Your Chatbot Widget Is Injecting Thousands of Hidden Links

On this page

A third-party widget, whether live chat, a social embed, a review badge or a support tool, loads its own markup into your pages, and that markup can include links to the vendor and to the vendor’s other customers. Google renders pages and indexes the rendered HTML, so links in that markup are part of what Google sees even when they sit in panels no visitor opens. Multiply a dozen injected links per page across a large site and the crawl report shows thousands of outbound links you never wrote. Before reacting, check whether those links are followed at all: if they are already marked nofollow or live inside an iframe, there may be nothing to fix. If they are followed links in your own page, add rel="nofollow" after the widget loads, and re-check after every vendor update.

A widget may add more than a button: its interface, including modals, panels and states the widget can display, whether or not a visitor ever triggers them. A chat widget’s “powered by” link, links to the vendor’s help center and, in certain widgets, a directory of the vendor’s other customers can all sit in markup that is rendered but hidden until someone interacts.

Hidden on screen isn’t the same as absent from the page. Google’s JavaScript SEO basics say Google uses the rendered HTML to index the page, and its guidance on crawlable links says Google can generally crawl a link that is an <a> element with an href. An anchor inside a collapsed panel is still an anchor in the rendered HTML. One widget adding a dozen or two links per page is trivial on one page and substantial across thousands, when the widget loads on every page.

That is why the team may not see it. The links aren’t in your CMS or templates, and a person reviewing the page sees nothing. They show up only in a rendered view, a JavaScript crawl or the DOM in developer tools, which is why they can sit unexamined until an outbound-link audit surfaces them.

The concerns, weighed honestly

It is easy to over-dramatize this, so weigh each concern against what Google says.

  • Association. Google’s guide to qualifying outbound links describes nofollow as the value to use when you’d rather Google not associate your site with, or crawl the linked page from, your site. Followed links from every page to a vendor and its unrelated customers are exactly the kind of association a site owner may not want. This is the concern the fix addresses.
  • Crawling. Extra links mean extra URLs for Google to consider. Google’s crawl budget guide says that if a site doesn’t have a large number of pages that change rapidly, its owner doesn’t need to read the guide. For a site that size, crawling isn’t the reason to act.

Treat this as hygiene, not an emergency. None of it justifies removing a widget that serves visitors. It justifies checking the links and cleaning them up if they are followed.

Step one is verification

The alarmist version of this advice skips straight to a fix. Check first:

  • Is the link marked? Google says links marked with nofollow, sponsored or ugc will generally not be followed. If the widget’s anchors already carry one of these, you are done.
  • Is it in an iframe? A widget that renders inside an iframe loads a separate document rather than adding anchors to your page’s own HTML.
  • Is it an anchor at all? See the audit section: a script or image URL isn’t a link.

Only followed anchors in your page’s own HTML need action.

The fix: add nofollow after the widget loads

If verification shows followed anchors in your HTML, a safe fix is JavaScript that adds rel="nofollow" to the anchors inside the widget’s container after the widget renders. Scope it to the widget’s container so your own editorial links are untouched.

It has to run after the widget loads, because a widget that loads asynchronously adds its markup after the page’s first render, and a script that runs too early finds nothing to change. Hook into the widget’s ready event, or watch the page for the container to appear, then mark the anchors inside it. Because the change applies to the same page visitors and Google both receive, everyone gets the same marked links.

Why not skip the widget for bots

The other option, not loading the widget when the requester is a crawler, is riskier. Google’s spam policies define cloaking as presenting different content to users and search engines with the intent to manipulate search rankings and mislead users. Branching page behavior on whether the visitor is a bot moves you toward that line, whatever your intent. The nofollow approach avoids the question by serving the same page to everyone, which makes it the better starting point.

Auditing it correctly

Run a crawl with JavaScript rendering that reports outbound links, and group them by destination domain. A cluster of links to one external domain can point to the widget responsible: a chat vendor, a support subdomain, a review platform.

One distinction helps prevent false alarms: separate anchors from asset URLs. A widget loads its own CSS, JavaScript and images from vendor URLs, and those references aren’t links. Look for <a href> anchors pointing to external pages, not <script src> or <img src> loads. Counting both can produce a frightening number that overstates the issue.

Treat it as recurring. Widgets change their markup on the vendor’s schedule, and an update can bring back followed links or change the container your fix depends on. Re-audit after vendor updates and after adding any new embed.

Frequently asked questions

How worried should I be about thousands of injected links?

Check whether they are followed first. If they are already marked or in an iframe, the count is cosmetic. If they are followed anchors in your HTML, mark them with nofollow so Google doesn’t associate your site with the destinations, but treat it as hygiene rather than an emergency.

Will adding nofollow break the widget?

No. rel="nofollow" tells search engines how to treat the link; it doesn’t change whether the link works for a visitor or how the widget behaves. Scope the change to the widget’s container so your own links are untouched.

Leave a comment

Your email address will not be published. Required fields are marked *