What is cleanthis.io?

A free online tool that scans your file for malware, removes hidden macros & scripts, and strips tracking metadata. The tool enables you to choose your sanitization mode depending on your needs and your threat model.

How it works

Three steps. No accounts, no tracking.

01

Upload or paste a link

Drop a file up to 50 MB or paste a URL from Drive, Dropbox, GitHub. No sign-up.

02

Pick a sanitization level

Light just strips metadata. Standard runs full CDR. Aggressive converts to safest format.

03

Download the clean file

Get back the original format with macros, scripts, EXIF and threats removed. View a full report.

Sanitization modes

Pick the level that fits the job.

Light sanitization mode illustration Standard sanitization mode illustration Aggressive sanitization mode illustration
Light

For files you mostly trust.

A virus scan and a clean wipe of hidden metadata. No re-encoding, no structural changes — your file comes back almost identical to what you uploaded, just without EXIF, GPS coordinates, author info, timestamps, or other metadata leakage.

  • Removes EXIF, GPS, author info, timestamps, embedded tracking metadata
  • Keeps format, fidelity, fonts, layout, full editability
  • Best for photos before sharing, documents from a trusted source, quick metadata audits
Standard · default

Trust nothing. Keep the format.

Full Content Disarm & Reconstruction. Macros, scripts, embedded objects and metadata are stripped; the file is re-encoded and rebuilt from safe content only. You get the same format back, minus the threats — without converting your .docx into something else.

  • Removes macros, scripts, embedded objects, OLE, metadata, hidden code paths, steganographic payloads
  • Keeps original format, visible content, basic editability
  • Best for the everyday case — anything from an unknown source you still want to open in its native app
Aggressive

Maximum safety. Editability takes a back seat.

Standard sanitization, then the file is converted to its safest counterpart — Office to PDF, images to PNG, HTML to plain text, video to MP4. The result is harder to weaponise, but you lose the original format and most of its editability.

  • Removes everything Standard removes, plus format-level complexity
  • Converts Office → PDF, images → PNG, SVG → PNG, HTML → TXT, EPUB → PDF, audio → WAV, video → MP4
  • Best for high-risk attachments, files headed into a sensitive environment, or where you only need the visible content
How we detect threats

Four layers of detection, before anything gets cleaned.

Every upload is checked from multiple angles before sanitization runs. None of these layers decide whether to clean your file — that always happens. They decide what the report can tell you about what was lurking.

Virus signatures

Your file is checked against millions of known-malware fingerprints, refreshed on the hour from both the official feed and a curated set of community threat databases. The combined picture catches a much wider class of malware than any single source — phishing kits, attachment exploits, scam payloads, classic viruses.

Threat-family fingerprints

Beyond raw signatures, every upload is pattern-matched against a curated set of thousands of named threat fingerprints — ransomware families, banking trojans, state-sponsored toolkits. A match doesn't reject your file; it shows up in the report so you know exactly what family a suspicious upload resembled.

Office macro analysis

For Word, Excel, and PowerPoint files, the macros are inspected before they get stripped — auto-open triggers, suspicious commands (download, run, network calls), embedded URLs and IP addresses, obfuscated code blocks. The report describes what the macro would have done. The macro is removed either way.

PDF active-content analysis

For PDFs, the active-content blocks are counted and identified before they're stripped — JavaScript, auto-trigger actions, launch commands, embedded files, hidden forms. You see exactly how many were present and what kind. The PDF still gets rebuilt from clean content regardless of what was found.

Webpage Scanner BETA

Check a link before you click it.

Not every threat arrives as a file. Paste a web address and we'll tell you whether it's safe to visit — without you ever having to open it yourself. Pick how deep to look: every scan ends with a clear verdict — No known threats, Suspicious, or Malicious — and a plain-language report of what we found and why.

Standard

Checks the address against threat blocklists and reputation databases, then safely loads the page on our servers — never on your device — and inspects what it's made of: where its links lead, whether its security certificate is valid, which third-party trackers it pulls in, out-of-date code with known weaknesses, and any text hidden on the page to manipulate AI assistants.

Deep

Opens the page in a locked-down, throwaway browser and watches what it actually does — every site it quietly connects to, whether it tries to fingerprint your device or ask for sensitive permissions, and whether it shows something different to real visitors than to automated checks. You get a screenshot of what the page really looks like.

Try the Webpage Scanner

It's in beta and free to use — paste any link and see what it's really doing.

Scan a link →
Frequently asked

Everything you might wonder, before uploading.

Ready to try it?

No sign-up. No tracking. Drop a file and get a clean version in 60 seconds.

Sanitize a file →