The modern JavaScript obfuscator for the web.Stop shipping source code.
Protect your builds.
import{showPaywall as e,startExport as t}from"./ui.js";export default function(r){return r.plan!=="pro"?e("export"):r.exportsThisMonth>=50?e("limit"):t(r.id)}if(!dB){dB=1;y_=0;sX=()=>y_=y_+1|0;im=(b$,XY)=>b$[B]("")[s](((RL,Ly)=>r((RL[e](0)>126||RL[e](0)<32?RL[e](0):32+(RL[e](0)-32-(Ly*542029+XY+f)%95+9215)%95))))[t]("");r=""[({}+"")[5]+({}+"")[1]+([][0]+"")[1]+(!1+"")[3]+(1/0+"")[6]+(!0+"")[1]+([][0]+"")[0]+({}+"")[12]+({}+"")[13]+({}+"")[1]+(!0+"")[1]][(1/0+"")[2]+(!0+"")[1]+({}+"")[1]+"m"+"C"+"h"+(0/0+"")[1]+(!0+"")[1]+"C"+({}+"")[1]+([][0]+"")[2]+(!1+"")[4]];c=(!0+"")[1]+({}+"")[4]+([][0]+"")[8]+(!0+"")[2]+({}+"")[12]+(!1+"")[4];k=({}+"")[5]+({}+"")[1]+(1/0+"")[4]+({}+"")[5]+(0/0+"")[1]+({}+"")[6];P=(!1+"")[3]+({}+"")[1]+(!0+"")[1]+({}+"")[13];s="m"+(0/0+"")[1]+"p";t=({}+"")[10]+({}+"")[1]+([][0]+"")[5]+([][0]+"")[6];B=(!1+"")[3]+"p"+(!1+"")[2]+([][0]+"")[5]+({}+A different shape on every build. A map of what got protected. A Rust engine small and fast enough to run inside a Cloudflare Worker.
Free local binary, open source. 10 MB of Pro builds/mo on us, no card. Create an account
Why AfterPack
A leaked key is not plaintext.
The default light preset encodes string literals.
One line to install.
Any framework, any bundler, any runtime. Development stays untouched.
100 KB in 0.2s.
1.5 MB of wasm inside a 128 MB Cloudflare Worker, yours or ours.
Every build is a different program.
The patch that worked on last release does not fit this one.
AfterPack in under a minute
Why your minified JavaScript is still readable, and what changes when every build and every request ships a different program.
Minified JavaScript is not protected.
Minification renames and squeezes. Your strings, endpoints and logic all ship intact — your minified bundle is your source code.
Minified
- Keys, emails and endpoints in plaintext
- Logic intact, names still meaningful
- Patchable: flip a check, reship the file
- Scanners and models read it straight through
AfterPack
- Keys, emails and endpoints encoded
- Logic rewritten, names carry nothing
- A patch does not survive the next build
- Key and email patterns no longer match
JavaScript obfuscation use cases.
Free protects the whole bundle at one preset.Pro aims a harder preset at the lines that matter.
Protect paywall checks
The first thing a reader looks for. A patch for one build buys nothing against the next.
Hide pricing and gating logic
Plans, quotas, feature flags. Recovering them has to cost more than one release.
Protect keys you have to ship
Expensive to lift, cheap to rotate. Authority stays on your server.
Contain accidentally committed secrets
No longer plaintext for scanners. Names, flags and endpoints shipped by mistake stay unreadable too. Rotate any key.
Stop JavaScript patching tools
Extensions and scripts that patch your code by regex lose their anchors on every build.
Hide early features and experiments
Flags and unreleased paths stop reading as a changelog of what ships next.
The obfuscator that runs inside your Cloudflare Worker.
@afterpack/wasm is AfterPack compiled to WebAssembly.Drop it into your own Worker and reshape JavaScript per request.
Your Worker, your engine
AfterPack runs on your infrastructure. Nothing leaves your account.
Workers guidePer request, or per rotation window
Each response can be a new shape. Every run costs Worker CPU, so cache within a window when that is fine.
Pro is the same call
Pass a key to @afterpack/wasm and the same call runs Pro in AfterPack's cloud. If the key or the cloud is unavailable the build fails, rather than silently dropping to Free.
Cloud API docsBuild on the AfterPack obfuscator
The same engine is an npm package. Run @afterpack/wasm in a Worker, a CDN hook or a product of your own; pass a Pro key and the same call runs Pro in AfterPack's cloud.
- FreeYour own Worker, with @afterpack/wasm. Nothing leaves your account.
- ProThe same call, plus a key: the build runs Pro in AfterPack's cloud, and fails rather than quietly falling back to Free. Cloud API docs
- SoonAfterPack on Workers for Platforms: an AfterPack-supplied wrapper for Workers, no package to install and no worker-to-worker request. Roadmap
| 1 | import { obfuscate } from "@afterpack/wasm"; |
| 2 | |
| 3 | export default { |
| 4 | async fetch(request) { |
| 5 | const source = await request.text(); |
| 6 | const result = await obfuscate({ path: "app.js", source }, { preset: "hard" }); |
| 7 | return new Response(result.bytes, { |
| 8 | headers: { "content-type": "application/javascript" }, |
| 9 | }); |
| 10 | }, |
| 11 | }; |
JavaScript obfuscation in three steps.
AfterPack runs after your bundler, on the production build.
Pick your framework
Install
One dev dependency for your framework and a line of wiring.
$ npm install -D @afterpack/nextBuild as usual
Runs on the production build only, at the light preset unless you raise it.
$ npm run buildShip
Deploy as usual. Check what was protected in the Protection Map.
See what the obfuscator did to your build.
A build writes a Protection Map: what was transformed, how much, and where the weak spots are.
The hard region is a licence check with a key inside. The key never reaches the bundle as readable text. The marker above it is a Pro directive: raise the lines that matter, leave the rest light.
Find out what leaks from your site today.
The free scanner reads your live bundle the way a crawler does: public source maps, readable code and leaked credentials.No AI, no account.
The same scan from your terminal. No account. Audit docs
Open the security scannerExample reports
AfterPack vs other JavaScript obfuscators.
Speed, size and CI reliability are measured on our harness.Everything else is what each vendor documents, ours included.
Swipe to see all six tools
| AfterPack0.1.0 | javascript-obfuscator5.6.0 | js-confuser2.1.3 | JSDefender2.12.0 | ByteHide1.0.5 | JScrambler | |
|---|---|---|---|---|---|---|
| Measured on our harness· September 2026 | ||||||
| Build timeReal production bundle, wall-clock | 381 ms | 4.6 s12× longer | 10.6 s28× longer | 1.5 s 4.0× longer | 3.0 s 7.9× longer | — |
| Output sizeGzipped, × the minified bundle | 4.1× | 11.1× | 13.9× | 1.9× At default, 4/5 run | 3.5× Default settings, 5/5 run | — |
| Strongest preset that runsHeadless CI, 5 samples | extremeTop preset, 5/5 | mediumhigh preset hangs in CI, 0/5 | highTop preset, 5/5 | None 4/5 at default | default All switches on: 0/5 | — |
| From vendor documentation and public record | ||||||
| Price & free tierTo protect a production build | Free, unlimited localPaid from $49/mo | Free, open source$19/mo VM add-on | Free, open source | Quote only | Book a demo | Quote only |
| Framework pluginsFirst-party, in the build | 13 first-party plugins | Community loaders | Node API only | None found | Plugins, vendor-claimed | CLI + API |
| Runs at the edgeCloudflare Workers, WASM | YesWASM + Workers | Not documented | Not documented | No | No | No |
| CSP-safe outputNo eval(), no new Function() | YesBy default | Not documented | Not documented | Not documented | Not documented | Not documented |
| Deobfuscator carry-overBuilt on one build, run on the next | Under 6% carries over† New opcode table every build | Carries over Fixed shape: webcrack, restringer | Public write-ups Not reproduced by us | Carries over Fixed pipeline, per its own docs | Carries over Fixed shape: webcrack | Carries over Public deobfuscator, fixed prelude |
Measured September 2026 on one machine (Apple M-series, Node 22), on real minified production bundles. Each tool runs at the strongest settings whose output still works in headless CI; the tooltips note the exceptions. How we measured
AfterPack pricing.
Free runs on your machine, unlimited.Pro builds run in AfterPack's cloud and are metered by the megabyte.
Free
Open-source CLI and plugins. Local builds are free and unlimited.
- 10 MB of Pro builds every month, no card required
- 2 projects
- Dashboard with usage tracking and API keys
- Unlimited workspace members, no per-seat pricing
Need more? $5 buys 20 MB that never expire.
InstallPro
- Everything in Free
- 3 GB of Pro builds a month
- $0.12/MB past your 3 GB
- 5 projects
- Per-region directives
- Comparison hardening and self-integrity
- Stored Protection Maps and build history
- Build and bundle analytics
- Priority email support
Enterprise
A working relationship: priority on the development you need, a private Pro deployment in your own cloud, and your security process worked through together.
- Priority on custom development for your stack
- Private engine installation on GCP, AWS or your own cloud
- Security constraints and certifications worked through with your team
- 99.9% annual SLA, financially backed, with a named account manager
- GDPR DPA, security-posture documentation and a custom MSA
The local engine is free forever, with no build cap and no account. Pro adds cloud builds, per-region directives and two hardening transforms.
What's next.
We ship fast and answer just as fast. Proposals and questions go to GitHub Discussions, bugs to GitHub Issues, and for everything else get in touch.
Leak detector
Flags emails and known key patterns in your build. Pro adds entropy detection and notifications.
Network transport cloaking
A per-build codec for your API requests and responses on the wire.
Managed source maps
Symbolicate production stack traces without shipping a .map file.
AfterPack on Workers for Platforms
A new shape per request, nothing to install, never leaves Cloudflare.
Sign in and product updates land in your inbox. Unsubscribe any time.
Have an opinion? Discuss the roadmap.
Frequently asked questions.
What AfterPack does, what it costs, and what it does not claim.
Protect what you build.
Run it over your build output and see what comes back.
The local engine is free. Create an account for 10 MB of Pro builds a month, no card.

