LocalPDFlab

Read-only PDF security review

Inspect a PDF for risky content

Find supported scripts, automatic actions, embedded files, external destinations, privacy data, interactive content, and structural warnings before you trust or share a PDF.

Scripts are not executedFiles stay in your browserDownloadable JSON report

Drop a PDF here, or click to choose one

Inspect scripts, attachments, links, actions, forms, layers, metadata, and structural warnings locally.

Files stay on your device

Enter PDF password

Enter the password to open.

Quick start

How to inspect a PDF for risky content

  1. 1

    Choose a PDF

    Select one PDF from your device. Enter its password if you are authorized to open a locked document.

  2. 2

    Let the local inspection finish

    The browser inventories supported scripts, actions, attachments, links, annotations, forms, layers, metadata, signatures, and structural warnings.

  3. 3

    Review prioritized findings

    Start with high-priority items, then examine review, low-concern, and informational results. Select a page-based result to open that page in the preview.

  4. 4

    Export or clean the document

    Download the JSON report for your records. If unwanted data is present, create a separate sanitized or redacted copy.

A PDF can do more than display pages

PDF supports interactive forms, JavaScript, automatic event actions, embedded files, multimedia, external links, optional content layers, comments, and digital signatures. Many of these features have legitimate business uses. They still deserve review when a document comes from an unfamiliar sender, arrives unexpectedly, or will be distributed outside your organization.

This inspector treats the PDF as data. It inventories supported features, identifies where page-based items appear, checks document structure, and assigns a review priority. It does not intentionally activate the behaviors it reports.

What the inspection checks

CategoryExamples
Active behaviorDocument JavaScript, automatic event actions, launch actions, remote navigation, form submission, data import, and multimedia actions.
Embedded contentFile attachments, attachment icons, PDF portfolios, sound, movies, 3D content, screen annotations, and rich media.
External destinationsWebsite, email, local-file, embedded-data, and JavaScript link schemes. The tool records destinations without opening them.
Privacy dataMetadata, comments, markups, hidden or optional layers, stored form widgets, and information outside the visible page.
Structure and trustMalformed PDF warnings, XFA, signatures, encryption on upload, version information, and features needing a trusted viewer.

How to interpret the priority labels

High priority

Features such as JavaScript, launch actions, data import, form submission, executable-looking attachments, unusual link schemes, or serious structure errors. Stop and investigate before trusting the file.

Review

Embedded files, rich media, XFA, remote navigation, portfolios, automatic actions, or structure warnings. These may be legitimate but should match the document's expected purpose.

Low concern

Ordinary external links, comments, metadata, and optional layers. These are common, but they can create privacy or sharing concerns.

Informational

Forms and signatures that provide context for review. Their presence alone is not treated as a security problem.

Inspection is not antivirus analysis

A browser tool can identify known PDF structures, but it cannot safely execute every viewer-specific behavior or detect every exploit. It also cannot confirm that an attachment is harmless just because its extension looks familiar. A report with no findings means only that the supported checks did not identify the listed features.

For an untrusted PDF, keep your PDF viewer and operating system updated, avoid enabling scripts or opening attachments, and use the malware-analysis process approved by your employer or security provider. Do not upload regulated or confidential files to third-party scanners unless your policy permits it.

Choose the correct follow-up tool

Remove hidden or active PDF data: use Sanitize PDF. Standard cleanup preserves searchable content, while Maximum privacy rebuilds visible pages.

Remove visible confidential information: use Redact PDF. Sanitization alone does not remove words or images that appear on the page.

Review document properties only: use Edit PDF Metadata when broader cleanup is unnecessary.

Protect the finished copy: use Password Protect PDF after inspection, cleanup, and final review.

Frequently asked questions

Can this tool tell me whether a PDF has a virus?

No. It identifies supported PDF features and structural warnings, but it is not antivirus software, a sandbox, or a malware verdict. Scan untrusted files with security software approved by your organization.

Does the inspection run PDF JavaScript?

No. JavaScript and action entries are inventoried as data. The tool does not intentionally execute document scripts, open discovered links, launch files, or submit forms.

What risky PDF content does it check?

It checks supported document JavaScript, automatic actions, launch and form-submission actions, external links, embedded files, file attachment annotations, rich media, XFA forms, comments, optional layers, metadata, signatures, portfolios, and PDF structure warnings.

Are all attachments dangerous?

No. Attachments can be legitimate. The report marks them for review because they are separate files inside the PDF. Executable, script, and active web file extensions receive higher priority, but a filename alone cannot prove malicious intent.

Why are external links listed as low concern?

Ordinary website and email links are common and are not automatically unsafe. They are listed so you can verify unexpected destinations. Unusual schemes such as JavaScript, local-file, or embedded-data links receive high priority.

Does a no-risk result mean the PDF is safe?

No. It means the inspector did not find supported risky features. Proprietary, malformed, encrypted, steganographic, or newly developed techniques may not be detected.

Can it inspect a password-protected PDF?

Yes, if you know the password and are authorized to open the file. Unlocking and inspection happen locally. The original PDF remains unchanged.

What should I do after finding risky content?

Confirm whether each feature is expected. Use Sanitize PDF to remove supported hidden or active data, Redact PDF for visible confidential content, and approved antivirus or endpoint security tools for malware analysis.

Does the JSON report contain sensitive information?

It can contain the PDF filename, attachment names, link domains, page locations, metadata field names, and technical findings. Store and share the report with the same care as the source document.

Choose another private, browser-based tool for the next step in your document workflow.