DevToolPal
EN

JavaScript Obfuscator

Make JavaScript hard to read by renaming variables, hiding strings and flattening logic, while it still runs the same.

Runs locally, never uploaded

Options

Strength

Higher strength hides more but makes the code larger and slower.

Input

0 chars · 0 B

Output

0 chars · 0 B

What it does

The JavaScript obfuscator rewrites a script so that it still runs exactly the same but is much harder for people to read and copy. Variable and function names become meaningless identifiers like _0x3f2a, string literals move into an encoded lookup table, and at higher levels the control flow is shuffled and dead code is mixed in.

It is useful for browser games, demos, widgets and licence checks that you ship as plain JavaScript and do not want copied word for word.

How to use

  1. Paste your JavaScript or open a .js file.
  2. Choose a Strength:
    • Low renames local names and moves strings into a lookup array. The output stays fast and fairly small.
    • Medium adds encoded strings, control-flow flattening and some dead code.
    • High applies everything at full strength. The result can be many times larger and noticeably slower.
  3. Turn on Rename global names only if nothing outside the script refers to its top-level functions or variables.
  4. Turn off Single line output if you want the result spread over several lines.
  5. Copy or download the obfuscated code and test it before deploying.

Example

The sample defines a greet function and a visit counter. After obfuscation at low strength the code is a single line of hexadecimal names, yet running it still prints Hello, Ada! You have visited 1 time(s).

Obfuscation versus minification

Minification, as done by the JavaScript and CSS minifier, removes whitespace and shortens names to make files smaller and faster to download. Obfuscation goes the other way on size: it deliberately adds indirection to make code harder to understand. Many projects minify everything and obfuscate only the few files that contain logic worth protecting.

Limits

Obfuscation cannot protect secrets. Anything the browser can run, a user can eventually inspect, so keep API keys and business rules that must stay private on your server. Heavy settings also slow code down, so avoid them in hot loops and performance-sensitive pages.

FAQ

› Does obfuscation change what my code does?

No. The obfuscated script behaves the same as the original; only its form changes. Always run your tests against the obfuscated build, because code that inspects its own source or function names can behave differently.

› Can obfuscated code be reversed?

Not completely, but a determined person with time can still work out what it does. Treat obfuscation as a speed bump against casual copying, never as a place to hide secrets such as API keys.

› When should I turn on Rename global names?

Only when the script is self-contained. Renaming globals breaks HTML attributes, other scripts or tests that call your top-level functions by name.

› Is my code uploaded?

No. Obfuscation runs in your browser with the open-source javascript-obfuscator library.