PDF inFOOT

A best-effort, plain-English read on a PDF's history — what likely made it, whether its metadata looks consistent, and roughly how old it really is.

1. Choose a PDF to inspect

One file per inquiry. Nothing about your file is uploaded — only a short summary of its metadata fields is sent off for the write-up below.

🔎📄

Drop your PDF here or click to browse

Quick verdict

Best-effort, based only on what's stored inside the file — not a forensic certainty. A plain copy or move in the file system leaves no trace here; only saves made through PDF software show up as edit history.

History report

See the raw metadata this was based on

Recover a folder's history from Thumbs.db

A separate, best-effort tool. Windows sometimes leaves a hidden Thumbs.db file behind in a folder — it can retain filenames and thumbnail previews of files that were once there, even after they were deleted or renamed.

Choose a Thumbs.db file

This is a different file than your PDF — it's a hidden file Windows creates named exactly "Thumbs.db", usually found in the same folder as the files it's caching. Nothing is uploaded; everything is read in your browser.

🗂️🖼️

Drop a Thumbs.db file here or click to browse

Thumbs.db findings

Honest limits: Thumbs.db's format is old, undocumented by Microsoft, and varies by Windows version. This tool handles the classic per-folder format (Windows XP through 8.1-era network shares) with reasonable confidence, verified against a hand-built test file — but some thumbnails use an older raw format this tool can't render, and newer per-folder files sometimes skip the filename index entirely, in which case only thumbnail images (no names) can be recovered. A corrupted or unsupported file will fail gracefully with a message rather than showing wrong data.

What PDF inFOOT looks for

inFOOT is a forensic inspection tool for PDFs — it surfaces the metadata, embedded scripts, hidden hyperlinks, internal file paths, document tracking IDs, and structural history that a normal PDF viewer never shows you. It's built for people who need to know where a file has actually been and what it might reveal about its author or origin: journalists checking a leaked document, researchers verifying provenance, or anyone who wants to know what's really inside a PDF before sharing it further.

Everything runs client-side against the file you provide. Two features are opt-in and click-to-run: an AI-written narrative summary of the findings (sends only extracted metadata field values, never your file), and per-link Wayback Machine / Google dork lookups (sends only the single URL you explicitly click).

Frequently asked questions

Want the longer version? Read our full guide: How to Check If a PDF Has Been Edited or Tampered With.

What can inFOOT detect that a normal PDF viewer can't?

Embedded JavaScript and launch actions, annotation-based hyperlinks, internal file system paths left in the document, XMP document/instance tracking IDs, and full metadata history — none of which are shown in a typical PDF reader's interface.

Is my PDF ever uploaded?

No. All parsing and forensic analysis happens directly in your browser. Only if you opt into the AI narrative summary are extracted metadata values (not the file) sent externally.

What are the Wayback Machine and Google dork buttons?

Click-to-run conveniences for a link found in the document — nothing is looked up automatically. Clicking "Check Wayback Machine" sends only that single URL to archive.org; the Google dork buttons just open a pre-built search in a new tab.

Can inFOOT recover deleted or hidden information?

It surfaces information that's technically still present in the file but not shown by normal viewers — like leftover metadata, tracking IDs, or embedded paths — rather than recovering data that's been genuinely removed.

Does inFOOT modify my file?

No, inFOOT is read-only. It analyzes and reports; it never writes or downloads a modified version of your PDF.