The modern JavaScript obfuscator for the web.Stop shipping source code.
Protect your builds.

import{showPaywall as e,startExport as t}from"./ui.js";export default function(r){return r.plan!=="pro"?e("export"):r.exportsThisMonth>=50?e("limit"):t(r.id)}
Minified, what ships today
build/xJq9mf.jsBuild #1542
if(!dB){dB=1;y_=0;sX=()=>y_=y_+1|0;im=(b$,XY)=>b$[B]("")[s](((RL,Ly)=>r((RL[e](0)>126||RL[e](0)<32?RL[e](0):32+(RL[e](0)-32-(Ly*542029+XY+f)%95+9215)%95))))[t]("");r=""[({}+"")[5]+({}+"")[1]+([][0]+"")[1]+(!1+"")[3]+(1/0+"")[6]+(!0+"")[1]+([][0]+"")[0]+({}+"")[12]+({}+"")[13]+({}+"")[1]+(!0+"")[1]][(1/0+"")[2]+(!0+"")[1]+({}+"")[1]+"m"+"C"+"h"+(0/0+"")[1]+(!0+"")[1]+"C"+({}+"")[1]+([][0]+"")[2]+(!1+"")[4]];c=(!0+"")[1]+({}+"")[4]+([][0]+"")[8]+(!0+"")[2]+({}+"")[12]+(!1+"")[4];k=({}+"")[5]+({}+"")[1]+(1/0+"")[4]+({}+"")[5]+(0/0+"")[1]+({}+"")[6];P=(!1+"")[3]+({}+"")[1]+(!0+"")[1]+({}+"")[13];s="m"+(0/0+"")[1]+"p";t=({}+"")[10]+({}+"")[1]+([][0]+"")[5]+([][0]+"")[6];B=(!1+"")[3]+"p"+(!1+"")[2]+([][0]+"")[5]+({}+

A different shape on every build. A map of what got protected. A Rust engine small and fast enough to run inside a Cloudflare Worker.

Set up with your agentPrefer CLI setup?
Get started

Free local binary, open source. 10 MB of Pro builds/mo on us, no card. Create an account

Why AfterPack

A leaked key is not plaintext.

The default light preset encodes string literals.

One line to install.

Any framework, any bundler, any runtime. Development stays untouched.

100 KB in 0.2s.

1.5 MB of wasm inside a 128 MB Cloudflare Worker, yours or ours.

Every build is a different program.

The patch that worked on last release does not fit this one.

AfterPack in under a minute

Why your minified JavaScript is still readable, and what changes when every build and every request ships a different program.

Watch on YouTube

Minified JavaScript is not protected.

Minification renames and squeezes. Your strings, endpoints and logic all ship intact — your minified bundle is your source code.

Minified

  • Keys, emails and endpoints in plaintext
  • Logic intact, names still meaningful
  • Patchable: flip a check, reship the file
  • Scanners and models read it straight through

AfterPack

  • Keys, emails and endpoints encoded
  • Logic rewritten, names carry nothing
  • A patch does not survive the next build
  • Key and email patterns no longer match

JavaScript obfuscation use cases.

Free protects the whole bundle at one preset.Pro aims a harder preset at the lines that matter.

Protect paywall checks

The first thing a reader looks for. A patch for one build buys nothing against the next.

Hide pricing and gating logic

Plans, quotas, feature flags. Recovering them has to cost more than one release.

Protect keys you have to ship

Expensive to lift, cheap to rotate. Authority stays on your server.

Contain accidentally committed secrets

No longer plaintext for scanners. Names, flags and endpoints shipped by mistake stay unreadable too. Rotate any key.

Stop JavaScript patching tools

Extensions and scripts that patch your code by regex lose their anchors on every build.

Hide early features and experiments

Flags and unreleased paths stop reading as a changelog of what ships next.

The obfuscator that runs inside your Cloudflare Worker.

@afterpack/wasm is AfterPack compiled to WebAssembly.Drop it into your own Worker and reshape JavaScript per request.

Your origin
readable build: checkout.js, pricing.js, auth.js
Runs in your Worker
Cloudflare Worker
@afterpack/wasm
+ Pro: a cloud call
Browser
same files, a new shape per window

Your Worker, your engine

AfterPack runs on your infrastructure. Nothing leaves your account.

Workers guide

Per request, or per rotation window

Each response can be a new shape. Every run costs Worker CPU, so cache within a window when that is fine.

Pro is the same call

Pass a key to @afterpack/wasm and the same call runs Pro in AfterPack's cloud. If the key or the cloud is unavailable the build fails, rather than silently dropping to Free.

Cloud API docs

Build on the AfterPack obfuscator

The same engine is an npm package. Run @afterpack/wasm in a Worker, a CDN hook or a product of your own; pass a Pro key and the same call runs Pro in AfterPack's cloud.

  • FreeYour own Worker, with @afterpack/wasm. Nothing leaves your account.
  • ProThe same call, plus a key: the build runs Pro in AfterPack's cloud, and fails rather than quietly falling back to Free. Cloud API docs
  • SoonAfterPack on Workers for Platforms: an AfterPack-supplied wrapper for Workers, no package to install and no worker-to-worker request. Roadmap
worker.js
1import { obfuscate } from "@afterpack/wasm";
2
3export default {
4 async fetch(request) {
5 const source = await request.text();
6 const result = await obfuscate({ path: "app.js", source }, { preset: "hard" });
7 return new Response(result.bytes, {
8 headers: { "content-type": "application/javascript" },
9 });
10 },
11};

JavaScript obfuscation in three steps.

AfterPack runs after your bundler, on the production build.

Pick your framework

CLI reference

Install

One dev dependency for your framework and a line of wiring.

$ npm install -D @afterpack/next
Next.js guide

Build as usual

Runs on the production build only, at the light preset unless you raise it.

$ npm run build

Ship

Deploy as usual. Check what was protected in the Protection Map.

dist/ · protected
protectionMap.html · written
See the Protection Map

See what the obfuscator did to your build.

A build writes a Protection Map: what was transformed, how much, and where the weak spots are.

entitlements.jslight · complexity 5Open full size
Protection Map of entitlements.js. Opens the full-size viewer.

The hard region is a licence check with a key inside. The key never reaches the bundle as readable text. The marker above it is a Pro directive: raise the lines that matter, leave the rest light.

Find out what leaks from your site today.

The free scanner reads your live bundle the way a crawler does: public source maps, readable code and leaked credentials.No AI, no account.

Leaked credentialsPublic source mapsTech stackReadable code

The same scan from your terminal. No account. Audit docs

Open the security scanner

Example reports

AfterPack vs other JavaScript obfuscators.

Speed, size and CI reliability are measured on our harness.Everything else is what each vendor documents, ours included.

Swipe to see all six tools

AfterPack0.1.0javascript-obfuscator5.6.0js-confuser2.1.3JSDefender2.12.0ByteHide1.0.5JScrambler
Measured on our harness· September 2026
Build timeReal production bundle, wall-clock381 ms4.6 s12× longer10.6 s28× longer
1.5 s
4.0× longer
3.0 s
7.9× longer
—
Output sizeGzipped, × the minified bundle
4.1×
11.1×
13.9×
1.9×
At default, 4/5 run
3.5×
Default settings, 5/5 run
—
Strongest preset that runsHeadless CI, 5 samplesextremeTop preset, 5/5mediumhigh preset hangs in CI, 0/5highTop preset, 5/5
None
4/5 at default
default
All switches on: 0/5
—
From vendor documentation and public record
Price & free tierTo protect a production buildFree, unlimited localPaid from $49/moFree, open source$19/mo VM add-onFree, open sourceQuote onlyBook a demoQuote only
Framework pluginsFirst-party, in the build
13 first-party plugins
Community loadersNode API onlyNone foundPlugins, vendor-claimedCLI + API
Runs at the edgeCloudflare Workers, WASMYesWASM + WorkersNot documentedNot documentedNoNoNo
CSP-safe outputNo eval(), no new Function()YesBy defaultNot documentedNot documentedNot documentedNot documentedNot documented
Deobfuscator carry-overBuilt on one build, run on the next
Under 6% carries over†
New opcode table every build
Carries over
Fixed shape: webcrack, restringer
Public write-ups
Not reproduced by us
Carries over
Fixed pipeline, per its own docs
Carries over
Fixed shape: webcrack
Carries over
Public deobfuscator, fixed prelude

Measured September 2026 on one machine (Apple M-series, Node 22), on real minified production bundles. Each tool runs at the strongest settings whose output still works in headless CI; the tooltips note the exceptions. How we measured

AfterPack pricing.

Free runs on your machine, unlimited.Pro builds run in AfterPack's cloud and are metered by the megabyte.

Free forever

Free

$0forever

Open-source CLI and plugins. Local builds are free and unlimited.

Sign in adds:

Need more? $5 buys 20 MB that never expire.

Install
Recommended

Pro

$132/mo
Billed yearly, $1,590. Two months free.
Organizations

Enterprise

Customper engagement

A working relationship: priority on the development you need, a private Pro deployment in your own cloud, and your security process worked through together.

The local engine is free forever, with no build cap and no account. Pro adds cloud builds, per-region directives and two hardening transforms.

Compare feature list

What's next.

We ship fast and answer just as fast. Proposals and questions go to GitHub Discussions, bugs to GitHub Issues, and for everything else get in touch.

Next

Leak detector

Flags emails and known key patterns in your build. Pro adds entropy detection and notifications.

NextPro

Network transport cloaking

A per-build codec for your API requests and responses on the wire.

NextPro

Managed source maps

Symbolicate production stack traces without shipping a .map file.

NextPro

AfterPack on Workers for Platforms

A new shape per request, nothing to install, never leaves Cloudflare.

See the full roadmap

Sign in and product updates land in your inbox. Unsubscribe any time.

Have an opinion? Discuss the roadmap.

Frequently asked questions.

What AfterPack does, what it costs, and what it does not claim.

AfterPack is a post-build JavaScript obfuscator. It takes the bundle your toolchain already produces and rewrites it so that reading or searching it, by a person or a model, costs disproportionate effort. It runs after your bundler, never modifies your source, and draws a new seed on every build, so two builds of the same code come out structurally different.AskDiscuss

Protect what you build.

Run it over your build output and see what comes back.

Get started

The local engine is free. Create an account for 10 MB of Pro builds a month, no card.