Skip to content

Hidden pages, layers and attachments in a PDF: what can hide, and how to find it

By the getPDF team · Published 11 October 2026

The short answer

A PDF can carry more than its visible pages: attached files, layers switched to invisible, earlier versions of edited pages, and pages or objects that nothing points to any more. Viewers show none of these, but anyone with the file can dig them out. Inspect lists attachments by name, and a fresh copy of the pages (Extract PDF pages, all pages) left the attachment, the earlier version and the orphaned page behind in our test. Layers need extra care, because removing their switch can make them visible.

Look inside your file first

Inspect PDFFonts, images, metadata, why it is big. Free, runs on your device.

Drop the PDF on Inspect. It reads the file on your device, changes nothing, and reports pages, fonts, pictures, metadata, scripts, launch actions, signatures and attachments with their names. It does not list layers, earlier versions or orphaned objects; the sections below say how to spot those.

What can hide below the pages

A PDF drawn as an iceberg. Above the waterline: the visible pages. Below it: attachments, hidden layers, earlier versions from appended saves, and orphaned pages and objects. Inspect lists the attachments; the others need other checks.what a viewer showsPagesAttachmentsInspect lists themHidden layerssearch and copy find themEarlier versionskept by appended savesOrphaned pagesin the file, shown by nothinga full rewrite or a fresh copy of the pagesleaves most of this behind
What a viewer shows is the top of the file. Below the waterline: attached files, invisible layers, earlier versions kept by appended saves, and pages and objects nothing points to.

To see what each of these does in practice, we built a 1-page test file with all 4: a page saying “Rent 1,190 EUR a month”, edited to “Rent 1,250 EUR” with an appended save; a hidden layer with a line about salaries; an attached file, salaries.csv; and a second page cut from the page list but left in the file, plus 1 more object nothing pointed to. Every viewer shows 1 page with “Rent 1,250 EUR”. The numbers below come from that file.

Attachments: whole files inside the PDF

A PDF can embed any file: a spreadsheet, an image, another PDF, an XML file. Viewers list them in an attachments panel, often behind a paperclip icon, but they are easy to overlook, and they travel with every copy you send.

The legitimate case is common in business: a German ZUGFeRD or Factur-X e-invoice carries its machine-readable XML as an attachment, usually factur-x.xml, and the attachment is the point of the file (the e-invoice guide explains). The leak is just as easy: a report exported with the working spreadsheet attached, or a contract with an earlier draft inside.

Inspect shows them: on our test file, “Attachments: 1: salaries.csv”, and in its summary “Has 1 attached file: salaries.csv”.

Hidden layers: content switched off, not removed

The PDF standard (ISO 32000) lets content belong to layers, which it calls optional content, and a layer can be set to invisible. Design and engineering programs use this for alternative versions, notes and construction lines. Invisible means “not drawn”, not “not there”.

On our test file the hidden line did not draw: not 1 dark pixel where it sits. But select all and copy, and it pastes out. Search finds it, and getPDF’s editor lists it as a text object on the page. Inspect does not report layers, so the check is this: copy all the text of a page and compare it with what you see.

To take hidden text out, open the file in the editor, press Ctrl+F and search for it, click it on the page where the find bar points, and press Delete; or draw a redaction box over that spot, which removes what is under it whether drawn or not. Then save.

Earlier versions: appended saves keep the old page

A PDF can be saved by appending: the changes are written after the original bytes, and the earlier version stays in the file, unused. The PDF standard allows it, it is fast, and digital signatures depend on it, because the signed bytes must not change.

On our test file the page shows “Rent 1,250 EUR”, and the old “Rent 1,190 EUR” was still in the file’s bytes. No viewer shows it; a text editor opened on the PDF, or a recovery tool, finds it.

getPDF’s editor does not append by default: it writes the saved file in full, so text you changed or deleted leaves no earlier copy. The one exception is a digitally signed file, which it appends to so the signature stays valid, and it says so on saving. Compress PDF, Flatten PDF and Remove PDF metadata drop earlier versions too, as the table below shows.

Orphaned pages and objects

Some programs “delete” a page by taking it out of the page list and leaving the page itself in the file. Our test file held such a page with its own text, and an extra object nothing pointed to. No viewer shows them, Inspect does not count them, and they are in every copy of the file.

Which tools leave what behind

We ran the test file through getPDF’s tools and checked each result:

Result of Attachment Hidden layer Earlier version Orphaned page and object
The original Yes Yes, hidden Yes Yes
Editor, Save PDF Yes Yes, hidden Gone Gone
Compress PDF Yes Yes, hidden Gone Gone
Flatten PDF Yes Yes, hidden Gone Gone
Remove PDF metadata Yes Yes, hidden Gone Gone
Extract PDF pages, all pages Gone Yes, and now visible Gone Gone
Merge PDF Gone Yes, and now visible Gone Gone

2 rows need explaining:

  • Remove metadata keeps attachments and layers. It clears the document’s properties and the XMP packet, and it drops what nothing points at any more: on our file the card said “Removed 5 leftover objects nothing pointed at, such as earlier versions of edited pages”, and the old rent and the orphaned page were gone from the bytes. An attachment and a layer are still part of the document, so they stay, as do bookmarks.
  • Extract and Merge make a hidden layer visible. They copy the pages into a new file and leave the rest behind, attachments and the layer switches included. Without its switch, a hidden layer is drawn like everything else: on our test the hidden line appeared on the page. That is useful as a check, and a surprise if you did not expect it. Remove hidden text in the editor first, then extract.

So, for a clean file to share: delete what you do not want in the editor (hidden text, notes) and save, then use Extract PDF pages with every page chosen, such as “1-12” for 12 pages, to leave attachments and leftovers behind, then Remove PDF metadata. Check the result with Inspect.

The honest part

  • Inspect is not a forensic tool. It lists attachments, scripts, launch actions, signatures, metadata and annotations. It does not list layers, count orphaned objects or detect appended versions. Absence from its report is not proof of absence.
  • There is no “remove attachments” switch. Today the route is a fresh copy of the pages, as above. It drops every attachment, wanted or not.
  • Attachments are often the point. An e-invoice without its XML, an archive file without its embedded originals, a portfolio without its files: strip with intent, not by default.
  • Rewriting breaks digital signatures. Every tool that writes a new copy of a signed file ends the signature’s validity, and getPDF warns when it does. Keep the signed original for anything that counts.
  • What is visible still counts most. Most leaks are on the page: a name in a footer, an account number in a table. Find personal data covers those, what PDF metadata reveals covers the properties, and the privacy and protection guide covers the whole picture.

Questions

Can a PDF really have pages I cannot see?

Yes, in 2 ways. A page can be cut from the page list and still sit in the file, and an earlier version of a page can stay inside after an edit was appended. No viewer shows either, but anyone reading the raw file can. Our test file held both.

Does getPDF have a button to remove attachments?

Not as such. Extract PDF pages, with every page chosen, writes a new file with the pages only, and in our test it left the attachment behind. Merge did the same. Check the result with Inspect before you rely on it.

How do I see a PDF's attachments?

Drop it on Inspect: the Attachments row gives the number and each file's name. Most viewers also have an attachments panel, often behind a paperclip icon in the side bar.

Should I remove the XML from an e-invoice?

No. In a ZUGFeRD or Factur-X invoice the attached XML is the invoice data the recipient's software reads. Remove it and the file is just a picture of an invoice.

The tools for this job