JavaScript Obfuscator

A quick, honest obfuscation pass: escaped strings and renamed identifiers, with property accesses protected.

Honest limits: this is light, reversible obfuscation — a speed bump for casual readers, not a security boundary.

Privacy: everything runs in your browser; your code never leaves this page.

How to use

  1. Paste your JavaScript into the input.
  2. Review the output and the counters (renamed identifiers, escaped strings).
  3. Test the result before shipping — and remember it is reversible, not security.

Frequently asked questions

What does "light obfuscation" mean here?

Two transformations: string literals are rewritten with \xNN hex escapes, and eligible identifiers are renamed to _0x0000-style names. It defeats the most casual skim-reading and keeps the code runnable, but it is reversible — treat it as a speed bump, never as security.

Why are some identifiers left alone?

The tool refuses to rename anything that also appears as a property access (user.name), an object key (name:), or inside brackets — renaming those would change behavior. It also skips template literals so ${} expressions keep working.

Will the output behave identically?

For the constructs this tool handles, yes — the transformation is purely lexical: strings decode to the same values and renamed identifiers point to the same bindings. Always test the output anyway; obfuscation is a code-changing operation.

How is this different from a real obfuscator?

Commercial obfuscators add control-flow flattening, dead-code injection and self-defending runtime checks. Those change program structure heavily; this tool deliberately stays light, fast and dependency-free.

Is my code uploaded anywhere?

No. Everything runs in your browser — nothing is sent to any server.

Comments