Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If wkhtmltopdf creates a PDF without your local styles or images, fix the file-access policy first, then verify URL paths and operating-system permissions. Start with an absolute project path and the least access needed:

wkhtmltopdf --enable-local-file-access --allow /absolute/path/to/project input.html output.pdf

Use the directory that contains the HTML file and its required CSS, images, fonts, and imported assets. If that command still produces an unstyled PDF, the remaining cause is usually an invalid file:/// URL, a nested CSS reference outside the allowed directory, a JavaScript timing issue, or AppArmor, SELinux, container, or ACL restrictions.

What the local-file flags actually do

wkhtmltopdf applies a local-file security policy before loading linked resources. The --disable-local-file-access setting prevents a local file from reading other local files unless an exception is granted. --enable-local-file-access permits those reads, while --allow <path> grants access to a specific directory.

For a trusted, self-contained project, the broad switch is convenient. For a converter that may process untrusted or user-supplied HTML, prefer a narrow --allow directory and operating-system sandboxing. The wkhtmltopdf downloads page identifies 0.12.6 as the current stable series, released June 11, 2020. It also warns not to use wkhtmltopdf with unsanitized untrusted HTML or JavaScript because that can lead to complete server takeover.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Philips 24 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 241V8LB
  • CRISP CLARITY: This 23.8″ Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
  • WORK SEAMLESSLY: This sleek monitor is virtually bezel-free on three sides, so the screen looks even bigger for the viewer. This minimalistic design also allows for seamless multi-monitor setups that enhance your workflow and boost productivity
  • A BETTER READING EXPERIENCE: For busy office workers, EasyRead mode provides a more paper-like experience for when viewing lengthy documents

Broad access versus least privilege

Approach Example When to use it
Enable local access --enable-local-file-access A trusted build directory where all local assets should resolve.
Allow one directory --allow /srv/report-assets Production jobs or mixed-content hosts where the converter should read only approved assets.
Disable local access --disable-local-file-access Untrusted input, combined with controlled remote resources and OS-level restrictions.

Use paths that Qt/WebKit can resolve

Prefer document-relative URLs

Keep the HTML and assets in a predictable tree and reference them relative to the document:

report/
  input.html
  css/site.css
  images/logo.png
  fonts/Inter-Regular.woff2
<link rel="stylesheet" href="css/site.css">
<img src="images/logo.png" alt="Company logo">

Run wkhtmltopdf with the HTML file’s path and allow the project directory:

wkhtmltopdf --enable-local-file-access 
  --allow /home/me/report 
  /home/me/report/input.html /home/me/report/output.pdf

Relative URLs are resolved from the HTML document’s location, not necessarily from the shell’s current directory. This distinction matters when an application generates HTML in a temporary directory or invokes the converter from a worker process.

Use correctly formed file URLs when absolute paths are necessary

An absolute local URL must use the file:/// scheme. Escape spaces and other special characters according to URL rules. Do not put a bare Windows drive-letter path such as C:reportslogo.png in an HTML src attribute; WebKit may interpret it incorrectly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Philips 22 Inch Computer Monitor FHD 100Hz VA VESA Flicker-Free, 221V8LB
  • CRISP CLARITY: This 22 inch class (21.5″ viewable) Philips V line monitor delivers crisp Full HD 1920x1080 visuals. Enjoy movies, shows and videos with remarkable detail
  • 100HZ FAST REFRESH RATE: 100Hz brings your favorite movies and video games to life. Stream, binge, and play effortlessly
  • SMOOTH ACTION WITH ADAPTIVE-SYNC: Adaptive-Sync technology ensures fluid action sequences and rapid response time. Every frame will be rendered smoothly with crystal clarity and without stutter
  • INCREDIBLE CONTRAST: The VA panel produces brighter whites and deeper blacks. You get true-to-life images and more gradients with 16.7 million colors
  • THE PERFECT VIEW: The 178/178 degree extra wide viewing angle prevents the shifting of colors when viewed from an offset angle, so you always get consistent colors
<img src="file:///C:/reports/images/logo.png" alt="Logo">

On Unix-like systems, an absolute URL looks like file:///var/lib/reports/images/logo.png. Even with a valid URL, the directory still has to be covered by --allow or local access must be enabled.

Run a minimal fixture before changing your application

  1. Record the build. Run wkhtmltopdf --version and save the exact output. Distribution packages and patched builds can differ in behavior.
  2. Create a fixture beside the assets. Put one stylesheet and one known-good image in a small directory:
mkdir -p /tmp/wk-test/css /tmp/wk-test/images
printf 'body { color: #c00; font-size: 24px; }' > /tmp/wk-test/css/site.css
# Copy a real PNG or JPEG to /tmp/wk-test/images/test.png
<!doctype html>
<html><head>
  <meta charset="utf-8">
  <link rel="stylesheet" href="css/site.css">
</head><body>
  <h1>CSS fixture</h1>
  <img src="images/test.png" alt="Test image">
</body></html>
  1. Convert it with an absolute allow path.
wkhtmltopdf --enable-local-file-access 
  --allow /tmp/wk-test 
  /tmp/wk-test/input.html /tmp/wk-test/result.pdf
  1. Interpret the result. If the fixture works, repair the application’s generated URLs, working directory, or container mount. If it fails, inspect permissions and host security controls before debugging application HTML.

Check nested CSS, fonts, and image references

A stylesheet can load while its own resources fail. Every URL inside CSS is resolved relative to that stylesheet’s location, then checked against the local-file policy.

/* /project/css/site.css */
@import "print.css";
.hero { background-image: url("../images/hero.jpg"); }
@font-face {
  font-family: ReportSans;
  src: url("../fonts/report-sans.woff2");
}
  • Allow the common parent directory of the CSS, imported stylesheets, images, and fonts.
  • Check capitalization: Linux filesystems are case-sensitive.
  • Confirm every referenced file exists inside the runtime environment, not only on the host that generated the HTML.
  • Replace broken relative bases in generated HTML with paths relative to the actual saved HTML file.

Make sure images are enabled and failures are visible

wkhtmltopdf exposes --images and --no-images. Keep images enabled unless you intentionally want a text-only PDF. During diagnosis, make missing media fail loudly instead of silently producing a partial document:

wkhtmltopdf --enable-local-file-access 
  --allow /absolute/path/to/project 
  --images 
  --load-media-error-handling abort 
  --log-level info 
  input.html output.pdf

The corresponding library settings are commonly named web.loadImages and load.loadErrorHandling. If your wrapper exposes those settings, verify that it has not disabled image loading or changed media-error handling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Dell 24 Monitor - SE2426H - 23.8-inch FHD (1920x1080) 144Hz 1ms Display, in-Plane Switching (IPS) Technology, AMD FreeSync™, TÜV 3-Star 2X HDMI, Tilt
  • Clear visuals. Fluid motion: A 144Hz refresh rate and 1ms MPRT deliver smooth, tear‑free motion across work, gaming, and streaming for clearer, more fluid viewing.
  • Eye comfort: TÜV Rheinland 3‑star* certification reduces harmful blue light while preserving stunning color quality without compromise. *TÜV Rheinland 3-star eye comfort certification.
  • Wide viewing angle: Get consistent views across a wide 178° /178° viewing angle.
  • In-Plane Switching (IPS): See excellent color accuracy and consistency across wide viewing angles with In-plane Switching (IPS) technology.
  • Ultra-thin bezels: Maximize your viewing experience with thin bezels.

Handle JavaScript-generated styles and images

Static HTML does not need a render delay, but pages that create a stylesheet, image element, canvas, or data after startup do. Leave JavaScript enabled, then choose a deterministic readiness signal.

Measured delay

wkhtmltopdf --enable-local-file-access 
  --allow /absolute/path/to/project 
  --javascript-delay 1000 
  input.html output.pdf

Increase the delay only enough for your local generation step. A long arbitrary delay slows every job and still fails when the page’s work time varies.

Window-status trigger

Set a status value after all assets and styles are inserted:

<script>
  // Build the page, append images, then signal readiness.
  window.status = 'wk-ready';
</script>
wkhtmltopdf --enable-local-file-access 
  --allow /absolute/path/to/project 
  --window-status wk-ready 
  input.html output.pdf

A status trigger is preferable when you control the page because it waits for a known condition rather than guessing a number of milliseconds.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Samsung 27" Essential S3 (S36GD) Series FHD 1800R Curved Computer Monitor
  • CURVED FOR ENHANCED ENGAGEMENT: An immersive viewing experience with a curved monitor that wraps more closely around your field of vision; It creates a wider view, enhancing depth perception and minimizing peripheral distraction
  • SMOOTH PERFORMANCE FOR SEAMLESS CONTENT: Stay in the action when playing games, watching videos, or working on creative projects; The 100Hz refresh rate reduces lag and motion blur so you don't miss a thing in fast-paced moments¹
  • MORE GAMING POWER: Gain the edge with optimizable game settings; Color and image contrast can be adjusted to see scenes more vividly and spot enemies hiding in the dark; Game Mode adjusts any game to fill the screen so you can view every detail²
  • KEEP IT EASY ON THE EYES: Care for your eyes and stay comfortable, even during long sessions; Advanced eye comfort technology certified by TÜV reduces eye strain by minimizing blue light and reducing irritating screen flicker²
  • INCREASED VERSATILITY: Connect to more; Plug devices straight into your monitor for increased flexibility, making your computing environment even more convenient

Check operating-system and container permissions

The wkhtmltopdf flag cannot override a host policy. The converter process must be able to traverse every parent directory and read every file.

Unix permissions and ACLs

  • Check execute permission on each parent directory and read permission on CSS, image, font, and HTML files.
  • Run the command as the same service account used by the application.
  • Inspect ACLs if ordinary mode bits look correct.

AppArmor and SELinux

AppArmor profiles can deny file reads even when --enable-local-file-access is present. Grant only approved working paths in the profile and review denial logs. SELinux policies can produce the same symptom; check the audit log and apply a policy appropriate to your deployment rather than disabling enforcement.

Containers and sandboxes

A host path must be mounted into the container at the path used in the HTML and command. A file that exists on the host but not in the container is simply missing to wkhtmltopdf. Verify the mount, the in-container absolute path, and the UID running the converter. Keep the allowed directory as narrow as practical.

Common symptoms and fixes

Symptom Likely cause Fix
All CSS and images are missing Local access is disabled or no directory is allowed. Add --enable-local-file-access or a precise --allow path.
CSS loads but background images or fonts do not Nested url(...) paths are outside the allowed tree or relative to the wrong directory. Correct the URLs and allow the stylesheet’s asset parent directory.
Only Windows paths fail A bare drive-letter string is not a valid resource URL. Use document-relative paths or escaped file:///C:/... URLs.
Images work in a browser but not in the PDF Images are disabled, the process cannot read the files, or the page is captured before JavaScript inserts them. Use --images, check permissions, and add --window-status or a measured delay.
The command reports a blocked-access warning The requested file is outside the local policy or an OS policy denied it. Use the smallest correct --allow directory, then inspect AppArmor, SELinux, mounts, and ACLs.
The PDF is blank or incomplete HTML loading failed, JavaScript is still running, or a required media resource failed. Use --load-media-error-handling abort, increase logging, and test a minimal fixture.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Security, reliability, and operational guidance

  • Do not trust the flag as a sandbox. Local-file access controls are one layer. Sanitize untrusted HTML and JavaScript, isolate conversion workers, and use AppArmor, SELinux, a container, or another OS control as a backstop.
  • Pin and record the binary. Include the exact --version output in bug reports and deployment records. The stable 0.12.6 series dates from June 11, 2020, so verify compatibility when selecting a package.
  • Make inputs reproducible. Save generated HTML and assets together, use deterministic relative URLs, and ensure the same directory is available in every worker or container.
  • Fail early in CI. Convert a fixture with --load-media-error-handling abort and inspect the output so a missing logo or stylesheet does not silently reach production.
  • Report useful bugs. Include the version, command, operating system, a self-contained HTML/CSS/JavaScript case, and the asset tree. That lets maintainers reproduce path and timing failures.

Or skip the browser setup

If your goal is a clean image or PDF of a URL rather than a local wkhtmltopdf build, ScreenshotNeo provides a single HTTP request. It accepts consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and each response identifies the result with X-Page-Verdict and X-Billed headers. Its MCP server lets Claude, Cursor, and other MCP clients call take_screenshot, get_page_info, and capture_pdf.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the complete parameter list and options, see the ScreenshotNeo documentation. A direct call looks like this:

Best Value
Sale
Sceptre New 22-Inch Gaming Monitor, FHD 1080p, Up to 144Hz, HDMI, DisplayPort, Built-in Speakers, Machine Black (E225W-FW144 Series, 2026)
  • 【INTEGRATED SPEAKERS】Whether you're at work or in the midst of an intense gaming session, our built-in speakers provide rich and seamless audio, all while keeping your desk clutter-free.
  • 【EASY ON THE EYES】 Protect your eyes and enhance your comfort with Blue-Light Shift technology. This feature reduces harmful blue light emissions from your screen, helping to alleviate eye strain during long hours of use and promoting healthier viewing habits.
  • 【WIDEN YOUR PERSPECTIVE】Our sleek minimal bezel design ensures undivided attention. The nearly bezel-free display seamlessly connects in a dual monitor arrangement, delivering an unobstructed view that lets you focus on more at once, completely distraction-free.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

There is a free allowance of 1,000 screenshots per month with no card. Paid plans start at $5 for 3,000 shots; every feature is included on every plan. Create a free ScreenshotNeo account to get an API key.

Frequently Asked Questions

Does wkhtmltopdf 0.12.6 automatically allow local CSS and images?

No. The local-file policy still applies. Enable access or add an appropriate --allow directory, and verify host permissions.

Should I always use –enable-local-file-access instead of –allow?

No. Use --allow for the smallest directory that contains the intended assets, especially when processing generated or untrusted content.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does a stylesheet load while its images do not?

URLs inside CSS are resolved separately. Check each nested url(...), its relative base, and whether its directory is permitted and readable.

What information should accompany a wkhtmltopdf bug report?

Provide the exact version, command, operating system, a self-contained HTML/CSS/JavaScript example, and the complete asset tree.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.