PDF Sanitizer
Remove declared JavaScript, automatic actions, attachments and rich active content locally.
Content disarm workspace
Remove declared JavaScript and active PDF content
Strip known active-content object classes locally, verify their removal and keep an honest boundary between structural sanitization and antivirus scanning.
—
pages
—
active indicators
—
sanitized output
Private workspace. Files stay in this browser tab and are never uploaded to ToolsOnDuty.
About the PDF Sanitizer
PDF Sanitizer is a content-disarm workflow for removing declared active-content structures from a PDF. It strips JavaScript name trees and actions, automatic document and page actions, launch and data actions, embedded files, file-attachment annotations, rich media, movies, sound, 3D content and XFA.
Sanitization runs locally and rewrites the PDF without uploading it. The output must pass QPDF structural validation, a second object-inventory scan and PDF.js page-count verification before download is enabled.
This is not antivirus software and does not certify that a file is malware-free. It cannot detect obfuscated exploits hidden in images, fonts or parser vulnerabilities. Treat unknown PDFs cautiously and use endpoint security for untrusted files.
Key features
- Declared JavaScript removal
- OpenAction and additional-action removal
- Launch, remote and form-data action removal
- Embedded-file removal
- Rich media, movie, sound and 3D removal
- XFA removal
- Optional external-link removal
- Optional metadata removal
- QPDF structure and object-inventory verification
- Protected input support
- Private local processing
- Explicit download
How to use
- 1Choose the PDF you want to sanitize.
- 2Review the detected structural indicators.
- 3Choose whether to remove external links and document metadata.
- 4Remove active content.
- 5Review the verified output summary and first-page preview.
- 6Download the sanitized copy and keep the original until you have checked important forms and links.
Examples
A PDF with an automatic JavaScript action and embedded source fileA structurally verified copy without the action or attachmentThis reduces declared active-content exposure but is not malware certification.
Frequently asked questions
- Is this an antivirus scanner?
- No. It removes supported declared active-content structures. It does not scan payloads or certify that a PDF is free from malware or viewer exploits.
- What is always removed?
- Declared JavaScript, OpenAction, additional actions, Launch and remote/data actions, embedded files, file-attachment annotations, rich media, movies, sound, 3D content and XFA structures.
- Will pages look the same?
- Visible page artwork is preserved, and page count is verified. Interactive forms, media, attachments and automated behavior may stop working by design.
- Are digital signatures preserved?
- No. Rewriting any signed PDF changes its bytes and invalidates existing cryptographic signatures.
- Does the PDF leave my device?
- No. Loading, rewriting and verification run locally in your browser.
Continue your workflow
Open a related tool to prepare your files or refine the finished result.
- Featured toolPDF ToolsPDF Security Inspector
Inspect PDF encryption, permissions, active features and privacy indicators without executing them.
Open tool - Featured toolPDF ToolsPDF Attachments Manager
Extract, add and remove embedded PDF files with verified local QPDF processing.
Open tool - Featured toolPDF ToolsRepair & Validate PDF
Check PDF structure, repair recoverable damage with QPDF and verify the rebuilt output.
Open tool - PDF ToolsFlatten PDF
Make PDF form fields permanent or completely flatten every page into fixed content.
Open tool
