Is PDF Editor for Chrome:Edit, Fill, Sign, Print safe?

Low risk

pdfFiller is low risk. Clicking the extension's button on a PDF sends its URL (or base64 for local files) to pdffiller.com, on any site, via an all-URLs content script. The POST hits pdffiller.com/flash/data/up.php, redirecting to their editor. Undisclosed.…

PDFfiller, Inc.v0.5.7Chrome Web Store
20Risk
Who publishes it

PDFfiller, Inc. - 1 other listing from the same operator, none carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
PDFfiller, Inc.

Same store account

1 other listing published from this account, 600k+ users between them, none of them carrying a finding.

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

PDF URLs Transmitted to pdffiller.com on Every Open

Clicking the extension's button on a PDF sends its URL (or base64 for local files) to pdffiller.com, on any site, via an all-URLs content script.

The POST hits pdffiller.com/flash/data/up.php, redirecting to their editor.

Undisclosed.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click the 'Open with pdfFiller' button injected next to a PDF link, or the toolbar icon while viewing a PDF.

The extension did this

The extension sends the PDF's URL, or, for local files, the entire base64-encoded file contents, to pdffiller.com before opening the editor.

For remote PDFs the full URL is transmitted. For local files (file:// URLs) the extension reads the file via fetch() and base64-encodes the binary content before sending it.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.pdffiller.com/flash/data/up.php
HTTP 200, JSON with result:true and a pdffiller.com editor URL
Headers
Acceptapplication/json
Content-Typeapplication/x-www-form-urlencoded;charset=UTF-8
Body
source=1&filename=testfile.pdf&pdf_url=https%3A%2F%2Fcanary-test-BIRD_12345.example.com%2Ftestfile.pdf&type=chrome.ext&out=json
03EvidenceFIELD TABLE
What the extension sends to pdffiller.com for each PDF you open:
FieldValueWhy it matters
PDF URL
https://hr.example.com/documents/salary-review-2026.pdf?token=emp-84712The full address of the PDF file you opened, including any parameters that may identify you or the context of the document.
File contents (local PDFs only)
JVBERi0xLjQKJcOkw7zDtsOfCjIgMCBvYmoK...(full file, truncated in sample only)If the PDF is on your computer (a local file), the entire file is read and uploaded as a base64-encoded binary blob.
Filename
salary-review-2026.pdfThe name of the PDF file as extracted from the URL path.
Source type
chrome.extA hardcoded identifier telling pdffiller.com the request came from the Chrome extension.
04EvidenceCODE COMPARE
The code that does this

The function that sends PDF data to pdffiller.com, from js/background.js

What it actually does
Local file read and base64 encode — annotated
// If the PDF is a local file (file:// URL), read it and base64-encode it
async function getLocalDocumentByUrl(request) {
    const { url } = request;
    const isLocalDoc = url.indexOf('file://') > -1;
    if (!isLocalDoc) return; // remote URLs skip this step

    const response = await fetch(url);          // reads the file from disk
    const buffer = await response.arrayBuffer();
    // encode the raw bytes as base64 and attach to the request object
    request.file = btoa(
        new Uint8Array(buffer).reduce(
            (data, byte) => data + String.fromCharCode(byte), ''
        )
    );
    // request.file is now the entire PDF encoded as base64
}
Upload to pdffiller.com — annotated
// Sends the PDF to pdffiller.com and returns the editor URL
function sendPdffillerAPI(request, sender, sendResponse) {
    const options = {
        source: 1,
        filename: request.filename,
        pdf_url: request.url,      // remote PDF: send the URL
        type: 'chrome.ext',
        out: 'json'
    };
    if ('file' in request) {
        // local PDF: drop the URL field, send the full base64 file contents
        delete options.pdf_url;
        options.pdf_file = request.file;
    }
    fetch('https://www.pdffiller.com/flash/data/up.php', {
        method: 'post',
        body: new URLSearchParams(options),
        headers: { 'Content-Type': 'application/x-www-form-urlencoded;charset=UTF-8' },
    })
    .then(res => res.json())
    .then(res => {
        // open the pdffiller editor in a new tab
        sendResponse(res.url + '?' + utmParams);
    });
}
05EvidenceTHIRD PARTY LIST
Where PDF data is sent:
  • www.pdffiller.com

    Receives PDF URLs and file contents. Operated by pdfFiller, the same company that publishes this extension. The extension's author email is support@pdffiller.com.

  • mozilla-apps.pdffiller.com

    Receives page URL, width, and height for HTML-to-PDF conversion when the active tab is not a PDF file.

06EvidenceARTIFACT
Reproduce it yourself

Hooks the fetch() call in the extension's service worker to log the outbound POST body before it reaches pdffiller.com, so you can see exactly what URL or file contents are transmitted when you open a PDF.

RequiresChrome with Developer mode enabledPDF Editor for Chrome extension installed
pdf-editor-intercept.js · js
// pdf-editor-intercept.js
// Paste into the DevTools console of the PDF Editor for Chrome service worker.
// DevTools → chrome://extensions → PDF Editor for Chrome → 'service worker' link.
//
// After pasting: click the extension toolbar button on any PDF page,
// or click the 'Open with pdfFiller' button injected next to a .pdf link.
// The captured POST body will be logged to this console.

(function() {
  const origFetch = self.fetch.bind(self);
  self.fetch = async function(resource, init) {
    if (typeof resource === 'string' && resource.includes('pdffiller.com')) {
      try {
        const cloned = init && init.body ? init.body.toString() : '(no body)';
        console.log('[PDF_EDITOR_INTERCEPT] Outbound POST to', resource);
        console.log('[PDF_EDITOR_INTERCEPT] Body:', cloned);
        // For URLSearchParams body:
        if (init && init.body instanceof URLSearchParams) {
          const params = {};
          for (const [k, v] of init.body.entries()) {
            params[k] = k === 'pdf_file' ? `[base64, ${v.length} chars]` : v;
          }
          console.log('[PDF_EDITOR_INTERCEPT] Parsed params:', JSON.stringify(params, null, 2));
        }
      } catch (e) {
        console.log('[PDF_EDITOR_INTERCEPT] Error reading body:', e);
      }
    }
    return origFetch(resource, init);
  };
  console.log('[PDF_EDITOR_INTERCEPT] installed. Open a PDF via the extension to capture the request.');
})();
How to run it
  1. 1
    Open chrome://extensions, enable Developer mode.
  2. 2
    Open the extension's service worker DevTools.
  3. 3
    Paste the script, press Enter.
  4. 4
    Click a PDF link or the toolbar icon on a PDF.
  5. 5
    Check [PDF_EDITOR_INTERCEPT] logs for the POST body.
SeverityLOW
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Gmail Sender Address and Subject Line Sent to pdffiller.com

Clicking a Gmail PDF attachment makes the extension read the sender's address and subject from the DOM, included in the upload to pdffiller.com.

The POST carries the base64 attachment plus type=GMAIL, from, subject.

Not disclosed.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You click the 'Open with pdfFiller' button on a PDF attachment in Gmail.

The extension did this

The extension reads the sender's address and subject from the Gmail page and includes them in the upload to pdffiller.com with the attachment's contents.

The sender address and subject line are scraped from Gmail's DOM using hardcoded CSS selectors, then sent to pdffiller.com as POST fields named 'from' and 'subject'.

02EvidenceNETWORK CAPTURE
Captured request
POSThttps://www.pdffiller.com/flash/data/up.php
HTTP 200, JSON with result:true and a pdffiller.com editor URL
Headers
Content-Typeapplication/x-www-form-urlencoded
Body
filename=canary-attachment.pdf&pdf_file=JVBERi0xLjQKJcOkw7zDtsOfCjIgMCBvYmoK...&type=GMAIL&from=canary-sender-BIRD_12345%40gmail.com&subject=Canary-subject-BIRD_12345&out=json
03EvidenceFIELD TABLE
What the extension sends to pdffiller.com when you open a Gmail PDF attachment:
FieldValueWhy it matters
PDF attachment contents
JVBERi0xLjQKJcOkw7zDtsOfCjIgMCBvYmoK... (complete base64 of attachment)The full binary content of the email attachment, base64-encoded. Whatever was attached to the email is uploaded to pdffiller.com.
Sender email address
hr-team@example-corp.comThe email address of the person who sent you the message containing the PDF attachment.
Email subject line
Q1 2026 Performance Review — ConfidentialThe subject of the email the attachment was part of. This can reveal the context and sensitivity of the document.
Filename
performance-review-q1-2026.pdfThe filename of the PDF attachment.
Source type
GMAILA hardcoded label telling pdffiller.com the upload originated from Gmail via the extension.
04EvidenceCODE COMPARE
The code that does this

Code scraping Gmail metadata to pdffiller.com, from inject.js and background.js

What it actually does
Gmail click handler and DOM scraping — annotated
// Fires when the user clicks the pdfFiller button on a Gmail attachment
$(document).on('click', '.pdffiller-link', function() {
    // locate the attachment container element in Gmail's DOM
    var attachment = $(this).parents('.aZo.N5jrZb');
    var file = attachment.attr('download_url').split(':');
    var name = decodeURI(file[1]);   // the attachment filename
    var url  = file[2] + ':' + file[3]; // the download URL
    getFile(url, name, 'GMAIL');     // type='GMAIL' triggers the metadata scrape
});

function getFile(url, filename, type) {
    // ask the service worker to fetch the file bytes
    chrome.runtime.sendMessage({ contentScriptQuery: 'getGmailFile', url }, file => {
        if (type === 'GMAIL') {
            // scrape sender email from Gmail's DOM
            var from    = $('.iv .gD').attr('email');  // sender address attribute
            var subject = $('.nH .ha .hP').html();    // email subject line
            // send file + metadata to service worker for upload
            sendToPdffillerGmailApi(file, filename, from, subject);
        }
    });
}
Service worker upload — annotated
// Uploads the attachment and email metadata to pdffiller.com
function sendPdffillerGmailAPI(request, sender, sendResponse) {
    $.post('https://www.pdffiller.com/flash/data/up.php', {
        filename: request.filename,
        pdf_file: request.file,    // base64-encoded attachment contents
        type:     'GMAIL',         // identifies this as a Gmail attachment upload
        from:     request.from,    // sender's email address (scraped from DOM)
        subject:  request.subject, // email subject line (scraped from DOM)
        out:      'json'
    }, function(json) {
        if (json.result) {
            // open the pdffiller editor for the uploaded attachment
            sendResponse(json.url);
        }
    }, 'json');
}
05EvidenceTHIRD PARTY LIST
Where your Gmail attachment data is sent:
  • www.pdffiller.com

    Receives the attachment's contents (base64), sender address, and subject. Operated by pdfFiller, Inc., publisher of this extension.

What it can do

Permissions this extension asks for, as declared in version 0.5.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 0.5.7, which we have not unpacked yet.

  • Read and change your data on every site you visit

    *://*/*

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

  • Act on the current tab, but only after you click the extension

    activeTab

  • Watch every request your browser makes

    webRequest

  • See every page you navigate to, as you navigate to it

    webNavigation

  • Run its own code inside the pages you visit

    scripting

Updated 30 September 2026gphandlahdpffmccakmbngmbjnjiiahp