help says how to look for them.

By Dean Cruddace · Published · Updated · Read 6 min

Key findings

  • Google's spam policies treat hidden text and links as a violation only when the aim is to manipulate search engines rather than be viewable by people; accordions, tabs, sliders, tooltips and screen-reader text are listed as acceptable.
  • Google names cloaking as a technique hackers use to make a hack harder for the owner to detect, so a page that looks clean in a browser is not proof that it is clean.
  • Google points site owners to Search Console's URL Inspection tool, Security Issues report and Manual Actions report as the first-party places to check what Google saw and whether it has flagged anything.

Most site owners can list the links they meant to publish. Fewer can say the list is complete. This article sets out what Google’s documentation says about hidden links, cloaking and injected content, and how Google suggests a site owner looks for them. Where we add our own reading, we label it.

Google’s spam policies for web search describe hidden text or link abuse as placing content on a page solely to manipulate search engines and not to be easily viewable by human visitors. The examples it lists include white text on a white background, text hidden behind an image, text positioned off-screen with CSS, a font size or opacity of 0, and hiding a link by linking only one small character, such as a hyphen in the middle of a paragraph.

The policy is explicit about what is not a problem: accordion or tabbed content, sliders, tooltips and screen-reader-only text. Our reading: the test is purpose, not the CSS property. A hidden element is not automatically spam; one that exists to put links in front of a crawler and not people is.

Cloaking: a different page for the crawler

The same document defines cloaking as presenting different content to users and search engines with the intent to manipulate search rankings and mislead users. Its examples are a page about travel destinations shown to search engines while users see discount drugs, and text or keywords inserted into a page only when the requesting user agent is a search engine.

Google adds that content search engines find hard to access, such as JavaScript or images, has separate recommendations for making it accessible without cloaking, and that it does not treat a paywall as cloaking when Google can see the full content a person with access would.

Google’s policy on hacked content is the relevant one here. It defines hacked content as any content placed on a site without permission, due to vulnerabilities in a site’s security, and lists several forms. Code injection adds malicious code, often JavaScript, to existing pages. Page injection adds new pages with spammy or malicious content. Content injection subtly changes existing pages to add content that search engines can see but people may not, which the policy says can involve hidden links or hidden text added with CSS or HTML, or more complex changes such as cloaking. Injected redirects can depend on the referrer, user agent or device, so a click from Google Search might behave differently from a direct visit.

On how sites get compromised, Google’s guide to the top ways sites get hacked by spammers lists compromised passwords, missed security updates, insecure themes and plugins, social engineering, security policy holes and data leaks. It calls outdated or unpatched themes and plugins a major source of vulnerabilities, and says adding malicious code to free versions of paid plugins or themes is a common tactic.

The spam policies say pages that violate them may rank lower or not appear in results at all, and that violations are detected by automated systems and, as needed, human review that can result in a manual action. Google’s Manual actions report help says that when a site has a manual action, some or all of it will not be shown in Google search results. Its list includes hidden text and/or keyword stuffing, cloaking and sneaky redirects, and unnatural links from your site.

Our reading, not a Google claim: the link spam policy covers links to or from a site, so an injected outbound link is a problem even though the owner did not choose it.

Looking for them: source, rendered page and what Google fetched

Google’s own guidance gives a few concrete checks.

  • Compare views of the page. The URL Inspection tool can show the crawled page’s raw HTML, HTTP headers, JavaScript console output and loaded resources, and a rendered screenshot in a live test. Google’s guide to JavaScript problems says the tool, and the Rich Results Test, show the rendered DOM. Our reading: view source, the browser’s rendered page and Google’s rendered page are three different things, and a link present in one but not another is a lead.
  • View the page as Google does. The Security Issues report help advises URL Inspection because many hackers make changes visible only to Google’s machines, such as links added only when the referrer is Google.
  • Check for hidden text directly. For the hidden text manual action, Google suggests using URL Inspection to find content visible to its crawler but not to a person, selecting all text on the page to reveal text that matches the background colour, and checking text hidden by CSS styling or positioning.
  • Search the site. Google suggests a site: search on the root URL to find pages a hacker may have added.

Google’s guide to knowing whether your site was hacked adds a warning: if you cannot see hacked content on the URLs Search Console provides, it might be cloaked, and its cloaked keywords and links guide says a 404 message can be a trick when the page is still hacked.

What the Search Console reports can and cannot tell you

The Security Issues report shows Google’s findings if its evaluation determines a site was hacked or behaves in a way that could harm a visitor. Its hacked categories include code injection, content injection (a hacker adding spammy links or text to a site’s pages) and URL injection. The sample URLs it lists are not necessarily complete, and an issue with no example URLs does not mean no pages are affected. Google says to treat the report as the source of truth, since browser warnings vary with context.

The limit matters. Google’s description of the URL Inspection live test says it does not check conformance to quality and security guidelines or manual actions. A clean live test is therefore not a clean bill of health. Our reading: the reports show what Google has flagged; the inspection tool shows what Google fetched.

Where this fits at Cultured Digital: seeing what the crawler sees

The gap between what a person sees and what a crawler receives sits within the rendering part of our technical SEO work, which covers rendered versus raw HTML. Whether a page can be fetched and what status it returns belongs to crawling and indexing. Both sit under the technical SEO service, where our starting question is whether the content is really there when Google looks.

One of our tools reads this from the outbound side. Link Signals detects hidden links using seven CSS techniques, along with cloaked links and script-written links. It says how each finding was reached and marks keyword-only or model-only flags as “Needs review”, so a person makes the call. It also states its limit: links built only while scripts run may be missed. For a confirmed hack, follow Google’s hacked-site guidance and involve a security professional.

Hidden and injected links are a separate problem from links that go stale. For that, see our earlier articles on expired domains in outbound links, false broken links caused by bot protection and why one-off link audits go stale.

Written by Dean Cruddace

Founder of Cultured Digital. Working in SEO since 2001, across independent consultancy, in-house and agency roles, with a focus on technical SEO, strategy and development.

About Dean →