Documentation
/

VM Obfuscation

VM Obfuscation

Highest Security

VM obfuscation transforms your JavaScript functions into custom bytecode that runs on a virtual machine embedded in the output, so the protected logic no longer ships as readable JavaScript.

VM protection applies to eligible functions. In root mode, vmWrapTopLevelInitializers can also wrap eligible initializers for virtualization; current VM presets enable it. Review coverage warnings such as VMNoFunctionsToVirtualize, and use comment mode to select sensitive functions explicitly.

Obfuscation raises the cost of reverse engineering without making it impossible, so keep secrets and authoritative security decisions on the server - see Best Practices for what obfuscation can and cannot guarantee.

Need help? If VM obfuscation misbehaves, see Diagnosing VM Runtime Errors for how to narrow it down and file a bug report.

In this section