ScreenshotNeo

BlogEngineering

Is wkhtmltopdf Still Maintained and Safe to Use?

wkhtmltopdf is no longer maintained upstream. Whether to keep using it depends on your build, inputs, wrappers, and the limits around the process.

By the ScreenshotNeo team4 October 20267 min read

Short answer: wkhtmltopdf is no longer maintained upstream. Its core GitHub repository was archived on January 2, 2023, and the project organization says it is no longer maintained. Whether a particular installation is safe depends on the exact binary and package, any wrapper around it, the HTML and options it processes, and the permissions of the process running it. The available evidence does not establish that every installation is exploitable, or that the core executable has one specific current vulnerability.

If you are deciding whether to keep it, treat it as an unsupported component: identify the exact build and integration, prevent untrusted content or options from controlling it, restrict its filesystem and network access, and plan a migration if the security and compatibility tradeoffs are no longer acceptable.

1. Is wkhtmltopdf still maintained?

No. The upstream repository is archived and read-only. The wkhtmltopdf GitHub organization is also archived and describes the project as no longer maintained. That means you should not expect upstream fixes or active support for newly discovered issues.

Keep core releases distinct from packaging revisions. The core releases page lists version 0.12.6, released June 10 (the release page records the date without a year in its release heading). A separate packaging repository lists packaging revisions; a packaging revision such as 0.12.6.1 r3 is not a new core release. Check the exact artifact you deploy rather than relying on a version string copied from a blog or wrapper. Core release records · Packaging releases

2. Is wkhtmltopdf safe to use?

There is no single yes-or-no answer for every deployment. An archived renderer deserves a more conservative security posture because there is no active upstream project to provide fixes. Actual exposure depends on what reaches the renderer and what the renderer can access.

Question Why it matters
Which binary and package are running? Operating system packages, static builds, and vendor bundles can differ. Record the source, version, build variant, and package revision.
Can users control HTML, URLs, or render options? Untrusted content and options can create risks at the renderer or wrapper boundary. Do not assume escaping alone makes arbitrary render options safe.
What can the process read or reach? Filesystem and network access determine the potential impact if hostile content triggers unintended access or behavior.
Is a wrapper involved? A wrapper may translate HTML, metadata, or user options into command-line arguments. Wrapper vulnerabilities are distinct from vulnerabilities in the core executable.
Can you tolerate unsupported software? Even if the current deployment is constrained, future compatibility needs and newly discovered issues may be harder to address without upstream maintenance.

3. What the 0.12.6 hardening note does—and does not—say

The 0.12.6 release notes document a breaking change: block local filesystem access by default. That is useful, but narrow. It supports the conclusion that local file access changed by default in that release; it does not show that every risky input path, network request, wrapper behavior, or downstream build is prevented. Review the flags your application supplies and the behavior of the specific build you run. wkhtmltopdf 0.12.6 release notes

4. Recent security advisories concern wrappers

Recent advisories illustrate why you must inspect the integration as well as the executable:

  • A July 2026 advisory describes shell command injection in affected versions of the Perl wrapper Catalyst::View::Wkhtmltopdf before 0.6.1 when user-controlled render options are not validated. The advisory recommends upgrading that wrapper to 0.6.1 or later. It is a wrapper-specific finding, not evidence that the same flaw exists in the core executable. Openwall advisory archive, July 2026
  • NVD CVE-2026-16770 describes argument injection in PDF::WebKit versions through 1.2: HTML meta-tag values can become wkhtmltopdf command-line options. The record describes argument injection, not shell command execution, and concerns that wrapper’s handling of input.

These examples do not mean every installation or integration is affected. They do show why you should trace untrusted data all the way from the request or document through wrapper option handling to the process invocation. The reviewed evidence is not a complete vulnerability inventory for every core build, downstream package, or deployment.

5. A practical decision checklist

  1. Inventory the renderer. Record the executable path, reported version, package manager or image, build variant, wrapper and wrapper version. Check package changelogs for downstream patches, but do not assume a package revision is an upstream core release.
  2. Trace inputs. Identify who controls the source HTML, URL, metadata, filenames, headers, cookies, and command-line options. Treat render options as structured data with a strict allowlist; do not pass arbitrary user-supplied option strings to a wrapper.
  3. Constrain execution. Run the renderer as a low-privilege user in a separate process or container where practical. Limit readable files, writable directories, network egress, CPU, memory, and execution time to what the job needs. These are risk-reduction measures, not a guarantee of safety.
  4. Review local-file settings. Confirm the behavior of your specific build and wrapper. Avoid enabling local file access unless the use case requires it, and constrain accessible paths at the operating-system level.
  5. Review wrapper advisories. Check the precise package named by an advisory and its fixed version. Do not treat a wrapper fix as proof that the core is maintained, or a core version as proof that a wrapper is safe.
  6. Decide whether to migrate. Compare maintenance and patch availability, exposure to untrusted HTML, isolation quality, template compatibility, output fidelity, and the effort of regression testing. The research here does not evaluate or rank replacement renderers, so choose alternatives against your own requirements.

6. Capture a PDF with wkhtmltopdf

For a controlled, trusted page, a basic command is:

wkhtmltopdf https://example.com report.pdf

This is a usage example, not a security recommendation for rendering arbitrary user content. For local HTML, a typical invocation is:

wkhtmltopdf report.html report.pdf

Version, build, and wrapper differences matter. Inspect the options supported by the installed binary with wkhtmltopdf --extended-help and its version with wkhtmltopdf --version. Do not copy options blindly from another installation. In particular, the 0.12.6 local-file default and the behavior of older or downstream builds may differ.

7. Troubleshooting

Symptom Likely cause What to check
Executable not found The binary is absent or not on the service user’s PATH. Check the deployed package and absolute executable path in the same runtime environment as the application.
Local images, stylesheets, or fonts are missing The input uses local paths that the build does not permit, or the service user cannot read them. Check the 0.12.6 local-file-access behavior, the exact build, path permissions, and wrapper options. Grant only the required access.
Output differs between developer machine and server Different binary builds, fonts, dependencies, or wrapper versions can affect rendering. Compare version output, package revision, build variant, installed fonts, and invocation options.
Wrapper reports an option error or unexpected behavior Wrapper and core option support can differ; untrusted input may also be altering options. Check the wrapper’s version and documentation. Validate options against an allowlist and inspect how the wrapper constructs the process arguments.
Process hangs or consumes excessive resources A page may load slowly, wait on external resources, or consume substantial rendering resources. Set an application-level deadline and resource limits, restrict unnecessary network access, and log the input and exit status without exposing secrets.
A CVE mentions wkhtmltopdf The affected component may be a particular wrapper rather than the core binary. Read the advisory’s affected package and version range. Upgrade the named wrapper when applicable, then separately assess the renderer and deployment.

8. Performance, reliability, and cost

wkhtmltopdf runs as a renderer in your own environment, so operational cost depends on your compute, packaging, maintenance, and the time spent diagnosing output and security issues. The supplied research provides no benchmark, so do not assume a particular throughput or cost advantage. Test representative pages under realistic resource limits if performance matters.

For reliability, pin and record the binary and wrapper versions, keep a reproducible deployment artifact, use deadlines and resource limits, and monitor nonzero exits and incomplete output. Archived upstream status means you should account for the possibility that a future compatibility or security problem will require a workaround or migration rather than an upstream patch.

9. Or skip the browser setup

If your task is to capture a website screenshot or PDF through an API, ScreenshotNeo is a website screenshot API and MCP server for developers. It is an alternative to operating a browser capture setup; it is not a drop-in wkhtmltopdf replacement for every HTML-to-PDF workload. See the ScreenshotNeo API documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
const data = new Uint8Array(await res.arrayBuffer());
await import('node:fs/promises').then(fs => fs.writeFile('shot.webp', data));
  • Cookie and consent banners, newsletter popups, and chat widgets can be removed before capture; each cleanup step can be turned off.
  • Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing; response headers report the page verdict and billing status.
  • An MCP server lets AI agents using Claude, Cursor, or another MCP client call screenshot and PDF tools.
  • The Free plan includes 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; yearly billing gives two months free, and every feature is on every plan.

Sign up for 1,000 free screenshots a month, with no card required.

10. FAQ

Does the 0.12.6.1 packaging revision mean the core is maintained?

No. Packaging revisions and upstream core releases are different records. Check both repositories and the artifact actually installed.

Does blocking local file access by default make every build safe?

No. The release note documents a specific default change. It does not establish protection against every input, network, wrapper, or deployment risk.

Does a wrapper CVE prove the wkhtmltopdf executable itself is vulnerable?

No. Read the affected component and version range in the advisory. The examples above identify flaws in specific wrappers and their input handling.

Can I get a definitive safe-or-unsafe verdict for my installation?

Not from project status alone. You need the exact build, package, wrapper, inputs, options, and runtime permissions to assess your exposure.