JavaScript Obfuscator
Rename variables and encode string literals to obscure JavaScript source.
Input
Drop file here or click to browse
Maximum 5 MB (.js,.mjs,.cjs,.ts,.txt)
Output
About the JavaScript Obfuscator
Obfuscate JavaScript before shipping it: rename local variables to meaningless names and encode string literals, so the logic is harder to skim at a glance. Built on a real parser rather than find-and-replace, so scoping, shadowing, and destructuring are handled correctly instead of silently breaking.
How to use it
- 1 Paste the JavaScript you want to obfuscate.
- 2 Toggle variable renaming and string encoding on or off as needed.
- 3 Click Obfuscate.
- 4 If renaming was skipped, the banner explains why — check the code for eval(), with, or import/export.
- 5 Copy or download the obfuscated result.
What it does
- Scope-aware variable renaming — every binding gets a file-unique name, so shadowing and closures can never collide after renaming
- String literal encoding to hex/unicode escapes
- Automatic safety checks for eval(), with statements, and ES module bindings
- Byte-size comparison
Frequently asked questions
Is my code sent to a server?
No. Every calculation happens locally in your browser using JavaScript. Nothing you paste is uploaded, logged, or stored on a server, which makes the tool safe to use with production data, credentials, and customer records.
Is this the same as minification?
No. Minification shrinks code for performance and is trivially reversible into readable form. This tool renames local variables to meaningless names and encodes string literals so the logic is harder to skim — it is not encryption, and anything shipped to a browser can still be read and executed by whoever receives it. Need to shrink file size instead? Use the JavaScript Formatter / Minifier.
Can this break my code?
It is built on a real parser (not find-and-replace), so it understands scoping, shadowing, and destructuring correctly. As a safety margin it automatically leaves renaming off — and tells you why — for code that uses eval(), a with statement, or ES module import/export, since those can reference variables in ways a static rename cannot safely predict. Always test the output before deploying it.
Why do some variables keep their original name?
Only local variables are renamed — globals like console, Math, or window are left untouched because renaming them would break the code, not obscure it. Object property names and destructured keys are also left alone unless they are the bound variable itself.
Does this actually protect my source code?
No obfuscator does. Anything sent to a browser can be read, deobfuscated, or debugged by a determined person — this raises the effort required to skim the logic, it does not make it secret. Do not rely on obfuscation to hide API keys or secrets; those must never ship to the client at all.