Stirling PDF: 12,660 title matches and no application fingerprint
A document tool that accepts uploads and returns modified files is a service worth counting, because the documents that pass through it are frequently the ones that were never meant to leave a controlled environment. Stirling PDF runs PDF conversions, merges and signature checks locally, and the index identifies it by page title while finding nothing by application signature.
What the queries measured
Two queries were run against the ZoomEye index on 5 October 2026, scoped to all asset types.
Search query: app="Stirling PDF". Result: 0 matching assets.
Comparison query: title="Stirling PDF". Result: 12,660 matching assets.
What the figures describe
The title count is the only population figure available, and it has the usual breadth. It covers running instances and it covers pages that reference the product. The figure is an upper bound.
The empty fingerprint result has a specific cause in this case. Stirling PDF is usually deployed as a container that serves a user interface and an API from the same port, and the front end is a single-page application. A crawler that reaches the address collects the shell of that application, not a banner that an index can attach to a product pattern.
The combination produces a population figure without a confirmed-instance figure, which is the weaker of the two arrangements. It is still an improvement on no figure at all, because the number is large enough that the product is clearly deployed in the wild and the entry points clearly exist.
Why this class of service matters
Document tooling sits inside the workflow rather than beside it. A service that converts, merges and signs documents is reached by people who are handling contracts, reports and forms. The upload path is the exposure that matters most, because it is the path that accepts a file from anywhere.
The defensive implications are structural rather than version-specific. Whether the service should be reachable from outside the network is one question. Whether it should accept anonymous uploads is another. Whether the files it processes are retained on disk is a third, and it is the one that is usually answered by a default rather than a decision.
What an operator can do next
Compare the figure against the organisation's records, and treat an unaccounted instance as an unmanaged service. Where the tool is used internally, a network rule is the smallest effective change.
Confirm the retention behaviour of any instance that stays reachable. A conversion service that keeps uploads after the response is a copy of every document it has processed.
Limitations
The count describes indexed assets on one day and cannot separate an instance from a page that mentions one. It does not identify version, authentication state or retention configuration.
References
[1] Stirling PDF. https://www.stirlingpdf.com/
[2] Stirling PDF source repository. https://github.com/Stirling-Tools/Stirling-PDF
[3] ZoomEye. https://www.zoomeye.ai/
Top comments (0)