File Signature Auditor
Select local files to compare their filename extensions with actual bytes. The auditor checks PNG chunk boundaries and CRCs, PDF header and cross-reference pointer, JPEG marker sequence, classic ZIP directory metadata, and RIFF/WAVE chunks. It reports exact hexadecimal evidence and separately marks truncation, unknown formats, ZIP-derived containers, unexplained trailing bytes and a complete appended second format. These bounded checks do not fully decode files or detect malware.
Key features
- Check actual PNG, PDF, JPEG, classic ZIP and RIFF/WAVE bytes against filename extensions
- Inspect bounded internal structure, not just the first magic bytes
- Distinguish a complete appended second format from unexplained or ambiguous trailing data
- List byte offsets and observed hex for supporting evidence and failures
- Download a per-file JSON audit report without changing the originals
How to use
- Select up to 20 local files or load the built-in example set.
- Run the audit to compare extensions with detected signatures and bounded structure.
- Open each evidence list to inspect byte offsets, hex and any trailing content.
- Download the JSON report if needed; confirm important files with a dedicated parser or security tool.
Use cases
- Spot a PNG renamed to .pdf or a PDF renamed to .png
- Identify truncated image, document, archive or audio files before sharing
- Review a PNG with a complete ZIP appended after its IEND chunk
- Separate unsupported file types and ZIP-based document containers from definite mismatches
Frequently asked questions
Does a matching extension mean the file is safe?
No. Format checks do not detect malware, malicious document content, or every malformed payload. Use a dedicated security scanner when needed.
Why is a DOCX shown as a ZIP container?
DOCX and several other formats use ZIP internally. This tool confirms only the ZIP container structure, not the document's members or semantics.
What does an appended second format mean?
After the first format's terminal marker, the tool found another supported header and bounded structure. That is a composite file; whether either format is dangerous depends on the software that opens it.
Is every PDF, ZIP or JPEG fully validated?
No. PDF objects and content streams are not decoded, ZIP member data is not inflated, and JPEG scan data is not decoded. The evidence shows the limited checks performed.
Are unknown or unsupported files considered corrupt?
No. Unknown bytes and extensions outside PNG, PDF, JPEG, ZIP and WAV are shown as unconfirmed or unsupported, not automatically damaged.
Privacy
Selected files are read only in this browser tab and are not uploaded. The downloadable JSON report contains filenames, lengths and short hexadecimal evidence, but not complete file content. Review filenames before sharing it.
Comments & questions