Extract and display any JavaScript embedded in a PDF so you can read it. PDF is a format that can carry executable script, which most people do not expect, and that capability has a long history as a malware vector. This tool lets you see exactly what a document would run before you open it in a reader that might actually run it.
Not necessarily - interactive forms legitimately use it for validation and calculated fields. What matters is what the code does. Script that reaches out to a URL, writes files or obfuscates itself deserves suspicion.
Use Sanitise PDF, which strips JavaScript along with embedded files and other active content.
No. The script is read out of the document as text and reported to you; it is not executed.
Files are uploaded over an encrypted connection and processed on CoonTool's own server, not in your browser. The working copy is deleted automatically once the job is done, and in any case within 24 hours. Nothing is stored permanently and no account is required.