A photo can look completely ordinary and still be carrying something else: a message, a document, or another file entirely. Hiding content inside images has a name, steganography, and it has honest uses (watermarking, private messages) as well as dishonest ones.
The common ways content is hidden
- Inside the picture itself. Tiny changes to pixel colours, too small for the eye to see, can spell out a message. The picture looks unchanged.
- Tacked on the end. A file can have extra data added after the point where the image ends. Image viewers ignore it, so the photo opens normally. Not all of it is suspicious: many phones add their own data here, such as a short video clip for a "motion photo", a depth map, or a small record with camera settings. Knowing what is on the end is what matters.
- A file that is two things at once. Some files are built to open as an image in one program and as something else, an archive say, in another.
- An invisible watermark. Some tools, including some AI image generators, mark images with a pattern you can't see but software can read.
What a check looks for
Upload the photo to snapWONDERS and open the Security section. It runs separate checks for each of the above:
- Statistical tests on the pixels' lowest bits, where pixel-level hiding usually lives. These only mean something on lossless files such as PNG. On a JPEG, compression scrambles those bits anyway, so the report says the test doesn't apply rather than calling the photo clean.
- Data after the end of the image, and whether it's a known structure (a phone's own record) or something unexplained.
- Files that are valid as two formats at once, such as an image that is also a ZIP archive.
- Invisible watermarks. Findings here are marked "possible": ordinary photos can trip them too.
Each finding is graded, with a confidence. The report tells you something is there and what kind it is. It doesn't tell you which tool put it there, or what it says.
A worked example: a note hidden on the end
We took a photo from a plane window, then made a copy with a small ZIP archive added on the end, holding a one-line note. Both copies open as the same photo:

The original has data after the end of the image too, but all of it is recognised: the phone's own record of the camera settings. Security grades A:

The copy has data the report can't explain:

And it is caught as a file that is both an image and a ZIP archive. Security grades D:

That's crude hiding, and crude hiding is easy to catch. Content hidden carefully in the pixels of a lossless image is much harder to spot, by any method.
See it as a before and after: 161 bytes hiding behind a photo
What a result means
- A flag means "likely something here", not "definitely". Heavily compressed or unusual photos can trip statistical tests.
- A clean result is not a guarantee. A small amount of well-hidden content is hard to detect by any method.
- Screenshots and social media re-uploads usually destroy pixel-level hidden content, which is useful to know if you're trying to send something privately, too.
Want to hide something yourself?
snapWONDERS Vaultify hides files inside photos and videos, protected by a password, so the result still looks like an ordinary photo. See how to hide a file inside a photo.
Why this works
Kenneth Springer explains the statistical tests in Building steganography detection.
Related guides
More guides on


