Skip to main content
PPDF123

Find JavaScript Inside a PDF

Show JavaScript scans a PDF for embedded JavaScript and returns the script text as a plain-text file. It reads scripts and never runs them. If none is found, the file says so.

Drag and drop files here, or click to choose

Accepts PDF · up to 500.0 MB per file · up to 20 files at once

You can also paste a file with Ctrl/Cmd+V, or from the clipboard menu.

Show JavaScript scans a PDF for embedded JavaScript and dumps the scripts as `text/plain`. It reads the catalog's JavaScript name tree, the catalog and page additional actions (`AA`), `OpenAction`, and the actions on annotations and form fields, following action chains. It does not execute JavaScript.

If nothing is found, the body is the sentence `No JavaScript actions found`. Password-protected files are unlocked for you on this page once you enter the password; API callers run Unlock first if they cannot be parsed.

This is an inspection dump, not a sanitizer. To strip JS, use Sanitize with removeJavaScript.

Embedded file attachments are a different store; use attachment tools, not this dump.

Features

  • Plain-text dump of JS actions; no execution
  • Empty case returns a fixed sentence
  • Not Sanitize
  • Anonymous API at /api/v1/misc/show-javascript

When to use this tool

  • Inspect OpenAction before opening a file in a trusting viewer
  • Copy embedded scripts for review
  • Confirm a form has no catalog JS the walker can see

How do I check a PDF for JavaScript?

  1. Upload a PDF you are allowed to inspect.
  2. Click Process and download the text file.
  3. Search the dump for app.alert or submitForm if you are hunting malware-ish actions.
  4. Use Sanitize if you need the JS gone from a copy.

Limits and edge cases

  • Not an executor
  • Scripts in unusual objects or XFA forms can be missed
  • Not a cleaner
  • Upload limit on this website: 500 MB per file, sent in chunks above about 95 MB. A single direct API request body is capped at 100 MB.

Examples

  • A PDF with OpenAction JS downloads as a .txt of that script
  • A plain text memo downloads the no-JS sentence

Privacy for this tool

Files are uploaded over HTTPS, processed in memory or a short-lived temporary directory on our servers, and deleted when your result is ready. We do not keep copies for later browsing, training, or advertising profiles. See the Privacy Policy for retention details and AdSense cookie disclosures.

Frequently asked questions

Does this run the scripts?
No. It only copies source text out of action dictionaries.
Why did I get No JavaScript actions found?
The scan found no JS in the places it reads. Scripts in unusual objects or XFA forms can still be missed.
Is this a malware scanner?
No. It is a dump. You still have to read it.
Will this remove JS?
No. Sanitize is the removal tool.

Last updated:

Call this from code

Every tool on this site is a plain REST endpoint - no account or API key needed for anonymous use. Built for AI agents and developers as much as for browsers.

curl -X POST "https://pdf123.xyz/api/v1/misc/show-javascript" \
  -F "[email protected]" \
  -o output.pdf

Also available as an MCP tool for agent clients that speak Model Context Protocol (JSON-RPC 2.0 over POST /mcp). Full API reference

Use it from an AI agent

Skill

Claude Code, Codex, Cursor and other AI agents can run Show Javascript for you with this skill: /skills/pdf123-show-javascript.md

All agent skills

Files are used only for this processing job and deleted automatically afterward.