Docuboxer

Check if a PDF Is Dangerous

Detect JavaScript, auto-actions and embedded files inside a PDF, without uploading it.

100% local — your files are never uploaded to any serverNo signupFree

Can a PDF contain a virus or malicious code?

Yes — the PDF format supports embedded JavaScript, actions that fire automatically on open (/OpenAction, /AA), and even attempts to launch external programs (/Launch), making it one of the most common ways malware gets disguised as an invoice, resume, or legal document. Docuboxer's PDF safety scanner reads the file's raw bytes right in your browser, without uploading anything, and flags every known risk marker: embedded JavaScript, auto-run actions, attachments, XFA forms, and external links — even when they're hidden behind hex-escaped names or packed inside a compressed stream. Any JavaScript it finds is shown as plain text, never executed, alongside a plain-English explanation of what each marker means and when it's actually normal to see it. It's free, requires no signup, and it isn't a substitute for antivirus software: a clean result doesn't guarantee the file is safe.

How to use Check if a PDF Is Dangerous

  1. Drag the suspicious PDF into the dropzone or click to pick it from your device — scanning starts automatically and the file never leaves your browser.
  2. Check the overall verdict first: it tells you at a glance whether high-risk markers were found (auto-launching JavaScript, /Launch), medium-risk ones (attachments, XFA forms), or only informational ones (links, forms).
  3. Open the markers table to see each one with its severity and an explanation of what it means and when it's legitimate — an /AcroForm with validation JavaScript, for instance, isn't suspicious on its own.
  4. If JavaScript was found, read it in its own section: it's rendered as plain text, never executed, and you can copy it to analyze further with another tool if you want to dig deeper.
  5. Copy any external links found (they're shown as plain text, never as clickable links) and check them before opening, or download the full report as a .txt file to keep as evidence.

Common use cases

Vet an email attachment before opening it

An invoice, resume, or legal notice landed in your inbox and something feels off — the sender, the urgency, the file extension. Before opening it in a reader with JavaScript enabled, run it through here to see if it has auto-run actions or tries to launch a program.

Audit third-party PDFs in an intake workflow

If your team processes PDFs uploaded by clients or vendors (contracts, forms, receipts), spot-check a sample periodically for injected JavaScript before those files hit an internal system.

Confirm a government or corporate PDF form is legitimate

XFA and AcroForm forms with validation JavaScript are normal, but they're also a targeted-phishing vector. Check what the code actually does before entering sensitive data.

Investigate a suspicious PDF from a download or USB drive

Before opening a PDF from an unknown source, check for /Launch (an attempt to run a program) or embedded files that could be the real payload of the attack.

Learn how PDF-based attacks actually work

Studying offensive or defensive security? Run this on sample PDFs — from a CTF, for example — to see /OpenAction, /JS, and the compressed streams that hide them in practice.

Frequently asked questions

Does this tool detect viruses in PDFs?

Not exactly. It doesn't check the file against a database of known malware signatures or run it inside a sandbox, which is how traditional antivirus software works. It performs static analysis instead: it inspects the PDF's structure and reports which risk-related constructs — JavaScript, auto-run actions, attachments — are present, along with an explanation. Treat it as a fast, free first filter, not a replacement for antivirus.

Does a clean result mean the PDF is 100% safe?

No. A clean result means none of the known markers this tool looks for were found, but that doesn't rule out other attack techniques, vulnerabilities in the PDF reader itself, or malware hidden in ways static byte analysis simply can't see. Treat it as one signal, not a final verdict.

Why would a legitimate PDF have JavaScript at all?

It's more common than you'd think — interactive forms use JavaScript to total up fields, validate required inputs, or format dates as you type. JavaScript by itself isn't the red flag; pairing it with an auto-run action (/OpenAction) that executes it without any user interaction is.

How does it catch code hidden with encoding tricks?

The PDF format lets you write names with hex escapes — /J#61vaScript instead of /JavaScript, for example — specifically to dodge scanners that only look for literal text. This tool decodes those escapes before searching, and it also inflates FlateDecode-compressed streams to check the content packed inside them too.

Can it read the contents of a password-protected PDF?

Not without the password. If the PDF is encrypted, the tool detects that (the /Encrypt marker) but can't read the internal content, so the analysis is incomplete — and it flags that clearly in the result.

Is my PDF uploaded to a server to be analyzed?

No. The entire analysis — reading the bytes, decoding names, inflating compressed streams, and displaying any JavaScript found — happens in your browser with local JavaScript. The file never leaves your device or gets sent to Docuboxer or anyone else.