Skip to content
ToolsOnDuty - free online tools
PDF Tools

PDF Sanitizer

Remove declared JavaScript, automatic actions, attachments and rich active content locally.

Free browser toolRuns in your browserNo sign-up

Content disarm workspace

Remove declared JavaScript and active PDF content

Strip known active-content object classes locally, verify their removal and keep an honest boundary between structural sanitization and antivirus scanning.

—

pages

—

active indicators

—

sanitized output

Private workspace. Files stay in this browser tab and are never uploaded to ToolsOnDuty.

Nothing downloads automatically. The original PDF remains unchanged.

About the PDF Sanitizer

PDF Sanitizer is a content-disarm workflow for removing declared active-content structures from a PDF. It strips JavaScript name trees and actions, automatic document and page actions, launch and data actions, embedded files, file-attachment annotations, rich media, movies, sound, 3D content and XFA.

Sanitization runs locally and rewrites the PDF without uploading it. The output must pass QPDF structural validation, a second object-inventory scan and PDF.js page-count verification before download is enabled.

This is not antivirus software and does not certify that a file is malware-free. It cannot detect obfuscated exploits hidden in images, fonts or parser vulnerabilities. Treat unknown PDFs cautiously and use endpoint security for untrusted files.

Key features

  • Declared JavaScript removal
  • OpenAction and additional-action removal
  • Launch, remote and form-data action removal
  • Embedded-file removal
  • Rich media, movie, sound and 3D removal
  • XFA removal
  • Optional external-link removal
  • Optional metadata removal
  • QPDF structure and object-inventory verification
  • Protected input support
  • Private local processing
  • Explicit download

How to use

  1. 1Choose the PDF you want to sanitize.
  2. 2Review the detected structural indicators.
  3. 3Choose whether to remove external links and document metadata.
  4. 4Remove active content.
  5. 5Review the verified output summary and first-page preview.
  6. 6Download the sanitized copy and keep the original until you have checked important forms and links.

Examples

Disarm a PDF before sharing
Input: A PDF with an automatic JavaScript action and embedded source file
Output: A structurally verified copy without the action or attachment

This reduces declared active-content exposure but is not malware certification.

Frequently asked questions

Is this an antivirus scanner?
No. It removes supported declared active-content structures. It does not scan payloads or certify that a PDF is free from malware or viewer exploits.
What is always removed?
Declared JavaScript, OpenAction, additional actions, Launch and remote/data actions, embedded files, file-attachment annotations, rich media, movies, sound, 3D content and XFA structures.
Will pages look the same?
Visible page artwork is preserved, and page count is verified. Interactive forms, media, attachments and automated behavior may stop working by design.
Are digital signatures preserved?
No. Rewriting any signed PDF changes its bytes and invalidates existing cryptographic signatures.
Does the PDF leave my device?
No. Loading, rewriting and verification run locally in your browser.

Open a related tool to prepare your files or refine the finished result.