Skip to content

PDF Security

PDF Security Analyzer

Not just what is in the file — which parts of it are a problem.

Processed locally in your browser. Your file is not uploaded to any server. How this works

  1. 01Add your file
  2. 02PDF Security Analyzer
  3. 03Download

Runs in your browser · nothing uploaded

About PDF security analyzer

The analyzer covers similar ground to the inspector and then does the part the inspector deliberately refuses: it forms a view. Each finding is weighted by how much it actually matters and paired with a recommended action. Weak legacy encryption is treated as a high-severity finding because it offers false assurance. Permission flags used as a substitute for encryption are called out as a misplaced reliance rather than a protection. Metadata carrying an internal author name, an organisational software fingerprint or a local file path is raised as a disclosure risk with a concrete fix. Incremental updates are escalated when the document also shows signs of redaction, because that combination is how supposedly removed text gets recovered. Hidden layers, off-page content and white-on-white text are surfaced as content that looks absent but is not. The audience is someone about to publish or send a document who needs to know what to fix, in what order, rather than a complete inventory of what exists.

How to PDF security analyzer

  1. 01

    Load the document you are about to share

    Ideally the final version, since the assessment reflects the file as it stands.

  2. 02

    Read findings in severity order

    High-severity items come first, each with the reason it is weighted that way.

  3. 03

    Apply the recommended fix

    Findings link to the tool that resolves them — strip metadata, re-encrypt, flatten or rewrite the file.

  4. 04

    Re-run after fixing

    Analyse the corrected file to confirm the findings have actually cleared.

What this tool does

  • Findings ranked by severity with the reasoning stated, not a single opaque score
  • Treats weak legacy encryption as worse than none, because it creates false confidence
  • Detects hidden content: optional-content layers, off-page objects and invisible text
  • Escalates incremental updates when combined with signs of redaction
  • Each finding names the specific remediation tool rather than offering vague advice

Limitations worth knowing

Every PDF tool has constraints. Stating them plainly is more useful than discovering them halfway through your work.

  • Severity weighting is a heuristic judgement. Your threat model may reasonably rank things differently.
  • Not a malware scanner. It reports that active content exists; it does not determine intent or execute anything.
  • Findings need the file to be readable — an encrypted document limits the assessment to structural observations.
  • A clean report is evidence of nothing detected, not proof that a document is safe to publish.

How your file is handled

This tool runs entirely inside this browser tab. When you choose a file, your browser reads it from your own disk and hands the bytes to JavaScript running on this page — no network request carries your document anywhere. You can confirm that yourself: open your browser’s developer tools, switch to the Network panel, and run the tool. You will see no upload.

Nothing is stored after the fact. Closing or reloading this tab discards the file, the result and everything derived from them, because none of it ever left your machine. Read how local processing works.

Questions about PDF security analyzer

Why choose this over PDF Security Inspector?

Use the inspector when you want a neutral inventory of what is in a file. Use the analyzer when you need to know what to fix before sharing it — the same territory, sorted by consequence and paired with actions.

Why is weak encryption ranked above no encryption?

Because of how people behave around it. An unencrypted file is handled with appropriate care. An RC4-encrypted file is treated as protected and circulated more freely, which makes the false assurance the more dangerous state.

What kind of hidden content does it find?

Optional-content groups that are switched off, objects positioned outside the visible page area, and text drawn in a colour matching its background. All three are invisible on screen and fully present in the file.

Does a clean report mean the document is safe to publish?

No. It means nothing the analyzer checks for was found. Judgement about the content itself — whether a sentence should be public at all — is not something any automated tool can supply.

Is the file sent anywhere for analysis?

No. The whole assessment runs in your browser tab, which is the only sensible arrangement for a tool whose purpose is finding accidental disclosures.

Read more about this