Skip to content

PDF Security

PDF Security Inspector

Every security-relevant feature of a document, inventoried in one pass.

Processed locally in your browser. Your file is not uploaded to any server. How this works

  1. 01Add your file
  2. 02PDF Security Inspector
  3. 03Download

Runs in your browser · nothing uploaded

About PDF security inspector

Where the checkers answer one question each, this is the survey. It walks the whole document and inventories everything with a bearing on security or disclosure: the encryption handler and cipher, every permission bit, the document information dictionary and XMP metadata, the presence of signature fields and whether they carry cryptographic content, embedded and attached files, JavaScript actions, launch and URI actions, and whether the file has been incrementally updated — which means earlier revisions may still be recoverable inside it. The output is descriptive rather than prescriptive: a map of what is in the file, organised so nothing hides. Reach for it before you send a document outward, or when one has arrived and you want to know what you are opening. It does not score the file or rank risks; for a judgement-oriented read of the same territory, use PDF Security Analyzer.

How to PDF security inspector

  1. 01

    Load the document

    Any PDF. Encrypted files are surveyed as far as their readable structure allows.

  2. 02

    Work through the sections

    Encryption, permissions, metadata, signatures, attachments and active content are reported as separate blocks.

  3. 03

    Note the incremental-update line

    If the file has been saved incrementally, previous content may still be embedded — a common accidental-disclosure route.

  4. 04

    Follow up with a targeted tool

    Strip metadata, re-encrypt, or flatten as the survey indicates.

What this tool does

  • Single pass covering encryption, permissions, metadata, signatures, attachments and actions
  • Detects embedded files and attachments that travel invisibly with a document
  • Reports JavaScript, launch and URI actions that a reader might execute or follow
  • Flags incremental updates, where earlier revisions can remain recoverable in the file
  • Purely descriptive output — nothing in the document is altered

Limitations worth knowing

Every PDF tool has constraints. Stating them plainly is more useful than discovering them halfway through your work.

  • Descriptive, not evaluative: it lists what exists without ranking how dangerous it is.
  • On an encrypted file the survey covers only the readable structure; content-level findings need the password.
  • Detecting a JavaScript action is not the same as analysing what that script does — no code is executed or interpreted.
  • Does not validate signature certificate chains; presence and properties only.

How your file is handled

This tool runs entirely inside this browser tab. When you choose a file, your browser reads it from your own disk and hands the bytes to JavaScript running on this page — no network request carries your document anywhere. You can confirm that yourself: open your browser’s developer tools, switch to the Network panel, and run the tool. You will see no upload.

Nothing is stored after the fact. Closing or reloading this tab discards the file, the result and everything derived from them, because none of it ever left your machine. Read how local processing works.

Questions about PDF security inspector

How is this different from the individual checkers?

Scope. The encryption and permissions checkers each answer one precise question for someone who already knows what they are looking for. This surveys the entire security surface for someone who wants to know what is in a file at all.

What is an incremental update and why is it flagged?

PDFs can be saved by appending changes rather than rewriting the file. Redactions and deletions applied that way may leave the original content still present earlier in the bytes, recoverable with the right tool. It is a real disclosure risk worth knowing about.

Should I worry if it reports embedded JavaScript?

Worth attention rather than alarm. Legitimate forms use scripts for validation. The concern is a script you did not expect in a document you did not author — this report tells you it is there so you can decide.

Does it check whether signatures are valid?

No. It reports that signature objects exist and describes their properties. Establishing that a signing certificate traces back to a trusted root, and that it has not been revoked, is a separate job a browser-based tool cannot do credibly.

Read more about this