Skip to main content
webfuscator turns a JavaScript source string into harder-to-read JavaScript. It runs synchronously, performs no file I/O, and returns source code. ESM only Seeded output TypeScript declarations Paste a file into the playground to watch a transform run in your browser before you install anything.

Run your first obfuscation

Install the package and transform a working JavaScript file.

Choose your transforms

Set which passes run, choose a naming mode, and configure property mangling.

Read the API reference

Check the function signature, supported syntax, output, and error behavior.

Use it in a build script

Pass JavaScript to obfuscate, then write the returned string wherever your build expects it.
obfuscate.mjs

Know what the pipeline does

Parses JavaScript

Babel accepts scripts and ECMAScript modules with unambiguous source detection. Compile TypeScript, JSX, and other syntax extensions first.

Runs transforms from the map

A transform runs when its entry is true or its supported options object. Transforms skip sites they cannot handle.

Prints source

The API returns JavaScript only. It does not return an AST or generate a source map.
The same source, options, package version, and Node.js version produce the same output. Change seed when you want a different built-in randomized sequence.
Obfuscation does not hide client-side secrets or create a security boundary. Use webfuscator only on software you own or are authorized to modify. Read the project’s responsible-use policy.

Explore the reference

Obfuscator options

Transform entries, naming modes, seeds, formatting, and verbose output.

Property mangling

Rename selected properties without losing control of public names.

String generator modes

Compare mangled, hexadecimal, randomized, zero-width, and numbered names.

Transform reference

See what each pass changes, with a before-and-after example.
Last modified on August 26, 2026