JavaScript Obfuscator
A quick, honest obfuscation pass: escaped strings and renamed identifiers, with property accesses protected.
Honest limits: this is light, reversible obfuscation — a speed bump for casual readers, not a security boundary.
Privacy: everything runs in your browser; your code never leaves this page.
How to use
- Paste your JavaScript into the input.
- Review the output and the counters (renamed identifiers, escaped strings).
- Test the result before shipping — and remember it is reversible, not security.
Frequently asked questions
What does "light obfuscation" mean here?
Two transformations: string literals are rewritten with \xNN hex escapes, and eligible identifiers are renamed to _0x0000-style names. It defeats the most casual skim-reading and keeps the code runnable, but it is reversible — treat it as a speed bump, never as security.
Why are some identifiers left alone?
The tool refuses to rename anything that also appears as a property access (user.name), an object key (name:), or inside brackets — renaming those would change behavior. It also skips template literals so ${} expressions keep working.
Will the output behave identically?
For the constructs this tool handles, yes — the transformation is purely lexical: strings decode to the same values and renamed identifiers point to the same bindings. Always test the output anyway; obfuscation is a code-changing operation.
How is this different from a real obfuscator?
Commercial obfuscators add control-flow flattening, dead-code injection and self-defending runtime checks. Those change program structure heavily; this tool deliberately stays light, fast and dependency-free.
Is my code uploaded anywhere?
No. Everything runs in your browser — nothing is sent to any server.