Recipes
Opinionated, end-to-end walkthroughs for common obfuscation integration problems. Each recipe focuses on how to combine options to achieve a specific outcome rather than documenting individual options.
Pick the recipe that matches the problem you're trying to solve. More recipes will be added over time - if you've hit an integration scenario that isn't covered here, let us know and we'll write it up.
In this section
Best Practices
What to protect, what to leave alone, and what obfuscation cannot do for you.
HTML Obfuscation
Obfuscate inline scripts in HTML files with Parse HTML, and what stays untouched.
Host-side Template Substitution
Inject server-rendered values into VM-obfuscated JavaScript using reservedNames and reservedStrings.
Bytecode Array Encoding Key
Supply your own VM bytecode encryption key with vmBytecodeArrayEncodingKey and resolve it at runtime with a key getter - from client storage, or fetched from your backend.
VM Defense Telemetry & Reactions
Report VM defense detections to your backend with vmDefenseHook, and tune how each detection category reacts with vmDefenseReaction.
Hiding Function Names from LLM Analysis
Why VM-obfuscated code can leak meaningful function names to an LLM, and how an IIFE wrap removes the leak.
