Sanitize PDF

Sanitize PDF

Remove scripts, embedded files and hidden actions, and see exactly what was in there.

Sanitize a PDF for free in your browser. A PDF can carry JavaScript that runs when the file opens, actions that ask to start a program, whole files hidden inside it and links that reach out to other documents. This tool removes all of it, keeps the pages, the text and the layout exactly as they were, and tells you what it found instead of just saying done. Nothing is uploaded: the document never leaves your device.

Select fileScanDownload
Private
Stays on Device
Instant

When this is worth doing

  • A PDF arrived by email from someone you do not know well
  • Passing a document on to a colleague or a client without passing on whatever came with it
  • Archiving files, where anything that runs is a liability years from now
  • Uploading to a portal that rejects PDFs containing JavaScript or attachments
  • Checking whether a file really is just a document before you trust it
  • Cleaning a form built with XFA so ordinary readers can open it

What you get

  • It Tells You What It Found - Most cleaners say done. This one lists every kind of active content that was in the file, and how many places it was in
  • The Document Survives - Pages, text, fonts, bookmarks and page labels are left alone. Only the parts that execute are removed
  • Every Object, Not Just The Cover - Actions can hang off a page, an annotation, a form field or an outline entry, so the whole file is walked rather than only its catalog
  • Nothing Leaves Your Device - A file you do not trust is the last one you should upload anywhere. This runs entirely in your browser

Privacy First:

Your PDF is read and rewritten inside your browser. No upload, no server, no copy kept anywhere. Close the tab and nothing remains.

Questions about sanitizing PDFs

Is this an antivirus?
No, and we will not pretend otherwise. It does not look for known malware or judge whether anything it found was harmful. It removes whole categories of active content, scripts, launch actions, form submissions, embedded files, media objects, remote jumps and XFA, whether or not any given one was dangerous. That is a different job from scanning, and for a document you simply want to read or forward it is usually the more useful one.
Will the document still look the same?
Yes. Page content, text, images, fonts, page size, bookmarks and page labels are untouched. The only visible change is that a video or sound object embedded in a page will not play, and a link that pointed at another file will no longer jump there.
What about the form fields I filled in?
Ordinary form fields and their values are kept. What is removed is the code attached to them, for example a script that fires when you leave a field. If a form was built with XFA, which is a second form format layered on top, that layer is removed and the ordinary fields underneath remain.
Does it really delete an embedded file, or just hide it?
It deletes it. Unlinking an attachment leaves its bytes sitting in the file as an unreferenced object, which no reader will show you but anyone who pulls the objects apart can recover. The streams holding the data are removed from the document, not just the entries pointing at them.
Why does the count sometimes look small?
Each piece of active content is counted once, in the place it lives. A script that runs on open is one open action rather than an open action plus a script, because it is one thing to know about. We would rather report a number you can act on than a larger one that flatters the tool.
Can I sanitize a password protected PDF?
Not directly. Unlock it first with the Unlock PDF tool, then sanitize the result. Both steps run in your browser and neither one uploads the file.
💡

After sanitizing, run Privacy Scanner to see what the document still says about itself, or strip its metadata.

You might also need: