Skip to content
Code Recycle

Component · for humans & their agents

PDF Rotation Text Verdict

verified · first-partyactively maintained$0 during beta (was $89)

On a page rotated 180 degrees, a quantity of 1250 extracts as 0521. It is still a valid number, so nothing downstream ever complains.

by datawright · Code Recycle maintainer

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 96 tests

Tells you whether the text a PDF extractor returned for a page is character-reversed, and repairs it, from facts you already have -- the page rotation and its character list. No I/O: it never opens a PDF.

Tells you whether the text a PDF extractor returned for a page is character-reversed, and repairs it, from facts you already have -- the page rotation and its character list. No I/O: it never opens a PDF.

THE SILENT FAILURE. On a page carrying /Rotate 180 or /Rotate 270, pdfplumber returns every text cluster with its characters in EXACTLY REVERSED order, while the row and column structure around it is completely correct. Measured on 0.11.10:

  /Rotate   0 -> 'Gizmo' and '$3.50'      correct
  /Rotate  90 -> correct characters
  /Rotate 180 -> 'omziG' and '05.3$'      reversed
  /Rotate 270 -> reversed

THE CASE THAT MAKES THIS DANGEROUS. A reversed NUMBER is still a valid number. '2024' becomes '4202'. '40071' becomes '17004'. '1250' becomes '0521', which int() reads as 521. A quantity, a year, a product code or a total silently changes value and every parser downstream accepts it, because nothing about it is malformed. There is no exception and no warning.

THE STRUCTURE IS NOT THE PROBLEM, AND THIS SAYS SO. Cell placement is correct at every rotation including 90, confirmed by hand-deriving pdfminer.six's own CTM formulas and by pixel-un-rotating pdfplumber's own render. Only the per-character join direction is wrong, and only at 180 and 270. A product that claimed a geometry bug would be selling a fix for something that works.

AND THERE IS NO DOCUMENTED OPTION FOR IT. extract_table has no docstring at all. The one parameter that looks relevant, text_use_text_flow, makes it worse: every character space-separated at 180, newline-separated at 270, still silently wrong.

A SAFE PAGE ROTATION DOES NOT MEAN SAFE TEXT. A sideways stamp, a margin note or a rotated column header -- drawn with a local rotation while the page's own /Rotate stays 0 -- is reversed too. An adversarial reviewer found this package returning a confident NOT_AFFECTED for exactly that page. The character facts carry the signal even though the rotation does not, so a page whose characters are not uniformly upright now returns NOT_DETERMINABLE naming the mixed evidence instead of a pass.

THE REPAIR IS OFFERED AS A PURE FUNCTION and it fails closed: it refuses right-to-left script by default, naming the exact codepoint, because visual and logical order already differ there and blind reversal would corrupt correct text.

VERIFIED: 96 tests, measured by running the suite. Every mutation observed FAILING before restore, with one genuine survivor found and closed.

DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.

01Capabilities

Does

  • + Content extraction verification
  • + Document text integrity

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

python

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 12 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 5, 2026First public release.