VelloDoc
PDF Security

PDF Sanitizer

Check a PDF for JavaScript, hidden layers, attached files and risky actions. Remove what you pick and download a clean copy with a before and after report.

Choose files

Drop files here or click to browse


Accepts: PDFMax 80 MBDeleted after delivery

Related tools

Next steps people often take after this one.

A PDF can hold far more than the pages you see. It can carry JavaScript, actions that run when the file opens, attached files, hidden layers and notes, and details about who made it. Most of the time these are harmless, but they're also how a bad file does damage. PDF Sanitizer scans the file, shows what it found, removes the parts you pick and gives you a clean copy with a report of what changed.

How to use PDF Sanitizer

  1. Add the PDF you want to check. The scan starts as soon as it's uploaded.
  2. Read the list of what was found, like scripts, attached files or hidden layers.
  3. Pick what to remove. The safe choices are already ticked.
  4. Select Clean PDF and download the clean copy.
  5. Look over the before and after report, and download it if you need a record.

What can hide inside a PDF

A PDF is a container.

  • Scripts and actions: Besides text and images, it can hold JavaScript that runs in some PDF readers, open actions that fire the moment the file opens, and launch actions that try to start another program.
  • Attachments, layers and hidden notes: It can carry whole files as attachments, layers that are switched off so you never see them, notes marked as hidden, and text drawn in invisible ink. Forms may include old XFA data.
  • Metadata: The file also stores metadata, like the author's name and the software used.
  • Good uses and bad: Some of this has good uses, like a form that adds up totals. But scripts and actions are also the usual way a harmful PDF tries to reach your computer, and hidden content is a common way private details leak.

What the scan and the clean copy do

  • The scan: When you upload a file, the tool opens it on the server and counts each kind of risky or hidden item, without running any of it.
  • What cleaning removes: Cleaning then removes what you picked: scripts and the actions that point to them, open and page actions, launch and form submit commands, media and 3D content, attached files, hidden layers along with what's drawn on them, hidden notes, and metadata. You can also remove links to websites and invisible text.
  • Scanned again afterwards: At the end, the clean copy is scanned again, so the report shows real before and after numbers instead of a guess.
  • What stays: Visible text, images, pages and links inside the document stay as they were.

Choosing what to remove

  • The defaults: The ticked options are safe for almost any file you just want to read, print or pass on.
  • Removing links: Two options are off by default for a reason. Removing links to websites also removes useful ones, like a list of sources.
  • Removing invisible text also removes the hidden text layer that OCR PDF adds to scans, so the file stops being searchable.
  • Turn these on only when needed: Turn these on only when you need to.
  • If a form stops working: If a form stops adding up totals after cleaning, that's because its scripts were removed. Keep the original if you still need those features, and share only the clean copy.

A clean copy isn't a virus scan

  • What it does and doesn't check: This tool removes the parts of a PDF that can run code or hide content. It doesn't check files against a list of known viruses, and it can't promise a file is safe in every PDF reader.
  • Why it still lowers risk: A clean copy does lower the risk a lot, because most PDF attacks need scripts, actions or attachments to work.
  • For files from strangers: For files from people you don't know, keep your PDF reader updated, open the clean copy instead of the original, and run your normal antivirus too.
  • For private details: If a file holds private details, use Redact PDF and Remove Metadata as well before you send it on.

When people use PDF Sanitizer

Opening files from strangers

Clean an invoice or CV from an unknown sender before you open it, so scripts and attachments never get a chance to run.

Publishing documents online

Strip scripts, hidden layers, old metadata and attachments before a PDF goes up on your website.

Passing files between teams

Give colleagues a clean copy along with the report, so they know exactly what was taken out.

Limitations to know

PDF Sanitizer cleans one PDF at a time, up to the upload limit. It isn't an antivirus and can't promise a file is safe in every reader. Removing scripts stops form calculations. Hidden layers built in unusual ways may be only partly removed, and the report says when that happens. Pages that are pictures still show whatever the picture shows.

PDF Sanitizer: common questions

Does PDF Sanitizer tell me if a file is a virus?

No. It finds and removes the parts of a PDF that can run code or hide content, which blocks most PDF attacks. It isn't an antivirus, so use one as well for files you don't trust.

Will the clean copy look the same?

Yes, in almost every case. Visible text, images and page layout stay the same. What changes is hidden content, scripts, attachments and, if you choose, links and invisible text.

Why did my form stop working out totals?

Form sums and checks are written in JavaScript, and removing JavaScript removes them. Keep the original form if you still need those features.

Where does the scan run?

On the VelloDoc server, in a temporary folder with a random name. The folder is deleted when your download finishes.

Can it clean a password protected PDF?

Yes, if you know the password. Enter it when asked. The clean copy is saved without the password, so protect it again with Protect PDF if you need to.

Learn more