Skip to content
PDFlora

Clean hidden extras out of a PDF before sharing

A PDF can hold more than the pages show: scripts, attached files, automatic actions and document properties. Sanitizing removes them in one pass and tells you exactly what it found.

In your browser
Loading the tool…

How it works

  1. Step 1: Choose or drop the PDF you want to clean.

  2. Step 2: Tick the extra option if you also want annotations and comments removed.

  3. Step 3: Select Sanitize PDF and read the report.

  4. Step 4: Download the cleaned copy.

What sanitizing removes

Sanitizing goes through the parts of a PDF that are not page content and clears them: the document properties and the XMP metadata stream, any embedded JavaScript, any file attachments, and open actions, which are instructions that run when the file is opened. You can also choose to remove annotations and comments.

When it finishes, the tool shows a report listing what was removed and how many of each item, so you are not left guessing whether anything was there. The visible pages are left as they were.

Why use this tool

A report, not a guess

You see what was found and removed, so you can confirm that a suspicious file really had a script or an attachment.

Several clean-ups at once

Metadata, scripts, attachments and open actions are handled together instead of in four separate tools.

Stays on your device

The file is inspected and rewritten in your browser, so a confidential document is not uploaded to be cleaned.

Pages unchanged

Visible content is not re-rendered, so text stays selectable and images keep their quality.

Common uses

  • A PDF from an unknown sender

    Before forwarding a file you did not create, strip anything that can run or ride along inside it, such as scripts and attached files.

  • Sending a contract to a counterparty

    Your law firm's document may carry an author name, comments from earlier drafts and an attached spreadsheet. Remove them before it leaves the building.

  • Publishing a report on a website

    An annual report exported from several tools may keep internal properties and attachments. Sanitize it so the download only holds the pages.

  • Compliance hand-overs

    A regulator or auditor asks for a clean copy. The report gives you a record of what you took out.

What the risky extras are, and why they exist

Embedded JavaScript is used legitimately for calculations in forms, but it is also the part of a PDF that malicious files often abuse. An open action is an instruction saying what should happen the moment a viewer opens the file, such as jumping to a page or running a script. File attachments are whole files, like spreadsheets or images, carried inside the PDF, and they are easy to forget about.

Removing them does not make the visible document any different. It shrinks what the file can do and what it can leak, which is why it is a sensible step before you send a file to someone you do not know well.

  • Scripts and open actions: removed so the file does nothing on its own.
  • Attachments: removed so nothing else is packed inside.
  • Metadata: cleared so author, software and dates do not travel with it.

Supported formats

Input
One PDF file (.pdf).
Output
One cleaned PDF file, plus an on-screen report of what was removed.

Encrypted PDFs must be unlocked first with Unlock PDF.

Good to know

  • Sanitizing does not remove anything that is part of the visible page, such as text, images, or text hidden inside a page. To remove that for real, use Redact PDF.
  • Annotation and comment removal is an option, not the default, so tick it if you want comments gone.
  • It cannot promise that a file is safe. It removes the listed elements, but it is not an antivirus scan.
  • Form field data and digital signatures are not the target of this tool; a signed file will no longer match its original signature once it has been rewritten.

Your files never leave your browser

This tool runs entirely on your device using your browser. Your files are not uploaded to our servers and are not stored anywhere. Closing the tab discards everything.

Frequently asked questions

What exactly does Sanitize PDF remove?

It removes document metadata (properties and XMP), embedded JavaScript, file attachments and open actions, and optionally annotations and comments. A report on screen lists what was found and removed.

Does sanitizing make a PDF virus-free?

Not as a guarantee. It removes scripts, attachments and automatic actions, which are the usual carriers, but it is not an antivirus scan. Keep your normal security software up to date.

Will it remove text I have hidden or covered on a page?

No. Text that is part of a page, including text under a white box, stays in the file. Use Redact PDF to remove that content permanently.

Is my document uploaded to be sanitized?

No. The file is analysed and rewritten inside your browser and is not sent to a server.

How is this different from Remove PDF Metadata?

Remove PDF Metadata clears only the document properties and XMP. Sanitize PDF does that too and also removes scripts, attachments and open actions, with an optional pass over comments.

Next stepContinue with Remove PDF MetadataClear author, title, dates and software details hidden in a PDF's properties.