Docuboxer

Sanitize PDF

Remove JavaScript, auto-actions, attachments and hidden metadata from a PDF.

100% local — your files are never uploaded to any serverNo signupFree

How do I remove JavaScript and hidden data from a PDF?

To remove JavaScript and hidden data from a PDF, drop it here, choose what to strip and download the sanitized copy. The tool always deletes embedded JavaScript, actions that run on open (/OpenAction, /AA), program launches (/Launch), actions that submit or import data, 3D model scripts, media actions, links to network shares (which leak your Windows credentials hash) and XFA forms. If you tick the options, it also removes attachments, metadata (author, title, producer app and the XMP packet), external links, and flattens form fields. It scans the file before and after with the same engine as /pdf-scan, so you can check that no high-risk markers are left, and your pages and text stay intact. It's a lightweight content disarm (CDR) for PDFs that runs entirely in your browser: nothing is uploaded, it's free and there's no signup. One honest limit: it doesn't rewrite fonts or images, so it can't promise to neutralize an exploit hidden inside them.

How to use Sanitize PDF

  1. Drop the PDF onto the upload area or click to choose it. It's scanned right away, so you see which markers it carries: JavaScript, auto-run actions, attachments, links.
  2. Pick what else to remove. Active content always goes. Attachments and metadata are ticked by default, while external links and form flattening are opt-in.
  3. Click “Sanitize PDF”. The tool cleans the document and scans the result again.
  4. Check the before/after table, which shows how many times each marker appeared in the original and in the sanitized copy.
  5. Download the sanitized PDF. For a full breakdown of the result, open it in /pdf-scan, or review what metadata is left in /pdf-metadata.

Common use cases

Disarming email attachments before anyone opens them

A PDF “invoice” from an unknown sender can fire JavaScript the moment it opens. Strip the scripts and auto-run actions first so nothing executes, then read it.

Publishing a report without leaking who made it

Remove the author name, the software that exported it, internal timestamps and the XMP packet before a document goes on your website or into a public records request.

Sharing a PDF that had files bundled inside

Some PDFs carry spreadsheets, drafts or source files as attachments you can't see on the page. Sanitizing removes the attachment tree and the paperclip annotations so only the visible document is shared.

Archiving a completed form

Flatten the fields so the answers can't be changed, and drop validation scripts and auto-submit actions. The form becomes a static record you can store or attach to a case file.

Meeting a “no active content” upload policy

Document portals and security teams often reject PDFs with JavaScript or embedded files. Sanitize them locally, without sending sensitive files to a cloud CDR service, and keep the before/after table as proof.

Frequently asked questions

How do I remove JavaScript from a PDF file?

You need to delete every /JavaScript action, the /JS entries that hold the code and the document-level /Names /JavaScript tree, plus the triggers that run them (/OpenAction and /AA). Less obvious places count too: 3D models carry their own script (/OnInstantiate) that runs when the model is activated. This tool does that across the whole file, including code hidden in compressed object streams. It then garbage-collects orphaned objects so the script isn't still sitting in the file.

Is a sanitized PDF guaranteed to be safe?

No, and be wary of any tool that says so. Sanitizing removes the PDF format's active content: JavaScript, auto-run actions, program launches, data submission and XFA. It doesn't rebuild fonts or images, which have had their own vulnerabilities. For a highly suspicious file, also open it in an up-to-date reader with JavaScript turned off.

Will sanitizing a PDF remove any text or pages?

No. Page content (text, images, vector graphics) isn't touched. Only action dictionaries, attachments and metadata are removed. If you choose to flatten forms, fields become fixed content that looks the same, and internal links such as a table of contents keep working.

Is my PDF uploaded anywhere?

No. Scanning and cleaning run in your own browser, and the file never leaves your device. That makes it suitable for contracts, payslips or medical records you shouldn't hand to an online converter.

What's the difference between sanitizing and flattening a PDF?

Flattening only turns form fields (and sometimes annotations) into static content. Sanitizing removes active and hidden content: scripts, actions, attachments, metadata and, optionally, links. It can also flatten forms in the same pass if you tick that option.

Can I sanitize a password-protected PDF?

Not directly, because an encrypted PDF can't be modified without corrupting it. Remove the protection first in /unlock (you'll need the password or permission), then sanitize the unlocked copy here.