Skip to content
ToolsOnDuty - free online tools
PDF Tools

PDF Security Inspector

Inspect PDF encryption, permissions, active features and privacy indicators without executing them.

Free browser toolRuns in your browserNo sign-up

Private PDF security workspace

Inspect encryption, permissions and active PDF features

Use QPDF to inventory security controls and risky interactive indicators without uploading the document or pretending this structural review is an antivirus scan.

—

review level

—

attention findings

Local

inspection

Private workspace. Files stay in this browser tab and are never uploaded to ToolsOnDuty.

Report excludes the PDF password and document content.

About the PDF Security Inspector

PDF Security Inspector creates a local structural inventory of a document using QPDF. It reports encryption method and bit strength, matched password role, permission flags, object count, PDF version and structural validation status.

The findings engine looks for JavaScript, automatic OpenAction and additional actions, external launch requests, form submissions, embedded files, rich media, XFA forms, links, signature objects and metadata indicators. It does not execute those features.

Results are severity-ranked and can be downloaded as a JSON report that excludes the PDF password and document content. A low review level means no recognized high-risk structural indicator was found; it is not a malware-free certificate.

This tool is not an antivirus sandbox and cannot prove that obfuscated or reader-specific exploit content is harmless. Digital signature objects are inventoried, but certificate trust, revocation and cryptographic validity are not verified.

Key features

  • QPDF encryption method and bit-strength inspection
  • Owner/user password role and permission inventory
  • JavaScript, OpenAction, additional-action and Launch indicators
  • Embedded attachment, rich-media, XFA and form detection
  • External link and form data-action indicators
  • Metadata and digital-signature object inventory
  • QPDF structural validation status
  • Severity-ranked findings and review score
  • Password-aware first-page preview
  • Downloadable privacy-safe JSON report
  • Private local WebAssembly processing

How to use

  1. 1Choose the PDF you want to inspect.
  2. 2For a protected document, enter its known password and confirm that you are authorized to inspect it.
  3. 3Select Inspect PDF security and wait while QPDF builds the encryption, permission and object inventory.
  4. 4Review high and medium findings first, then inspect the feature counts, structural status and permission flags.
  5. 5Download the JSON report when you need to retain or share the indicator summary.
  6. 6Use an antivirus scanner, sandbox or trusted security team for a malware verdict or investigation of suspicious content.

Examples

Review a protected contract
Input: AES-256 PDF with restricted printing and extraction
Output: Encryption, password role and nine permission capabilities plus active-feature findings

Permission flags are advisory and depend on the PDF reader.

Triage an unfamiliar PDF
Input: PDF received by email from an unknown sender
Output: Severity-ranked JavaScript, automatic-action, attachment, link, form and metadata indicators

Escalate suspicious findings to an antivirus scanner, sandbox or security team.

Frequently asked questions

Does this prove a PDF is safe?
No. It identifies recognized structural indicators and security controls without executing them. It is not an antivirus engine, exploit sandbox or malware-free certificate.
Does the inspector execute PDF JavaScript or attachments?
No. It reads QPDF object data and counts relevant names and actions without running scripts, launch actions, rich media or embedded files.
Can it inspect a password-protected PDF?
Yes, when you provide the correct password and confirm authorization. The password stays in the browser and is excluded from the report.
What encryption details are reported?
The report includes whether encryption is enabled, its method and bit strength, whether a user or owner password matched, and each QPDF permission capability.
Are digital signatures validated?
No. Signature object indicators are reported, but certificate trust, revocation, timestamp validity and cryptographic document integrity are not verified.
Why are attachments or links not automatically called malicious?
Both are legitimate PDF features. They are surfaced for review because their destination or embedded content must be assessed separately.
Is the PDF uploaded?
No. QPDF WebAssembly, PDF.js previewing, classification and report generation run in the current browser tab.

Open a related tool to prepare your files or refine the finished result.