VelloDoc
Security

How to check a PDF is safe and make a clean copy

Most PDFs are just pages of text and pictures. But the format can also carry code, attached files and content you can't see, and that's what makes a PDF from a stranger worth a second look. This guide explains what can hide inside a PDF, the signs that a file needs care, and how to make a clean copy that keeps the pages and drops the risky parts.

By VelloDocUpdated Reading time: 6 min

Try it now: PDF Sanitizer

Check a PDF for scripts, hidden layers, attached files and risky actions, then save a clean copy with a before and after report.

Open the full PDF Sanitizer page

Choose files

Drop files here or click to browse


Accepts: PDFMax 80 MBDeleted after delivery

Why a PDF can be risky

A PDF isn't only a picture of a page.

  • JavaScript: The format allows JavaScript, which some readers run to check forms or change what's shown.
  • Actions: It allows actions. It can fire when the file opens, when a page is shown or when a field is clicked, and some actions can try to open another program or send data to a website.
  • Files carried inside: A PDF can also carry other files inside it, like a spreadsheet or a program.
  • Why attackers use them: Attackers use these features because people trust PDFs more than they trust unknown programs.
  • Keep your reader updated: Keeping your PDF reader updated closes most known holes, but removing the features a file doesn't need closes them for good.

Hidden content and privacy leaks

Not every problem is an attack.

  • Switched-off layers: A PDF can hold layers that are switched off, so text you never saw is still in the file and still searchable.
  • Hidden notes, invisible text and metadata: It can hold notes marked as hidden, text drawn in invisible ink, old form data, and metadata like the author's name, the company's software and the date the file was made.
  • It all travels with the file: When you pass a file on, all of this goes with it. That's how draft comments, internal names and deleted wording end up with people who were never meant to see them.

Warning signs worth noticing

  • A file that asks you to enable something: Be careful with a PDF you didn't expect, especially one that asks you to enable something, click a button to see the content, or open an attachment inside it.
  • A file bigger than it should be: A document that's supposed to be a simple invoice but is much bigger than it should be may be carrying extra files.
  • A security warning from your reader: A reader showing a security warning about a script or a program trying to run is a clear sign to stop.
  • None of this is proof: None of these prove a file is harmful, and a harmful file may show no signs at all. That's why making a clean copy is a good habit for any file from outside.

Scanning a PDF before opening it

  • What PDF Sanitizer reports: PDF Sanitizer opens the file on the server, without running anything in it, and counts what it finds: scripts, open and page actions, launch and submit commands, media, attached files, hidden layers, hidden notes, invisible text, links to websites and metadata. You see that list as soon as the upload finishes.
  • A clean bill of health: A file with no scripts, actions or attachments is lower risk.
  • When to make a clean copy: A file with any of them deserves a clean copy before you open it, even if the sender is someone you know, because their computer may be the one that's affected.

Making the clean copy

Pick what to remove and save.

  • The defaults: The default choices remove scripts, actions, media, attached files, hidden layers, hidden notes and metadata, which suits almost every file you only need to read.
  • Links: Leave links to websites on unless you don't trust them, because a list of sources is useful.
  • Invisible text on scans: Leave invisible text on for scanned documents, because it's the searchable text that OCR adds.
  • The before-and-after report: The report shows each item before and after. You can see exactly what changed and download a copy for your records.

What a clean copy doesn't do

A clean copy isn't a virus scan.

  • It doesn't detect viruses: The tool doesn't compare the file with known viruses, and a picture on a page still shows whatever it shows, including a fake login screen or a phone number for a scam.
  • It doesn't hide what's on the page: Cleaning also doesn't hide private details you can see on the page.
  • Redact and remove metadata: For those, use Redact PDF to delete them properly, and Remove Metadata if you only need the document properties cleared.
  • Protect it before sending: Then, if the file is going to someone else, protect it with Protect PDF or send it as a link that expires.

Questions

Is it safe to upload a suspicious PDF?

Yes. The file is read on the server without running any scripts or actions, and it's deleted when your download finishes. Nothing in it can run on your computer during the upload.

Will cleaning break my PDF?

The pages look the same. Forms lose their automatic sums and checks, because those are scripts, and attached files are gone unless you keep that option off.

Should I still use antivirus software?

Yes. A clean copy removes the features most PDF attacks rely on, but it isn't a replacement for antivirus software and keeping your PDF reader updated.

Tools for this topic