Documentation
/
Recipes
/

Best Practices

Best Practices

How to apply obfuscation effectively: what to protect, what to leave alone, and what obfuscation cannot do for you.

Recommendations

  • Only obfuscate your own code.

    Don't VM-obfuscate vendor scripts, libraries, or polyfills. They're already minified and obfuscation will just slow them down.

  • Use comment mode for surgical protection.

    Set vmTargetFunctionsMode to 'comment', then mark only the sensitive functions with /* javascript-obfuscator:vm */ instead of protecting everything. See Targeting Specific Functions.

  • Test thoroughly after obfuscation.

    Always test obfuscated code in your target environment. Some options can break code in subtle ways. Runtime defenses also react to test automation and debuggers; see Testing and CI.

  • Exclude hot paths from VM obfuscation.

    Use vmExcludeFunctions for animation loops, real-time rendering, or frequently called code. It only matches root-level function names (under Async Executor, the outermost async functions); to keep nested hot code out of the VM, use comment mode and mark only the functions that need protection.

Critical security notice

Never store API keys, secrets, or credentials in frontend JavaScript code - even with obfuscation.

Obfuscation increases the effort needed to understand and modify code, but it is not encryption and cannot guarantee that reverse engineering is impossible. The runtime remains observable in an environment an attacker controls, so a determined attacker can always extract data from client-side code. Keep secrets and authoritative security decisions on the server.

In practice:

  • Store secrets on your backend server
  • Use environment variables server-side
  • Proxy API calls through your backend to hide keys
  • Use short-lived tokens issued by your server

What should you protect?

VM obfuscation is ideal for:

  • Proprietary algorithms and business logic
  • License validation code (client-side checks)
  • Anti-tampering and integrity checks
  • Game logic and anti-cheat mechanisms
  • Premium feature implementations
  • Pricing calculation logic

Build and release

Obfuscate your compiled, bundled output as the last build step; see Runtime Compatibility for the build pipeline. Measure the cost of the preset you choose on your own code, as described in Choosing Presets. Run functional tests against a testing build, then validate the separate release artifact you actually ship, as described in Testing and CI.