See what a PDF hides
A PDF carries more than its pages: who wrote it and with which program, files tucked inside it, JavaScript, instructions to open a web address or launch a program, form values, and every earlier version if it was edited and saved again. Drop one here to see all of it, each finding in one plain sentence, before you open it in a reader.
The file is read on your device by this tab. It is not uploaded, and nothing in it is run or followed.
What it shows
- A summary. Pages, PDF version, the program that made the document (Creator, for example “Microsoft Word for Microsoft 365”) and the one that wrote the PDF (Producer), author, title, subject, keywords, created and modified dates, and the edit history in the XMP metadata when there is one (Acrobat, InDesign and Illustrator add an entry each time they save). Page sizes named when they are A4, US Letter and so on, whether it is encrypted and which permissions are withheld, whether it is tagged for screen readers, whether it is linearized for fast web view, and the first six pages as thumbnails.
- Embedded files. A PDF can carry any file inside it: a spreadsheet behind a report, the XML of an e-invoice (ZUGFeRD and Factur-X invoices are PDFs with an XML file attached), or a program. Each is listed with its size and can be saved as it is. Types that run code when opened (.exe, .js, .vbs, .html, macro-enabled Office files and others) are flagged.
- JavaScript, as text. Document-level scripts (run when the file opens), the script of the OpenAction, scripts on page open and close, and the keystroke, format, validate and calculate scripts of form fields, each with the event that triggers it.
- Automatic actions. What the file asks a reader to do by itself or on a click: open a web address when it is opened, launch a program (a Launch action, with its command line), send the form to an address (SubmitForm), import data, or open another file.
- Form fields with their name, type and saved value, including fields that are hidden or look empty on paper.
- Links: every clickable area that leads out of the document, with its page, as text.
- Changes after the first save. “This file was changed twice after it was first saved”, with the byte offset where each version ends.
- Digital signatures: the signer named in the certificate, who issued that certificate, the signing time, the reason and location, the exact bytes the signature covers, whether the file was changed after signing, and whether the covered bytes still match the digest stored in the signature.
- Fonts on each page (the first 40), with their type and whether they are embedded.
How a PDF keeps its earlier versions
The PDF standard (ISO 32000, section 7.5.6, “incremental updates”) lets a program save changes by appending them: the new and changed objects go at the end of the file, followed by a new cross-reference table, a trailer that points back to the previous one (/Prev) and another %%EOF line. Nothing before is removed, so cutting the file after an earlier %%EOF gives back the earlier version, text that was “deleted” included. viewhack follows that chain of trailers from the last startxref to the first and counts the links. A linearized (“fast web view”) file is written with two sections from the start, and that is not counted as an edit.
A signature works the same way. Signing appends a signature dictionary whose /ByteRange lists two stretches of the file, everything before and after the signature’s own /Contents, and the signature vouches for exactly those bytes. If more was appended after signing (a second signature, a filled-in field, or an edit), the ranges stop short of the end of the file, and this page says by how many bytes and versions.
For example, the IRS Form W-9 (Rev. March 2024) as downloaded from irs.gov reads as: 6 pages, PDF 1.7, made with Designer 6.5, three document-level scripts (Adobe’s reader version checks), 23 form fields, changed once after it was first saved, and that change is a usage-rights signature by “ARE Production V8.1 G3 P24 1007685” (Adobe Reader Extensions, which lets Adobe Reader save the filled-in form) covering the whole file, its SHA-1 digest matching.
What this cannot do
- Run anything. No script in the PDF is executed: PDF.js reads the file with eval off and its scripting sandbox is never created. That also means a form whose fields are filled or calculated by scripts shows only the values saved in the file.
- Check a signature’s trust chain. It names the certificate and its issuer and compares the digest of the signed bytes with the one in the signature; it does not check the signature’s cryptography over its signed attributes, revocation, or whether the issuer is trusted. Adobe Acrobat Reader does that.
- Repair, edit or remove anything. It only reads. To strip scripts or attachments, a PDF editor (or
qpdf) has to rewrite the file. - Tell you a file is safe. A clean report is not a malware scan: it lists what the file declares. An exploit can hide in a damaged font or image that no list shows, so a PDF from a stranger still belongs in an up-to-date reader.
- See inside encrypted files. A PDF that needs a password to open has its strings and streams encrypted; only its structure, revisions and signatures are reported. Files with only permission restrictions (an owner password) are read in full.
- Read XFA forms. Forms made with Adobe LiveCycle Designer can carry their fields in XML that only Adobe readers use; the regular form fields, when present, are listed, and the XFA is named.
To read the pages themselves, use the “Open it in a new tab” button: every browser has a PDF viewer built in. Adobe Illustrator files (.ai) are PDFs too and open in the Illustrator viewer.