How it works
On Android, R8 shrinks a release build and renames classes and methods to short, meaningless names, keeping a mapping file that turns crash reports back into real names (Play Console and crash reporters accept it). JavaScript minifiers such as Terser, esbuild and SWC shorten names and strip whitespace, mainly to save size. Heavier tools such as javascript-obfuscator and commercial protectors (DexGuard and iXGuard from Guardsquare, Jscrambler) add encrypted strings, scrambled control flow and checks that detect tampering or debuggers.
Obfuscation raises the cost of copying code or finding weak spots, and it hides business logic from casual inspection. It does not hide secrets: an API key inside an app can be pulled out however well the code is scrambled, so secrets stay on a server. Heavy obfuscation also costs size, speed and debugging time. Publishing source maps undoes minification, so they are usually uploaded privately to an error tracker instead.
Obfuscation pricing
Open source
R8, ProGuard and javascript-obfuscator are free and open source. Commercial protectors such as Guardsquare's DexGuard and iXGuard are priced on request.
Obfuscation pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost
Related terms
More in Security
Testing and research