Best Practices
How to apply obfuscation effectively: what to protect, what to leave alone, and what obfuscation cannot do for you.
Recommendations
Only obfuscate your own code.
Don't VM-obfuscate vendor scripts, libraries, or polyfills. They're already minified and obfuscation will just slow them down.
Use comment mode for surgical protection.
Set
vmTargetFunctionsModeto'comment', then mark only the sensitive functions with/* javascript-obfuscator:vm */instead of protecting everything. See Targeting Specific Functions.Test thoroughly after obfuscation.
Always test obfuscated code in your target environment. Some options can break code in subtle ways. Runtime defenses also react to test automation and debuggers; see Testing and CI.
Exclude hot paths from VM obfuscation.
Use
vmExcludeFunctionsfor animation loops, real-time rendering, or frequently called code. It only matches root-level function names (under Async Executor, the outermostasyncfunctions); to keep nested hot code out of the VM, use comment mode and mark only the functions that need protection.
Critical security notice
Never store API keys, secrets, or credentials in frontend JavaScript code - even with obfuscation.
Obfuscation increases the effort needed to understand and modify code, but it is not encryption and cannot guarantee that reverse engineering is impossible. The runtime remains observable in an environment an attacker controls, so a determined attacker can always extract data from client-side code. Keep secrets and authoritative security decisions on the server.
In practice:
- Store secrets on your backend server
- Use environment variables server-side
- Proxy API calls through your backend to hide keys
- Use short-lived tokens issued by your server
What should you protect?
VM obfuscation is ideal for:
- Proprietary algorithms and business logic
- License validation code (client-side checks)
- Anti-tampering and integrity checks
- Game logic and anti-cheat mechanisms
- Premium feature implementations
- Pricing calculation logic
Build and release
Obfuscate your compiled, bundled output as the last build step; see Runtime Compatibility for the build pipeline. Measure the cost of the preset you choose on your own code, as described in Choosing Presets. Run functional tests against a testing build, then validate the separate release artifact you actually ship, as described in Testing and CI.
