Free PDF Forensics & Metadata Viewer
See who made a PDF, with what software, and how many times it was re-saved. This free PDF metadata viewer reads it all in your browser — the file never leaves your device.
0 bytes leave your browser · no account · no watermark
Every point below is attributable to one finding. Nothing is hidden in the number.
How this file was saved
A PDF is written once and then appended to. Each %%EOF marker after the first is a revision that is still physically inside the file — the earlier version has not been removed, only superseded.
The evidence
Each panel names the part of the PDF it was read from, so anything here can be checked independently.
Take the report with you
Everything above stays free and on screen. Get it as a dated PDF report you can attach to a case file, plus batch checking for more than one document at a time.
Report ready
Your report has been generated in this browser. Use the button below if the download did not start.
What gets checked
Nine things a PDF admits about itself
A document verification team does not start with the pixels. It starts with the structure — because the structure is written by software, not by the person trying to pass the document off.
Info dictionary
Author, creator and producer
The name of the person and the software that wrote the file. A payslip whose producer is an image editor is worth a second look.
XMP packet
The second copy of the metadata
PDFs store their dates twice. Editors update both; a hand-edited file often updates only one, and the two stop agreeing.
Trailer · xref
Incremental saves
How many times the file was re-saved after it was first written, counted from the end-of-file markers the writer left behind.
xmpMM:History
The edit trail
Some software records each save inside the file — which program, which action, at what time. When it is there, it is the clearest history you will get.
FontDescriptor
Fonts and how they travel
Which typefaces are carried inside the file and which are borrowed from your reader. One family arriving by both routes suggests text from two sources.
Page tree
Text layer or picture
Whether each page holds real selectable text or a photograph of a page. It decides which checks even apply.
Catalog · AcroForm
Signatures and form fields
Whether the document carries a digital signature — the one thing that makes post-signing changes provable rather than arguable.
Names tree
Active content
Embedded JavaScript, launch actions and attached files. Ordinary documents do not need any of them.
SHA-256
A fingerprint of the exact bytes
Computed in your browser so you can prove later that the file you examined is the same file you were sent.
Reading the result
A high score is a reason to look, not a verdict
Structural forensics tells you how a file was produced and handled. It cannot tell you whether the salary printed on it is the real one. A scanned certificate that was cropped in Photoshop and a scanned certificate that was forged in Photoshop look identical at this level — which is exactly why the tool shows you the evidence and its weight instead of a yes or no.
Two things worth knowing before you act on a result. Ordinary business documents are re-saved all the time, so one incremental save on its own proves very little. And metadata can simply be removed: a file with no dates and no producer is not clean, it is quiet, which is why missing metadata counts towards the score rather than away from it.
Questions
PDF metadata, answered
Is my document uploaded anywhere?
No. The PDF is read by JavaScript running in your own browser tab and is never transmitted. You can confirm it: open your browser's network panel, run a file, and you will see no request carrying it. Closing the tab discards everything.
How do I know if a PDF has been edited?
The strongest structural signal is an incremental save: a revision appended after the original, which leaves an extra end-of-file marker inside the file. Alongside it, look for a modification date later than the creation date, an XMP packet that disagrees with the document metadata, and a producer that names image-editing software. This tool reports all four with the weight each one carries.
What does the producer field actually mean?
Producer names the software that wrote the PDF file; creator names the application the content came from. A Word document printed to PDF shows Word as creator and a PDF engine as producer. When either names an image editor on a document that should have been scanned or exported, the content was handled as a picture at some point.
Can metadata be faked?
Yes, and that is the honest limit of any metadata viewer. Dates and producer strings can be rewritten with freely available tools. What is far harder to remove cleanly is the structural record — the appended revisions, the mismatched font sources, the leftover objects. That is why the score weights structure more heavily than strings.
Does this work on scanned documents?
It reads the metadata and structure of a scan just as it does any other PDF, and it will tell you that the pages carry no text layer. But tampering inside a scanned image is a pixel-level question — cloning, splicing, resampling — which structural analysis cannot see. For that, use the Document Tampering Checker.
Checking one file, or every file?
One document at a time is a habit, not a control
This page inspects a single PDF because you chose to look. DocuExprt checks every document as it arrives — extracts the data, verifies it against 20+ government databases, flags the ones that need a human, and keeps a record of what was checked and why.
Reading one file, or screening an intake?
Metadata tells you how a file was made. It cannot tell you the claim on it is true.
This page reads the structure of a single PDF. DocuExprt reads the content of every document that arrives, checks the details against the issuing source, and escalates only the ones that do not reconcile.