DocSupra › Integrity Scanner › Is this PDF safe to open?
DocSupra · Integrity Scanner
Safe to open?
Scripts, launch actions, executable attachments and hidden payloads, read without opening the file in a viewer.
How to check whether a PDF or image is safe to open.
The short answer. Drop the file into the Integrity Scanner before you open it. The card answers Safe to open? with Yes, Caution or No and the reason: JavaScript, actions that run when the file opens, executable attachments, forms that send what you type somewhere, links to raw IP addresses, an encrypted structure, or a file or code hidden inside an image. This answer is shown to everyone, before any payment.
A document can do things. A PDF can carry a script, start an action the moment it opens, hold another file inside it or send what you type in a form to an address you never see. An image can have a second file appended behind its last pixel. The scanner reads the structure of the file in your browser, without running any of it, and tells you what is there.
What it looks for
Scripts embedded in a PDF, whether attached to the document, a page or a form field.
Instructions that run when the file opens or a page is shown, including commands that start another program.
Files embedded inside the PDF, with executable types called out.
Forms set up to send what you type to a web address.
Links that point to a bare IP address instead of a named site.
A ZIP or a PDF stuffed behind the end of a JPEG, code inside an image comment, and encrypted PDFs whose content cannot be read.
How to check a file
Do not open it yet
Save the attachment without opening it.
Open the Integrity Scanner
Go to docsupra.com/?abre=scanner and drop the file, or a whole folder or ZIP.
Read Safe to open?
Yes means no scripts, executables or hidden payloads were found. Caution and No come with the finding that caused them.
Decide
If the answer is not Yes, ask the sender what the file is and do not allow anything a viewer asks to run.
What it is not
It is not antivirus software. It does not match a file against known malware and it cannot detect an attack hidden in deliberately malformed data. It tells you whether the file carries the things that let a document act: code, automatic actions, attachments, forms that submit, raw links, encryption. Use it alongside your security software, not instead of it.
What the Integrity Scanner costs
From one lease to a whole department: pay once for a few checks, or subscribe.
Document downloads are not part of this subscription: repairing and exporting documents is the Compliance Studio. Prices are in USD and exclude any tax that applies in your country; Stripe calculates it and shows it before you pay.
Check a file now →Questions
Can a PDF contain a virus?
A PDF can carry JavaScript, actions that run on opening and embedded files, and those are the usual ways a malicious PDF works. The scanner reports whether a file carries them. It is not antivirus software and does not identify specific malware.
Do I have to pay to see the security answer?
No. Whether a file carries JavaScript, actions that run on opening, executable attachments, a hidden file or code inside an image, or an encrypted structure is shown to everyone, with the detail.
Does the scanner run the file?
No. It reads the bytes and the structure of the file in the browser. It does not execute the file’s scripts or open its attachments.
Is the file uploaded?
No. The file is read on your own device, inside the browser. There is no upload endpoint, no server copy and no retention period; you can disconnect from the internet and it keeps working.
What does the rest cost?
Where the file came from and whether it is safe to open are shown to everyone. Whether it was edited, how, and what it exposes comes with a check: 3 checks with the $9.99 pack, 50 with the $19.99 pass, or up to 1,000 files a month with the $14.99 subscription. It is included with Professional Team and Corporate Studio.
More on DocSupra
Made and copyrighted © 2026 by Soelys Muñoz. DocSupra™ is her trademark. All rights reserved. How to recognise the real site.