Skip to content

Homoglyph & Invisible Character Detector

Detect zero-width characters, bidi overrides, non-ASCII spaces and Cyrillic or Greek look-alike letters in text or code, and copy a sanitized version.

Homoglyph & Invisible Character Detector

6 suspicious characters found

116
Characters
6
Suspicious
1
Zero-width
2
Bidi
1
Whitespace
2
Homoglyph

Highlighted view

Сlick here to ver200Bify your аccount·balance before it expires. function isAdmin() { return user.202Erole === "nimda"202C; }

Hover any highlighted chip to see its codepoint and Unicode name. Invisible characters are shown by their hex code; non-ASCII spaces show as a dot.

Findings

Zero-width / invisible (1)

Have no visible width. Often used to hide markers, watermarks, or instructions inside text.

  • U+200BZERO WIDTH SPACE×1at 17

Bidirectional control (2)

Reorder how text is displayed vs. stored. The 'Trojan Source' risk — code can read differently than it runs.

  • U+202ERIGHT-TO-LEFT OVERRIDE×1at 95
  • U+202CPOP DIRECTIONAL FORMATTING×1at 112

Non-ASCII whitespace (1)

Look like a normal space but are a different codepoint (NBSP, narrow space, ideographic space).

  • U+00A0NO-BREAK SPACE×1at 34

Homoglyph look-alike (2)

Cyrillic or Greek letters that look like Latin ones (e.g. Cyrillic 'а' vs Latin 'a'). Used for spoofing.

  • U+0421CYRILLIC CAPITAL LETTER ESlooks like C×1at 0
  • U+0430CYRILLIC SMALL LETTER Alooks like a×1at 27

Zero-width and bidirectional characters are removed, non-ASCII spaces become a normal space, and Cyrillic/Greek look-alikes are mapped to their ASCII equivalent.

Updated . Provided as is. Check the output before you rely on it in production.

How to use Homoglyph & Invisible Character Detector

  1. 1

    Paste the text or code

    Drop a snippet, filename, URL, username, or prompt into the scan box. Use Load sample to see a string that already hides a zero-width space, a bidi override, and Cyrillic look-alikes.

  2. 2

    Read the findings

    Each suspicious character is grouped by category with its codepoint, Unicode name, occurrence count, and positions, so you can see exactly what was hidden and where.

  3. 3

    Inspect the highlighted view

    The rendered text marks every hit with a colored chip. Hover a chip to read its codepoint and name; invisible characters show their hex code and exotic spaces show as a dot.

  4. 4

    Copy the sanitized text

    Use Copy sanitized to grab a cleaned version with invisible and bidi characters stripped and homoglyphs mapped back to ASCII, ready to paste into your editor or ticket.

Questions and answers

What does this tool detect?
Homoglyphs are characters that look like others, such as a Cyrillic letter that mimics Latin a; with invisible or bidi control characters they can spoof names or hide instructions. This detector flags zero-width characters, bidi controls, non-ASCII spaces and Cyrillic or Greek look-alikes, and outputs a clean copy.
What is a Trojan Source / bidi attack?
Bidirectional override characters reorder how text displays without changing how it is stored, so source code can read one way to a human and run another way to a compiler. The tool flags those controls so reviews are not fooled.
How does the sanitize output work?
Zero-width and bidi characters are removed, non-ASCII spaces become a normal ASCII space, and curated Cyrillic/Greek look-alikes are mapped to their Latin equivalent. The rest of the text is left untouched.
Is my text kept private?
Yes. Scanning, highlighting, and sanitizing all run in your browser with plain JavaScript. The text you paste is never uploaded or sent to any server.
Why would normal-looking text contain these characters?
They appear in copied web content, phishing domains, prompt-injection payloads, watermarked AI output, and spoofed usernames. Catching them prevents look-alike accounts and hidden instructions reaching your code or model.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/homoglyph-detector/

For automation planning, fetch the canonical contract at /api/tool/homoglyph-detector.json.