Is PDF Editor for Chrome:Edit, Fill, Sign, Print safe?
pdfFiller is low risk. Clicking the extension's button on a PDF sends its URL (or base64 for local files) to pdffiller.com, on any site, via an all-URLs content script. The POST hits pdffiller.com/flash/data/up.php, redirecting to their editor. Undisclosed.…
Who publishes itPDFfiller, Inc. - 1 other listing from the same operator, none carrying a finding
PDFfiller, Inc. - 1 other listing from the same operator, none carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
1 other listing published from this account, 600k+ users between them, none of them carrying a finding.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
PDF URLs Transmitted to pdffiller.com on Every Open
Clicking the extension's button on a PDF sends its URL (or base64 for local files) to pdffiller.com, on any site, via an all-URLs content script.
The POST hits pdffiller.com/flash/data/up.php, redirecting to their editor.
Undisclosed.
You click the 'Open with pdfFiller' button injected next to a PDF link, or the toolbar icon while viewing a PDF.
The extension sends the PDF's URL, or, for local files, the entire base64-encoded file contents, to pdffiller.com before opening the editor.
For remote PDFs the full URL is transmitted. For local files (file:// URLs) the extension reads the file via fetch() and base64-encodes the binary content before sending it.
| Accept | application/json |
| Content-Type | application/x-www-form-urlencoded;charset=UTF-8 |
source=1&filename=testfile.pdf&pdf_url=https%3A%2F%2Fcanary-test-BIRD_12345.example.com%2Ftestfile.pdf&type=chrome.ext&out=json
| Field | Value | Why it matters | |
|---|---|---|---|
PDF URL | https://hr.example.com/documents/salary-review-2026.pdf?token=emp-84712 | The full address of the PDF file you opened, including any parameters that may identify you or the context of the document. | |
File contents (local PDFs only) | JVBERi0xLjQKJcOkw7zDtsOfCjIgMCBvYmoK...(full file, truncated in sample only) | If the PDF is on your computer (a local file), the entire file is read and uploaded as a base64-encoded binary blob. | |
Filename | salary-review-2026.pdf | The name of the PDF file as extracted from the URL path. | |
Source type | chrome.ext | A hardcoded identifier telling pdffiller.com the request came from the Chrome extension. |
The function that sends PDF data to pdffiller.com, from js/background.js
// If the PDF is a local file (file:// URL), read it and base64-encode it
async function getLocalDocumentByUrl(request) {
const { url } = request;
const isLocalDoc = url.indexOf('file://') > -1;
if (!isLocalDoc) return; // remote URLs skip this step
const response = await fetch(url); // reads the file from disk
const buffer = await response.arrayBuffer();
// encode the raw bytes as base64 and attach to the request object
request.file = btoa(
new Uint8Array(buffer).reduce(
(data, byte) => data + String.fromCharCode(byte), ''
)
);
// request.file is now the entire PDF encoded as base64
}// Sends the PDF to pdffiller.com and returns the editor URL
function sendPdffillerAPI(request, sender, sendResponse) {
const options = {
source: 1,
filename: request.filename,
pdf_url: request.url, // remote PDF: send the URL
type: 'chrome.ext',
out: 'json'
};
if ('file' in request) {
// local PDF: drop the URL field, send the full base64 file contents
delete options.pdf_url;
options.pdf_file = request.file;
}
fetch('https://www.pdffiller.com/flash/data/up.php', {
method: 'post',
body: new URLSearchParams(options),
headers: { 'Content-Type': 'application/x-www-form-urlencoded;charset=UTF-8' },
})
.then(res => res.json())
.then(res => {
// open the pdffiller editor in a new tab
sendResponse(res.url + '?' + utmParams);
});
}- www.pdffiller.com
Receives PDF URLs and file contents. Operated by pdfFiller, the same company that publishes this extension. The extension's author email is support@pdffiller.com.
- mozilla-apps.pdffiller.com
Receives page URL, width, and height for HTML-to-PDF conversion when the active tab is not a PDF file.
Hooks the fetch() call in the extension's service worker to log the outbound POST body before it reaches pdffiller.com, so you can see exactly what URL or file contents are transmitted when you open a PDF.
// pdf-editor-intercept.js
// Paste into the DevTools console of the PDF Editor for Chrome service worker.
// DevTools → chrome://extensions → PDF Editor for Chrome → 'service worker' link.
//
// After pasting: click the extension toolbar button on any PDF page,
// or click the 'Open with pdfFiller' button injected next to a .pdf link.
// The captured POST body will be logged to this console.
(function() {
const origFetch = self.fetch.bind(self);
self.fetch = async function(resource, init) {
if (typeof resource === 'string' && resource.includes('pdffiller.com')) {
try {
const cloned = init && init.body ? init.body.toString() : '(no body)';
console.log('[PDF_EDITOR_INTERCEPT] Outbound POST to', resource);
console.log('[PDF_EDITOR_INTERCEPT] Body:', cloned);
// For URLSearchParams body:
if (init && init.body instanceof URLSearchParams) {
const params = {};
for (const [k, v] of init.body.entries()) {
params[k] = k === 'pdf_file' ? `[base64, ${v.length} chars]` : v;
}
console.log('[PDF_EDITOR_INTERCEPT] Parsed params:', JSON.stringify(params, null, 2));
}
} catch (e) {
console.log('[PDF_EDITOR_INTERCEPT] Error reading body:', e);
}
}
return origFetch(resource, init);
};
console.log('[PDF_EDITOR_INTERCEPT] installed. Open a PDF via the extension to capture the request.');
})();
- 1Open chrome://extensions, enable Developer mode.
- 2Open the extension's service worker DevTools.
- 3Paste the script, press Enter.
- 4Click a PDF link or the toolbar icon on a PDF.
- 5Check [PDF_EDITOR_INTERCEPT] logs for the POST body.
Gmail Sender Address and Subject Line Sent to pdffiller.com
Clicking a Gmail PDF attachment makes the extension read the sender's address and subject from the DOM, included in the upload to pdffiller.com.
The POST carries the base64 attachment plus type=GMAIL, from, subject.
Not disclosed.
You click the 'Open with pdfFiller' button on a PDF attachment in Gmail.
The extension reads the sender's address and subject from the Gmail page and includes them in the upload to pdffiller.com with the attachment's contents.
The sender address and subject line are scraped from Gmail's DOM using hardcoded CSS selectors, then sent to pdffiller.com as POST fields named 'from' and 'subject'.
| Content-Type | application/x-www-form-urlencoded |
filename=canary-attachment.pdf&pdf_file=JVBERi0xLjQKJcOkw7zDtsOfCjIgMCBvYmoK...&type=GMAIL&from=canary-sender-BIRD_12345%40gmail.com&subject=Canary-subject-BIRD_12345&out=json
| Field | Value | Why it matters | |
|---|---|---|---|
PDF attachment contents | JVBERi0xLjQKJcOkw7zDtsOfCjIgMCBvYmoK... (complete base64 of attachment) | The full binary content of the email attachment, base64-encoded. Whatever was attached to the email is uploaded to pdffiller.com. | |
Sender email address | hr-team@example-corp.com | The email address of the person who sent you the message containing the PDF attachment. | |
Email subject line | Q1 2026 Performance Review — Confidential | The subject of the email the attachment was part of. This can reveal the context and sensitivity of the document. | |
Filename | performance-review-q1-2026.pdf | The filename of the PDF attachment. | |
Source type | GMAIL | A hardcoded label telling pdffiller.com the upload originated from Gmail via the extension. |
Code scraping Gmail metadata to pdffiller.com, from inject.js and background.js
// Fires when the user clicks the pdfFiller button on a Gmail attachment
$(document).on('click', '.pdffiller-link', function() {
// locate the attachment container element in Gmail's DOM
var attachment = $(this).parents('.aZo.N5jrZb');
var file = attachment.attr('download_url').split(':');
var name = decodeURI(file[1]); // the attachment filename
var url = file[2] + ':' + file[3]; // the download URL
getFile(url, name, 'GMAIL'); // type='GMAIL' triggers the metadata scrape
});
function getFile(url, filename, type) {
// ask the service worker to fetch the file bytes
chrome.runtime.sendMessage({ contentScriptQuery: 'getGmailFile', url }, file => {
if (type === 'GMAIL') {
// scrape sender email from Gmail's DOM
var from = $('.iv .gD').attr('email'); // sender address attribute
var subject = $('.nH .ha .hP').html(); // email subject line
// send file + metadata to service worker for upload
sendToPdffillerGmailApi(file, filename, from, subject);
}
});
}// Uploads the attachment and email metadata to pdffiller.com
function sendPdffillerGmailAPI(request, sender, sendResponse) {
$.post('https://www.pdffiller.com/flash/data/up.php', {
filename: request.filename,
pdf_file: request.file, // base64-encoded attachment contents
type: 'GMAIL', // identifies this as a Gmail attachment upload
from: request.from, // sender's email address (scraped from DOM)
subject: request.subject, // email subject line (scraped from DOM)
out: 'json'
}, function(json) {
if (json.result) {
// open the pdffiller editor for the uploaded attachment
sendResponse(json.url);
}
}, 'json');
}- www.pdffiller.com
Receives the attachment's contents (base64), sender address, and subject. Operated by pdfFiller, Inc., publisher of this extension.
What it can do
Permissions this extension asks for, as declared in version 0.5.5. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to. The current listed version is 0.5.7, which we have not unpacked yet.
Read and change your data on every site you visit
*://*/*
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Act on the current tab, but only after you click the extension
activeTab
Watch every request your browser makes
webRequest
See every page you navigate to, as you navigate to it
webNavigation
Run its own code inside the pages you visit
scripting