Home / Tools / See what is hidden inside a PDF

Free · no upload · no account

See what is hidden inside a PDF

Choose a PDF or drop it here

Processed on this device. Nothing is uploaded.

Short answer

Open a PDF and it is examined in your browser for the things that do not appear on the page: metadata naming the author and their software, embedded JavaScript, files attached inside the document, text positioned off the page, optional layers, and earlier revisions left behind by re-saving. Nothing is uploaded, which matters most when the file is one you are unsure about.

Doing more than one thing?

The full editor puts every operation in one workspace with undo, so you are not exporting and re-opening between each step. Same engine, same privacy, still nothing uploaded.

Open the full editor Browse all tools

Why this one does not upload your file

Almost every free see what is hidden inside a pdf tool works by sending your document to a server, doing the work there, and sending a result back. That is a cost decision rather than a privacy one — server time costs money, which is why those tools meter you, ask for an account, or cap your file size.

This one runs the same work in your browser using JavaScript, so your file never travels anywhere. There is no upload step, no queue, no account, and no page limit — and the page keeps working if you disconnect from the internet partway through.

You do not have to take that on trust. Open your browser's network tab and watch while you work, or read how it works.

What happens to your file

  • It is read from your disk into this tab's memory
  • Every change happens on your own processor
  • The result is built in memory, reopened and checked before you are offered it
  • Your original file is never modified
  • Closing the tab releases everything — nothing is stored
Questions

Straight answers

What counts as hidden data in a PDF?
Anything carried by the file that is not printed on a page. Most commonly: the author name, organisation and original file path recorded automatically when a document is exported; comments attributed to named people; text drawn off the edge of the page; layers that are switched off; whole files attached inside; and earlier drafts still present because the document was re-saved rather than rewritten.
Why does it matter?
Because it travels. A contract exported from a word processor usually names whoever wrote it and which company they work for. That has revealed the real source of supposedly independent documents more than once, and it is invisible until somebody looks.
Is it safe to check a suspicious PDF here?
Safer than the alternative. The file is read by JavaScript in your own browser and never transmitted, so inspecting a file you do not trust does not also hand it to a third party. Nothing in the document is executed — scripts are detected and listed, never run.
Can I remove what it finds?
Metadata, yes — there is a button to download a copy with the title, author, keywords and producer history cleared. Attachments, layers and earlier revisions are reported but not yet strippable.
Does this detect malware?
No, and it does not claim to. It tells you a file contains JavaScript, an automatic action or an attachment. Whether those are malicious is a judgement it cannot make, and any tool saying otherwise from a browser is overreaching.