PDF Security Inspector
Inspect PDF encryption, permissions, active features and privacy indicators without executing them.
Private PDF security workspace
Inspect encryption, permissions and active PDF features
Use QPDF to inventory security controls and risky interactive indicators without uploading the document or pretending this structural review is an antivirus scan.
—
review level
—
attention findings
Local
inspection
Private workspace. Files stay in this browser tab and are never uploaded to ToolsOnDuty.
About the PDF Security Inspector
PDF Security Inspector creates a local structural inventory of a document using QPDF. It reports encryption method and bit strength, matched password role, permission flags, object count, PDF version and structural validation status.
The findings engine looks for JavaScript, automatic OpenAction and additional actions, external launch requests, form submissions, embedded files, rich media, XFA forms, links, signature objects and metadata indicators. It does not execute those features.
Results are severity-ranked and can be downloaded as a JSON report that excludes the PDF password and document content. A low review level means no recognized high-risk structural indicator was found; it is not a malware-free certificate.
This tool is not an antivirus sandbox and cannot prove that obfuscated or reader-specific exploit content is harmless. Digital signature objects are inventoried, but certificate trust, revocation and cryptographic validity are not verified.
Key features
- QPDF encryption method and bit-strength inspection
- Owner/user password role and permission inventory
- JavaScript, OpenAction, additional-action and Launch indicators
- Embedded attachment, rich-media, XFA and form detection
- External link and form data-action indicators
- Metadata and digital-signature object inventory
- QPDF structural validation status
- Severity-ranked findings and review score
- Password-aware first-page preview
- Downloadable privacy-safe JSON report
- Private local WebAssembly processing
How to use
- 1Choose the PDF you want to inspect.
- 2For a protected document, enter its known password and confirm that you are authorized to inspect it.
- 3Select Inspect PDF security and wait while QPDF builds the encryption, permission and object inventory.
- 4Review high and medium findings first, then inspect the feature counts, structural status and permission flags.
- 5Download the JSON report when you need to retain or share the indicator summary.
- 6Use an antivirus scanner, sandbox or trusted security team for a malware verdict or investigation of suspicious content.
Examples
AES-256 PDF with restricted printing and extractionEncryption, password role and nine permission capabilities plus active-feature findingsPermission flags are advisory and depend on the PDF reader.
PDF received by email from an unknown senderSeverity-ranked JavaScript, automatic-action, attachment, link, form and metadata indicatorsEscalate suspicious findings to an antivirus scanner, sandbox or security team.
Frequently asked questions
- Does this prove a PDF is safe?
- No. It identifies recognized structural indicators and security controls without executing them. It is not an antivirus engine, exploit sandbox or malware-free certificate.
- Does the inspector execute PDF JavaScript or attachments?
- No. It reads QPDF object data and counts relevant names and actions without running scripts, launch actions, rich media or embedded files.
- Can it inspect a password-protected PDF?
- Yes, when you provide the correct password and confirm authorization. The password stays in the browser and is excluded from the report.
- What encryption details are reported?
- The report includes whether encryption is enabled, its method and bit strength, whether a user or owner password matched, and each QPDF permission capability.
- Are digital signatures validated?
- No. Signature object indicators are reported, but certificate trust, revocation, timestamp validity and cryptographic document integrity are not verified.
- Why are attachments or links not automatically called malicious?
- Both are legitimate PDF features. They are surfaced for review because their destination or embedded content must be assessed separately.
- Is the PDF uploaded?
- No. QPDF WebAssembly, PDF.js previewing, classification and report generation run in the current browser tab.
Continue your workflow
Open a related tool to prepare your files or refine the finished result.
- Featured toolPDF ToolsRepair & Validate PDF
Check PDF structure, repair recoverable damage with QPDF and verify the rebuilt output.
Open tool - Featured toolPDF ToolsUnlock PDF
Remove PDF password protection locally with the correct user or owner password.
Open tool - Featured toolPDF ToolsProtect PDF
Add AES-256 password protection and configurable viewer permissions to a PDF.
Open tool - Security & CryptographyMetadata Privacy Cleaner
Inspect and remove common private metadata from images and PDFs entirely in your browser.
Open tool
