Tiny Online Tools logoTiny Online ToolssearchSearch tools…grid_viewAll Tools
Homechevron_rightPDF Toolschevron_rightPDF Hidden Data InspectorPDF Hidden Data Inspector

PDF Hidden Data Inspector

Reveal what a PDF carries but does not show: metadata, hidden layers, attachments, JavaScript, invisible text and text under redaction boxes.

upload_file

Click to browse or drag & drop files here

Select a PDF to inspect

Accepted: .pdf,application/pdf

Similar Tools

PDF Metadata Cleaner

PDF Metadata Cleaner

Strip author, software, timestamps, XMP and other hidden data from a PDF, then see proof that each value is really gone.

PDF JavaScript Inspector

PDF JavaScript Inspector

Find every script inside a PDF — document actions, page and annotation events, and form-field calculations — and read it without running it.

PDF Font Inspector

PDF Font Inspector

List every font in a PDF with its subset tag, subtype, embedding status and the pages that actually use it.

PDF Link Extractor

PDF Link Extractor

List every link in a PDF — external, internal, mailto, and the bare URLs in the text that carry no annotation — with pages, anchor text and risk flags.

Image Flip Tool

Image Flip Tool

Flip images horizontally, vertically, or both directions.

Video Rotate Tool

Video Rotate Tool

Video Rotate Tool helps you fix sideways footage and correct orientation directly in your browser. Use it for fast, private media cleanup, publishing, lessons, demos, and everyday video or audio editing.

3D Web Optimizer

3D Web Optimizer

Optimize a 3D model for the web against a real performance budget, free and entirely in your browser.

apps

More Tools

Browse our full collection of free online tools.

What a PDF hides

A PDF is a container, not a picture. A great deal can travel inside one without ever appearing on screen, and most of it survives being emailed, printed to PDF, or uploaded to a portal.

Metadata. The Info dictionary holds the author name, the authoring application and the creation timestamp. The XMP packet often holds a second, older copy — including fields the Info dictionary no longer has, such as the original document ID that links this file to the one it was derived from.

Layers. Optional content groups can be switched off in the default configuration. The content is still there; a reader that ignores the configuration, or a user who opens the layers panel, sees it.

JavaScript. Document-level scripts, open actions, page actions, annotation actions and form-field calculate/validate scripts. This tool lists every one and never runs any of them.

Invisible text. Rendering mode 3 draws nothing but stays selectable and searchable — normal for an OCR layer, and equally normal for text someone wanted out of sight.

Content off the page. Anything painted outside the crop box is trimmed away by the viewer but still in the file, and it comes straight back when the crop box is removed.

The redaction check

The single most consequential failure in real documents: drawing a black rectangle over a name and saving. The rectangle covers nothing — the text underneath is still in the content stream and copies out with two clicks.

This tool looks for filled dark rectangles and reports any text whose box falls entirely inside one, shows you the text, and draws the rectangle on the page preview. If you see a finding here, the file is not redacted.

What it cannot see

Streams it cannot decode are not searched, and encrypted documents are reported as a limit rather than quietly skipped. A clean report means these checks found nothing — it is not a certificate that the file is safe to publish.

Privacy

Everything is parsed in your browser. The file is never uploaded, which is the only sensible way to inspect a document you are worried about.