Text placed outside the page

pdf.offpage-text

Text positioned beyond the page boundary, so no viewer draws it and every extractor still reads it.

How the text is hidden

The text matrix and the current transformation matrix place a run at a coordinate. Put that coordinate outside the box the reader displays and the glyphs fall off the sheet — the operators run, the string is in the content stream, and nothing appears. No colour trick, no font trick, no flag; only arithmetic.

Why a model still reads it

Extraction walks the content stream and does not ask where a run landed. Position is exactly the property a text extractor discards.

What we do about it

invisibleReason is ordered by strength of evidence, so a run that is off-page AND inside a switched-off layer, in the invisible render mode, collapsed to no area, or fully transparent is reported under that stronger reason instead. Off-page itself outranks the font-size test, so a run that is both off the page and below the sub-readable size is reported here rather than as pdf.tiny-font.

How often it fires

1% of 400 real UK public-sector contract PDFs (Contracts Finder, 2019–2023) — Word, Adobe, Nitro, office copiers, measured 2026-08-23.

This is an alert-volume number and nothing else. It says how often the alarm sounds on documents as found — not how often it is right, and not whether what it found was harmless. Documents as found may themselves carry concealment. Read it against the population named above rather than as a property of documents in general.

Seen in the wild

2 Aug 2026 · arXiv · research
CrackedPDFs: A Controlled Benchmark for Hidden Prompt Injection in PDFs

A benchmark of 29,322 PDFs built from 4,983 real documents, injecting payloads through invisible render mode, tiny fonts, white and low-contrast text and off-page placement — every one of which is a technique we detect.

27 May 2026 · USENIX Security 2026 · research
Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening

Across 196,682 real résumés submitted to a live hiring platform, roughly 1% carried a prompt injection hidden by white-on-white text, 1pt fonts or text placed off the page — and more than 90% of those prompts contained no explicit instruction at all, so a phrase matcher catches under one in ten.

Every recorded incident, across all techniques.

next

Check your own file

Three commands: a key, credit, a verdict.

Start with the API