JavaScript Obfuscator

Make JavaScript harder to read and copy by renaming identifiers, moving strings into encoded arrays and restructuring control flow. Choose a strength preset.

Loading tool…

About the JS Obfuscator

This tool runs the open-source javascript-obfuscator library in your browser. The presets map to its built-in option sets. Low renames identifiers to hexadecimal names like _0x3a1f, moves string literals into a rotated, shuffled array and simplifies code layout; performance impact is small. Medium adds control-flow flattening (functions become switch-based state machines), Base64-encoded strings and dead-code injection. High adds RC4-encoded strings, self-defending code that breaks when reformatted, and more aggressive transformations — expect code that is several times larger and noticeably slower.

Rename globals also renames top-level functions and variables; only use it when no other script calls them. Disable console output replaces console methods at runtime. Reproducible output uses a fixed seed so the same input always gives the same output, which helps with caching and diffs.

Be realistic about what obfuscation buys you. The browser must be able to run the code, so it can always be executed, stepped through in a debugger and gradually reversed with deobfuscation tools. Use it to deter casual copying, never to hide API keys, license checks or business logic that must stay secret — keep those on the server. Always test obfuscated code before releasing it.

How to use it

  1. Paste the JavaScript you want to protect.
  2. Choose Low, Medium or High.
  3. Set Rename globals and the other options as needed.
  4. Test the output, then copy or download it.

Frequently asked questions

Can obfuscated JavaScript be reversed?
Largely, yes. Tools like webcrack and de4js undo common transformations, and anyone can observe what the code does at runtime. Obfuscation raises the effort, it does not make code secret.
Does obfuscation slow down my code?
It can. String decoding and control-flow flattening add runtime work, and the High preset can make hot code paths several times slower. Obfuscate only the parts that need it.
Should I minify or obfuscate?
Minify all production JavaScript for performance. Obfuscate only when deterring copying is worth the size and speed cost, and obfuscate the source first, not already-minified code.

Related tools