logologo
  • How it works
  • Why It Matters
  • Statistics
  • Pricing
  • FAQ
  • API
logologo
  • How it works
  • Why It Matters
  • Statistics
  • Pricing
  • FAQ
  • API
HTPBE?

Structural PDF tamper detection API. Catches edits your KYC stack misses.

Product

  • How It Works
  • Use Cases
  • Metadata Viewer
  • Pricing

Developers

  • API Reference
  • GitHub/docs
  • Changelogv2.44.3

Resources

  • About
  • Blog
  • Comparisons
  • Legal & Imprint

© 2024–2026 TMI Iurii Rogulia · VAT ID: FI29845875 · Made in Finland 🇫🇮

Status

Algorithm v2.44.3

Tool profile

WPS Office

WPS Office appears on both legitimate first-generation output and downstream re-save flows — context (the other tool on the same document) is what flips the signal.

Back to all statistics
Forensic verdict

Mixed signal

Based on this tool’s share of the HTPBE? corpus.

Modification rate
13%-36pp below baseline
Corpus baseline: 49%
Corpus share
0.33%
Share of all analyzed appearances
Modification rate
13%
-36pp below baseline
Role split
100%C/0%P
Creator vs Producer share of appearances

Corpus profile

How WPS Office shows up in HTPBE? corpus

WPS Office is one of the PDF-handling tools surfaced in the HTPBE? corpus. WPS Office appears predominantly as the original Creator (100% of its occurrences) — i.e. on documents that started life inside WPS Office rather than passing through it as a downstream re-saver.

In the HTPBE? corpus the contextual signal we look for is a producer/creator mismatch: when WPS Office appears as the latest Producer on a document whose Creator was an institutional source (e.g. Adobe PDF Library, Microsoft Word, a banking back-end), the document was rebuilt or re-saved after its original creation. That mismatch is the marker — never the tool itself.

On documents where WPS Office acts as Creator, 13% carry modification markers; on documents where it acts as Producer, 0% do. These are observed rates inside the HTPBE? corpus and should be read as base-rates, not as accusations against WPS Office or its users.

The signal
In the HTPBE? corpus the contextual signal we look for is a producer/creator mismatch: when WPS Office appears as the latest Producer on a document whose Creator was an institutional source (e.g. Adobe PDF Library, Microsoft Word, a banking back-end), the document was rebuilt or re-saved after its original creation. That mismatch is the marker — never the tool itself.

Role in the workflow

How WPS Office shows up in metadata

Every PDF carries a Creator (the application that produced the original document) and a Producer (the engine that wrote the PDF). The same tool can appear in either slot, with very different modification profiles.

CAs Creator · 100%
As Producer · 0%P
CAs Creator
  • Share of appearances
    100%
  • Modification rate
    13%
  • Avg file size
    263 KB
PAs Producer
  • Share of appearances
    0%
  • Modification rate
    0%

How to read this

The Creator slot typically reflects where a document started life. The Producer slot reflects whatever wrote the bytes — and is the field that gets overwritten when a PDF is opened, edited, and saved by a downstream tool.

A higher modification rate as Producer than as Creator usually means the tool is acting as a re-saver on documents that originated elsewhere. A higher rate as Creator points to fragile workflows around the original authoring app.

Name fingerprints

Also goes by

Different version strings and spellings observed for WPS Office in the wild. All are merged into the same canonical profile.

WPS 表格65.8%
WPS 文字24.1%
WPS Writer5.1%
WPS Docs2.5%
WPS Office WWO_wpscloud_20250605154722-c1ee60194f1.3%
WPS Office_12.1.0.25225_F1E327BC-269C-435d-A152-05C5408002CA1.3%

Why variants matter

The same tool publishes itself under 6 different metadata strings — version bumps, locale tags, build IDs. We canonicalize them so the corpus reflects one identity, not noise.

Most common
WPS 表格
65.8% of appearances
Variant spread
6 distinct strings
Long-tail share: 34.2%
Observed range
18.12.2023 → 28.07.2026

Distributions

What ships alongside WPS Office

The PDF versions WPS Office writes when acting as Producer, and the other tools that appear in the same documents.

Common Producers when WPS Office is the Creator

macOS Print to PDF writes 3% of these files — that pairing is the Adobe-stack default for many institutional pipelines.

macOS Print to PDF2.5%
iOS Print to PDF1.3%
Aspose1.3%

Related profiles

Tools you’ll see next to WPS Office

Other tools that frequently share metadata with WPS Office in the same documents. Each card links to its own forensic profile.

P3% co-occurrence
macOS Print to PDF
Corpus share3.4%
Mod rate64%
P1% co-occurrence
iOS Print to PDF
Corpus share1.7%
Mod rate64%
P1% co-occurrence
Aspose
Corpus share3.7%
Mod rate39%

Long tail

Notable observations

Smaller cuts of the WPS Office corpus — useful context, but treat each row as a single data point rather than a strong signal.

Avg pages per document
2.4
Oldest observed
18.12.2023 — over 2 years ago

Secure your workflow

Create your account — check PDFs on the web or with an API key, both ready on signup.
From $15/mo. No sales call. Cancel any time.

Start Free — Close the Structural Fraud GapSee Pricing
Read API Docs →