October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
HTML to PDF

wkhtmltopdf 0.12.6: Which Build to Install and Whether It Is Safe to Keep Using

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: wkhtmltopdf 0.12.6 is still the project’s named stable series, released on June 11, 2020, but it is legacy software rather than an actively maintained renderer. Choose a package only after checking your operating system, CPU architecture and need for the project’s patched Qt features. Do not feed it untrusted HTML or JavaScript: the project warns that doing so can lead to complete server takeover, and Debian’s tracker currently marks its bookworm 0.12.6-2 package vulnerable to CVE-2022-35583 (SSRF).

What wkhtmltopdf 0.12.6 is today

wkhtmltopdf converts HTML into PDF from the command line using a Qt/WebKit rendering stack. The project’s downloads page says “The current stable series is 0.12.6, which was released on June 11, 2020.” That wording identifies the latest named series; it does not mean the code is receiving current security updates. The GitHub repository is archived and read-only, and the project status page describes Qt 4 as unsupported since 2015 and its WebKit as not updated since 2012.

That leaves three practical decisions:

  • Which build? Match the package to your operating system, distribution and architecture.
  • Do you need patched Qt? Some wkhtmltopdf features exist only in the project’s patched Qt build.
  • Can your threat model tolerate a legacy browser? If your service handles attacker-controlled HTML, the answer should generally be no unless you have strong isolation and sanitization.

Choose the package before installing

Upstream patched-Qt packages

The project publishes packages for selected operating systems, distributions and CPU architectures. These builds include the project’s patched Qt, which supplies features unavailable in an ordinary upstream Qt build. They are the compatibility choice when your templates depend on wkhtmltopdf-specific behavior such as headers, footers or other patched functionality.

Distribution-provided builds

Linux distributions may ship wkhtmltopdf without the patches. The project notes that such builds can use a later web engine and can behave differently. A distribution package may integrate more naturally with system libraries and updates, but feature parity with the upstream packages is not guaranteed. Check the package description and test the exact output your application needs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Static does not mean self-contained

A “static” package links Qt in the stated way; it does not guarantee that every system dependency is bundled. Fonts, X-related libraries, SSL components and other runtime packages can still be required. Treat the package’s installation notes as prerequisites, not optional documentation.

Architecture and operating-system checklist

  • Identify the exact distribution release, not just “Linux.”
  • Confirm whether the host is x86_64, 32-bit x86, ARM64 or ppc64le.
  • Check whether your package is from the upstream project or your distribution.
  • Record the package version and build provenance so production and development use the same renderer.
  • Verify fonts and locale data in the target container or server.

What changed in 0.12.6

The official 0.12.6 release record lists these changes:

  • Local filesystem access is blocked by default. This is a breaking change for documents that read local images, stylesheets or files.
  • Table-of-contents and other special pages missing from output were fixed.
  • A Canvas setLineDash regression was fixed.
  • --encoding can be used with non-patched builds.
  • Support was added for ppc64le and 64-bit ARM.

These are changelog items, not independent proof that every vendor package behaves identically. The earlier 0.12.5 history includes SSL client-certificate support, fixes for crashes or blank pages during count and print phases, and fixes involving fonts, Unicode URLs and read-only form fields.

Is wkhtmltopdf 0.12.6 safe?

Untrusted input is the hard boundary

The project’s downloads page says: “Do not use wkhtmltopdf with any untrusted HTML – be sure to sanitize any user-supplied HTML/JS, otherwise it can lead to complete takeover of the server it is running on!” Take this literally. A web endpoint that accepts arbitrary HTML, templates or JavaScript should not render it directly in a process with access to application secrets or the internal network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Legacy engine and package-specific exposure

The project describes the WebKit1 in-process API and old Qt/WebKit components as security concerns. Debian’s Security Tracker lists bookworm package 0.12.6-2 as vulnerable to CVE-2022-35583, an SSRF issue. That status applies to the identified Debian package; it is not a complete audit of every distribution’s build, nor proof that all deployments have identical exposure.

Minimum containment if you must run it

  • Sanitize HTML and JavaScript before rendering.
  • Run the converter as a dedicated unprivileged user in a container or isolated worker.
  • Deny outbound network access except for explicitly required origins.
  • Block access to cloud metadata endpoints, localhost, private address ranges and Unix-sensitive paths.
  • Use read-only filesystems, small memory and CPU limits, and a job timeout.
  • Keep credentials, sockets and application data out of the worker.
  • Log the exact command, package version, exit status and output size.

Installation and first verification

Because package names and dependencies vary, install from the package source appropriate to your host rather than copying a command for a different distribution. After installation, verify the binary and renderer:

  1. Run wkhtmltopdf --version and record whether the output mentions “with patched qt.”
  2. Render a known local test document and a controlled HTTPS page.
  3. Check that fonts, images, page breaks, headers, footers and any table of contents match your application’s requirements.
  4. Test with filesystem access disabled. If a legacy template expects local assets, move those assets to an approved HTTP endpoint or explicitly review the security implications before changing defaults.
  5. Repeat the test inside the production container, where available fonts and libraries may differ from your workstation.

Do not enable broad local-file access merely to make a broken template work. First identify which asset is missing and whether it can be supplied safely.

Common failures and fixes

“Command not found” or shared-library errors

The binary is absent from PATH or a runtime dependency is missing. Confirm the installed package, inspect the package’s dependency list, install the required system libraries and run the same binary path used by your service.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Adobe Acrobat 6 PDF For Dummies
  • Used Book in Good Condition

Headers, footers or special pages disappear

You may be running an unpatched distribution build. Compare wkhtmltopdf --version output with the upstream package and test the feature in a minimal document. If patched behavior is mandatory, use a supported upstream package for the target architecture or change the template.

Local images or CSS no longer load

0.12.6 blocks local filesystem access by default. Prefer serving approved assets over a controlled local HTTP endpoint. If you must alter the setting, isolate the worker and restrict which files it can read.

Blank pages, clipped content or different pagination

WebKit is an old browser engine, and distribution builds can differ. Fix missing fonts, wait for asynchronous content explicitly, set a deterministic viewport and compare the exact package in development and production. Do not assume a modern browser’s CSS support.

Timeouts and hanging jobs

Use a per-document timeout, limit concurrent workers and capture diagnostic stderr. Check for unreachable external assets, JavaScript loops and pages that wait forever for network activity. A queue with a kill-and-restart policy is safer than allowing a stuck process to consume all workers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SSRF or unexpected outbound requests

Treat every URL and redirect as hostile. Apply egress firewall rules and DNS/IP validation outside wkhtmltopdf; renderer flags alone are not a complete network policy.

Operational guidance: reliability, performance and cost

Rendering cost is dominated by page complexity, external resources, JavaScript and process startup. Reuse a worker pool only if you can reset state between jobs; otherwise launch short-lived isolated workers. Cache immutable assets, bundle approved fonts, and avoid waiting on third-party analytics or advertising. Measure output size and render duration per template, then set limits based on those measurements rather than a single global timeout.

Pin the binary and package checksum in your build pipeline. A distribution update can change the WebKit engine or linked libraries, while an upstream static package can still depend on host components. Keep a golden set of PDFs and compare text, page count, images and layout after upgrades.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When to retain it—and when to migrate

Retain temporarily when

  • Your templates rely on patched-Qt behavior that has been validated with the exact package.
  • Input is controlled, sanitized and rendered in a strongly isolated worker.
  • You have regression PDFs and a documented rollback package.

Plan a migration when

  • Users can submit HTML or JavaScript that reaches the renderer.
  • You need current browser standards, modern TLS behavior or active security maintenance.
  • Your distribution package is flagged by its security tracker or cannot provide required features.
  • Maintaining old fonts, patches and workarounds costs more than adapting templates to a maintained renderer.

The supplied project material does not establish a particular replacement’s compatibility or support lifetime. Evaluate candidates against your real HTML, CSS, JavaScript, PDF metadata, pagination and isolation requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

If your goal is simply a clean screenshot or PDF of a web page, ScreenshotNeo provides a hosted website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF. It accepts cookie and consent banners before capture, removes more than 60 known consent platforms plus newsletter popups and chat widgets, and bills only clean shots: bot checks, CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.

cURL:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

See the complete parameter reference in the ScreenshotNeo documentation. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Sign up free.

Frequently Asked Questions

Does 0.12.6 mean wkhtmltopdf is actively maintained?

No. It is the project’s named stable series, released June 11, 2020, while the repository is archived and the underlying Qt/WebKit components are obsolete.

Are all Linux packages equivalent?

No. Upstream patched-Qt packages and distribution builds can differ in features, engine behavior and dependencies. Verify the exact binary in your deployment.

Can I render user-submitted HTML safely?

Not by default. Follow the project’s warning, sanitize input and isolate the renderer with strict filesystem and network controls.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 2
Adobe Acrobat 6 PDF For Dummies
Adobe Acrobat 6 PDF For Dummies
Used Book in Good Condition
$13.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.