javascript-obfuscator
JavaScript obfuscator
100
Versions
BSD-2-Clause
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
sanex3339
Keywords
obfuscatorobfuscationuglifycrushcode protectionjavascript obfuscatorjs obfuscator
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:env-paths | AI (dependencies): env-paths is a well-known sindresorhus utility for OS standard paths; used here as a legitimate replacement for conf/mkdirp in path management. | ai | |
| source-diff | obfuscated-file:dist/index_debug.js | AI (source-diff): Webpack-bundled debug build of the obfuscator tool. Long lines are from bundling, not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:opencollective-postinstall | AI (phantom-deps): Referenced only in postinstall script, not imported in source. Expected pattern for opencollective integration. | ai | |
| source-diff | net-exec-file:dist/index_debug.js | AI (source-diff): A JS obfuscator tool inherently contains code-generation and eval patterns. Bundled dist file, not malicious. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs opencollective-postinstall, a benign funding message. Present across many versions of this package. | ai | |
| phantom-deps | phantom-dep:env-paths | AI (phantom-deps): env-paths is an explicit runtime dep; phantom detection is a false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:process | AI (phantom-deps): process is an explicit runtime dep used in the webpack bundle; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:assert | AI (phantom-deps): assert is an explicit runtime dep used in the webpack bundle; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a legitimate explicit runtime dep for a TypeScript-compiled webpack bundle; phantom detection is a false positive for this package. | ai |
Versions (showing 100 of 213)
| Version | Deps | Published |
|---|---|---|
| 1.2.0 | 21 / 40 | |
| 1.1.1 | 21 / 40 | |
| 1.1.0 | 21 / 40 | |
| 1.0.1 | 21 / 40 | |
| 1.0.0 | 21 / 40 | |
| 0.28.5 | 21 / 40 | |
| 0.28.4 | 21 / 40 | |
| 0.28.3 | 21 / 40 | |
| 0.28.2 | 21 / 40 | |
| 0.28.1 | 21 / 40 | |
| 0.28.0 | 22 / 40 | |
| 0.27.4 | 22 / 40 | |
| 0.27.3 | 22 / 40 | |
| 0.27.2 | 22 / 40 | |
| 0.27.1 | 22 / 40 | |
| 0.27.0 | 22 / 40 | |
| 0.26.0 | 22 / 40 | |
| 0.25.5 | 22 / 40 | |
| 0.25.4 | 22 / 40 | |
| 0.25.3 | 22 / 40 | |
| 0.25.2 | 22 / 40 | |
| 0.25.1 | 22 / 40 | |
| 0.25.0 | 22 / 40 | |
| 0.24.6 | 22 / 40 | |
| 0.24.5 | 22 / 40 | |
| 0.24.4 | 22 / 40 | |
| 0.24.3 | 23 / 34 | |
| 0.24.2 | 23 / 34 | |
| 0.24.1 | 23 / 34 | |
| 0.24.0 | 23 / 34 | |
| 0.23.2 | 19 / 34 | |
| 0.23.1 | 19 / 34 | |
| 0.23.0 | 19 / 34 | |
| 0.22.1 | 19 / 34 | |
| 0.22.0 | 19 / 34 | |
| 0.21.0 | 19 / 34 | |
| 0.20.4 | 19 / 34 | |
| 0.20.3 | 19 / 34 | |
| 0.20.2 | 18 / 34 | |
| 0.20.1 | 18 / 34 | |
| 0.20.0 | 18 / 34 | |
| 0.19.4 | 19 / 39 | |
| 0.19.3 | 19 / 39 | |
| 0.19.2 | 19 / 39 | |
| 0.19.1 | 19 / 39 | |
| 0.19.0 | 19 / 39 | |
| 0.18.8 | 19 / 39 | |
| 0.18.7 | 18 / 39 | |
| 0.18.6 | 18 / 39 | |
| 0.18.5 | 18 / 39 | |
| 0.18.4 | 18 / 39 | |
| 0.18.3 | 18 / 39 | |
| 0.18.1 | 18 / 39 | |
| 0.18.0 | 18 / 39 | |
| 0.17.3 | 18 / 39 | |
| 0.17.2 | 18 / 39 | |
| 0.17.1 | 18 / 39 | |
| 0.17.0 | 18 / 39 | |
| 0.16.0 | 19 / 38 | |
| 0.15.0 | 19 / 38 | |
| 0.14.3 | 17 / 35 | |
| 0.14.2 | 17 / 35 | |
| 0.14.1 | 17 / 35 | |
| 0.14.0 | 17 / 35 | |
| 0.13.0 | 16 / 34 | |
| 0.12.5 | 16 / 34 | |
| 0.12.4 | 16 / 34 | |
| 0.12.3 | 16 / 34 | |
| 0.12.2 | 16 / 33 | |
| 0.12.1 | 16 / 33 | |
| 0.12.0 | 16 / 34 | |
| 0.11.2 | 16 / 33 | |
| 0.11.1 | 16 / 33 | |
| 0.11.0 | 16 / 33 | |
| 0.10.2 | 15 / 32 | |
| 0.10.1 | 15 / 32 | |
| 0.10.0 | 15 / 31 | |
| 0.9.4 | 12 / 28 | |
| 0.9.3 | 12 / 28 | |
| 0.9.2 | 12 / 28 | |
| 0.9.1 | 13 / 29 | |
| 0.9.0 | 13 / 29 | |
| 0.8.6 | 10 / 27 | |
| 0.8.5 | 10 / 27 | |
| 0.8.4 | 10 / 27 | |
| 0.8.3 | 10 / 27 | |
| 0.8.2 | 10 / 27 | |
| 0.8.1 | 10 / 27 | |
| 0.8.0 | 10 / 27 | |
| 0.7.3 | 10 / 27 | |
| 0.7.2 | 10 / 27 | |
| 0.7.1 | 10 / 27 | |
| 0.7.0 | 10 / 27 | |
| 0.6.2 | 5 / 8 | |
| 0.6.1 | 5 / 8 | |
| 0.6.0 | 3 / 11 | |
| 0.5.4 | 4 / 2 | |
| 0.5.3 | 4 / 2 | |
| 0.5.2 | 4 / 2 | |
| 0.5.1 | 4 / 2 |
Showing 100 of 213
Next page →