Why sanitize PDFs
PDFs can carry far more than pages of text. They can include JavaScript that runs when the file opens, actions that launch other programs, web links that report back when clicked, embedded file attachments and metadata that names the author, the software and the editing history. When you receive a PDF from an unknown source - or send one that was created on a company laptop - those hidden parts can be a security risk or an unintended disclosure.
The PDF Script & Link Sanitizer opens your file locally, removes /JS and /JavaScript entries, /Launch and other dangerous actions, /URI links, /EmbeddedFiles, rich media, form submission actions and document metadata, then saves a clean copy. It lists every item it removed, so you know exactly what was inside. All work happens in your browser using pdf-lib; the file is never sent to a scanning service or cloud converter.
How to use PDF Script & Link Sanitizer in 3 steps
- Drag your PDF into the drop zone. It is read into memory only.
- Choose what to strip. All options are enabled by default for maximum cleaning.
- Click "Sanitize & Download". A list of removed scripts, links, attachments and metadata fields appears with your clean copy.
Frequently asked questions
Will my links still work after sanitizing?
Web links (URI actions) are removed by default because they can be used for tracking. The text remains, but clicking will do nothing. You can switch link removal off if you want to keep them.
Does sanitizing remove hidden text or images?
No. This tool removes active content and metadata. Text and images that are visible on the page, or hidden in it, are untouched. Use the redaction tools to delete page content.
Is this an antivirus scan?
No. It does not detect malware signatures. It removes the PDF features that malware commonly abuses, such as scripts and launch actions, and that tracking uses, such as links and metadata. Treat unknown files with caution regardless.