Hidden text in a Word document
A Word file is a zip of XML, and several of its parts describe text that is present in the document but not drawn on the page. Some of it was hidden on purpose. Some of it is wording the author deleted and the format kept.
w:vanishtracked changeswhite textdocx metadatahidden text
Four things in a five-paragraph contract
$ augur scan contract.docx
contract.docx (office): 4 finding(s)
INVISIBLE
* [alarm] offset 611 — marked hidden in the document's formatting: "The agreed rate is 120.00 per hour."
part=word/document.xml
how=marked hidden in the document's formatting
text=The agreed rate is 120.00 per hour.
* [alarm] offset 611 — text is the colour of the page: "Termination requires 90 days notice."
part=word/document.xml
how=text is the colour of the page
text=Termination requires 90 days notice.
METADATA
* [concern] offset 611 — tracked changes: 1 insertion(s), deleted text "Payment is due within 90 days."
part=word/document.xml
insertions=1
deleted text=Payment is due within 90 days.
* [concern] offset 1057 — document properties, 2 field(s)
author=A. Reviewer
last saved by=legal@othercompany.example
* not removable — reported and left in placeOpened in Word, this document has five visible paragraphs and none of these four things in it. The deleted payment term is the one that matters: the file still says ninety days, and whoever accepts the revision never sees that it once did.
The four hiding places, in order of how often they matter
Tracked changes. A deletion is not a removal. The old wording sits in a w:del element until somebody accepts the revision, and sending a document with changes tracked but not accepted ships every draft of every clause you negotiated.
Document properties. Author and last-saved-by are filled in by whoever last opened the file. Send a contract back to a counterparty and you have told them which of their competitors’ templates you started from, or which lawyer actually wrote it.
Hidden formatting. A run marked with w:vanish is not displayed and is not printed, but it is in the text layer: it copies, it searches, and anything reading the document rather than looking at it gets it in full.
White on white. The oldest trick in the format and still the commonest, because it needs no feature anybody has to know about.
Why augur reports these and never removes them
Every one of them is legitimate somewhere. Tracked changes are the entire point of a review cycle; hidden runs carry template instructions; white text is sometimes just white text on a coloured shape. Stripping them automatically would silently rewrite documents people are in the middle of negotiating.
So this is a read: it says what is in there, quotes it, and leaves the file alone. Word can accept the revisions and clear the properties itself, once you know to.
What it covers
The OOXML formats — .docx, .xlsx, .pptx — and OpenDocument. Comments and authorship, hidden and white runs, tracked insertions and deletions with the deleted text quoted, the property parts, and bytes stapled past the end of the archive. The legacy binary .doc is a different format and is not read.
$curl -fsSL https://raw.githubusercontent.com/dejo1307/augur/main/install.sh | shRelated:Invisible text in a PDFHidden text in HTMLeverything it looks for