An illustration of a typical result. No real file, name or location is used.
Before — what you would be sending
board-pack.pdfPDF
Comments and annotations11 found
Embedded JavaScriptThis PDF contains embedded JavaScript. It was detected in the file structure and has not been run.
Attached filesAnother file is packaged inside this PDF. Its presence is detected; it has not been opened or read.
After cleaning
board-pack-clean.pdfPDF
Comments and annotationsremoved
Embedded JavaScriptremoved
Attached filesremoved
Inspected as bytes, never rendered — nothing inside the document runs.
PDFs can contain more than pages
The format allows embedded JavaScript that runs when the document opens, complete files attached inside it, and actions that ask to launch an external program. All of these are legitimate features and all of them are used by attackers. Knowing they are present before you open the document is useful in itself.
Comments survive being collapsed
Annotations added during review stay in the file whether or not your viewer displays them. Forwarding a reviewed PDF often forwards the review with it.
Reading a file is not opening it
This page inspects the bytes of the document rather than rendering it, so nothing inside it executes. If the report shows embedded JavaScript in a PDF you were not expecting, that is a good reason not to open it at all.
In practice
Reading a PDF without opening it
Inspecting a document as bytes and rendering it are different operations. A checker that scans for the presence of script, attachments and launch actions never executes any of them, because it never runs the document's structure — it reads it as data. That distinction matters when the report tells you a PDF you were not expecting contains JavaScript: you now know that before your reader opens it.
What annotations survive
Comments, highlights, sticky notes and freehand markup are all annotation objects stored in the document. Whether your viewer shows them is a display setting on your machine. Flattening the document — printing it to a new PDF — converts visible annotations into ordinary page content and removes the objects, which is the only reliable way to send a reviewed document without the review.
Attachments are not obvious
A PDF can carry complete files inside it, and most viewers surface them only in a side panel that is closed by default. A document assembled from several sources can therefore be carrying a spreadsheet nobody remembers embedding. If the checker reports embedded files, look in your viewer's attachments panel before forwarding it.
Common questions
Can a PDF contain a virus?
A PDF can carry embedded JavaScript and attached files, both of which have been used to deliver malware. Inspecting the file is safer than opening it.
Does this page run the JavaScript in a PDF?
No. It reads the file as data and reports what it finds. Nothing inside the document is executed.
Are PDF comments visible to everyone?
Yes, to anyone whose viewer displays annotations, which is most of them.