Security · Concept

Obfuscation

Deliberately making shipped code hard for people to read, by renaming, scrambling and hiding parts of it, so copying or tampering takes more effort. It slows reverse engineering but never stops it.

Testing and research · Open source · updated

How it works

On Android, R8 shrinks a release build and renames classes and methods to short, meaningless names, keeping a mapping file that turns crash reports back into real names (Play Console and crash reporters accept it). JavaScript minifiers such as Terser, esbuild and SWC shorten names and strip whitespace, mainly to save size. Heavier tools such as javascript-obfuscator and commercial protectors (DexGuard and iXGuard from Guardsquare, Jscrambler) add encrypted strings, scrambled control flow and checks that detect tampering or debuggers.

Obfuscation raises the cost of copying code or finding weak spots, and it hides business logic from casual inspection. It does not hide secrets: an API key inside an app can be pulled out however well the code is scrambled, so secrets stay on a server. Heavy obfuscation also costs size, speed and debugging time. Publishing source maps undoes minification, so they are usually uploaded privately to an error tracker instead.

Obfuscation pricing

Open source

R8, ProGuard and javascript-obfuscator are free and open source. Commercial protectors such as Guardsquare's DexGuard and iXGuard are priced on request.

Obfuscation pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost

More in Security

Testing and research

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.