Skip to main content
No configurable transform runs unless its transforms entry is true. Transforms with settings also run when that entry is an options object. The playground opens with a starter preset. Its checked transform switches are example configuration, not library defaults.
Internal preparation passes always normalize AST shapes before configurable transforms run. They are not exposed in options.transforms.

Run one transform

Set an ordinary transform’s key to true. An options object also makes that transform run and supplies its settings. An omitted key or false means that transform does not run.
obfuscate.mjs
The options reference lists all transform keys and links to the safety rules for each pass.

Choose generated name styles

Set stringGeneratorMode once to control generated identifiers, labels, property names, and string contents.
obfuscate.mjs
pack, renameIdentifiers, and specialsToStrings can override the top-level mode:
obfuscate.mjs
See string generator modes for output samples and tradeoffs.

Use seeds for repeatable output

seed controls the built-in randomized choices. Keep it fixed for stable build artifacts, or change it deliberately when you want a new sequence.
Reproducibility assumes the same input, options, webfuscator version, and Node.js version. A seed is not a cryptographic key.

Mangle only properties you control

Code outside the source string can still use its original property names. Unrestricted mangling can therefore break another file, serialized data, templates, framework hooks, or browser APIs.
obfuscate.mjs
This configuration selects names ending in _ and then excludes public_api_. For multi-file builds, share one cache between every file that exchanges those properties.

Plan property mangling

Compare regex, annotation, cache, and quoted-property strategies before using the transform.

Verify the built artifact

Run tests against the generated file, not only the unobfuscated input. Cover exported calls, dynamic imports, reflection, serialization, framework hooks, and external callers. Use verbose: true when you need stage timings. It writes progress to standard error and does not change the returned source.
Last modified on August 26, 2026