Hidden WordScanner
Private scans · No account required

Product updates

See what has changed in each verified Hidden Word Scanner release.

Current release: 1.9.5vH.tk3 — 24 September 2026

Shipped and verified

Recent releases

These notes describe behavior supported by reviewed release records.

Clearer Word reports and more accurate DOCX checks 1.7.2v 10 September 2026
Released

Review Word properties, comments and revisions with clearer evidence, follow a worked DOCX guide, and scan nested body tables with explicit hidden-text overrides respected.

  • Fixed: Respect direct not-hidden formatting when the immediate character style is hidden, and inspect nested body tables without repeating merged-cell findings.
  • Improved: Separate document properties, comments and revisions, text visibility, and linked or embedded content, with readable values and recorded source locations.
  • Accessibility: Add keyboard-friendly finding-group navigation and mobile-readable property evidence, while keeping limited coverage visible in reports and exports.
  • Documentation: Expand the Word guide with a verified safe DOCX example, Microsoft manual-review instructions, privacy and expiry details, and clear limits on identity and cleaned-document claims.
Link to release 1.7.2v
Python usage counts and clearer inspection guidance 1.7.1v 8 September 2026
Released

See aggregate Python inspection activity, understand inspection without generative AI, and restore HTTPS document form submissions.

  • Added: Add completed Python visibility inspections to the private usage dashboard with today, seven-day, and total counts.
  • Privacy: Count Python inspections using a content-free signal with no source, filenames, or findings; a failed signal never blocks inspection.
  • Documentation: Explain defined checks without generative AI on the homepage, methodology page, and Python guide, including OCR, reviewed cleanup, and course-policy boundaries.
  • Fixed: Allow same-origin referrers needed for HTTPS document form verification while suppressing referrers to other sites and retaining stricter inspector policies.
Link to release 1.7.1v
Python Code Scanner 1.7.0v 7 September 2026
Released

Inspect Python source for hidden characters, check syntax and unresolved names locally, and review a cleaned copy without executing your code.

  • Added: Add a browser-local Python code inspector for invisible Unicode, confusing punctuation, indentation patterns, and selected look-alike identifiers.
  • Added: Check original and cleaned source with locally hosted Python 3.14.2 and Pyflakes name analysis without executing source or importing its dependencies.
  • Added: Review before-and-after fixes, resolve conflicts, undo decisions, replay audit exports, and copy or download the reviewed source.
  • Accessibility: Provide paged findings, source-location links, cancellation, responsive review panels, and clearer syntax/name result navigation.
  • Documentation: Add a Python scanner guide with examples, privacy boundaries, syntax-error troubleshooting, and coverage limitations.
  • Improved: Update the developer note and clarify that additional programming-language scanners are in development; Python is the supported code language today.
Link to release 1.7.0v
Security, operations, and deterministic packaging 1.6.9v 1 September 2026
Released

Protect operational metrics, introduce a conservative production HSTS policy, and make private aggregate usage easier to interpret.

  • Security: Protect process-local runtime metrics with the same constant-time owner authentication as the private usage dashboard while keeping health checks public.
  • Security: Send a recoverable one-day HSTS policy on production HTTPS responses without committing subdomains or preload.
  • Improved: Show scans today, the latest seven UTC calendar days, explicit zero-count days, and the completed-document counting unit.
  • Privacy: Keep runtime and usage aggregates content-free, avoid unique-user estimates, and retain the warning that nonpersistent usage counters may reset.
  • Documentation: Clarify generated PDF, Word, and Excel reviews, Redis data boundaries, future Excel finding projection, and truthful lightweight release evidence.
  • Fixed: Exclude non-runtime release documentation from the Docker build context so approval evidence cannot change the reviewed application image.
Link to release 1.6.9v
Private aggregate usage dashboard 1.6.7v 31 August 2026
Released

Add an owner-only view of anonymous completed-scan totals without collecting document details or visitor identities.

  • Added: Count successfully completed document scans by file type and UTC day using the existing shared ephemeral store.
  • Added: Add an owner-only usage dashboard protected by a strong deployment secret and HTTPS Basic authentication.
  • Privacy: Store no filenames, uploaded content, keywords, findings, IP addresses, visitor identifiers, report IDs, or scan IDs in usage counters.
  • Security: Keep the dashboard disabled when no admin token is configured, prevent caching and indexing, and reject weak production tokens.
  • Documentation: Clarify that phase-one counters are nonpersistent and may reset if the shared Redis service restarts.
Link to release 1.6.7v