JavaScript Eval/Function Unpacker
Detect and unpack JavaScript code hidden inside eval(), new Function(), setTimeout(), and setInterval() calls. Recursively extracts nested eval layers up to 5 levels deep and shows the original code at each depth level — with severity ratings, line numbers, and extracted per-layer previews. Free, private, and no signup required.
Detect and unpack JavaScript code hidden inside eval(), new Function(), setTimeout(), and setInterval() calls. Recursively extracts nested eval layers and shows the original code at each depth level — perfect for deobfuscating packed scripts and analyzing malicious code. All processing runs locally in your browser with no data uploaded.
Paste JavaScript code containing eval(), new Function(), setTimeout(), or setInterval() with string arguments above, then click Unpack Code. Nested eval layers will be recursively extracted — up to 5 levels deep. Click Load example obfuscated code to try it.
Why Use Our JavaScript Eval/Function Unpacker?
Instant Eval/Function Detection & Unpacking
Instantly detect and unpack JavaScript code hidden inside eval(), new Function(), setTimeout(), and setInterval() calls. Our JS eval unpacker scans your code, identifies all dynamic code execution patterns, and extracts the hidden source — no manual searching or debugging needed.
Secure & Private Code Analysis
The JavaScript eval/function unpacker runs entirely in your browser. Your code, extracted strings, and analysis results never leave your device. No data uploaded, no tracking, no signup required — complete privacy for all your code analysis work.
Eval Unpacker Online - No Installation
Use the JS eval/function unpacker directly in any modern browser with no downloads, apps, or plugins required. Features a two-panel editor, recursive eval extraction up to 5 levels deep, and one-click unpacking with detailed pattern reports.
Recursive Nested Eval Extraction & Depth Analysis
Unlike basic search tools, our eval unpacker recursively extracts code from nested eval() calls — up to 5 levels deep. Each layer is individually identified, and the unpacked output shows what code was hidden inside each eval(), new Function(), or timer call with clear annotations.
Common Use Cases for JavaScript Eval/Function Unpacker
Analyzing Packed JavaScript with eval() Calls
Developers and security researchers use the JS eval unpacker to analyze JavaScript code that uses eval() to execute dynamically constructed strings. Paste the packed code to instantly extract and read the hidden code inside each eval() call, including deeply nested eval layers that traditional search tools would miss.
Malicious Code Analysis & Threat Detection
Cybersecurity professionals use the eval/function unpacker to analyze potentially malicious scripts. Attackers often hide payloads inside eval() calls, new Function() constructors, or setTimeout() string arguments to evade static analysis. The tool detects and extracts these hidden payloads, revealing the actual code being executed.
Reverse Engineering Obfuscated JavaScript
Reverse engineers use the eval unpacker to deobfuscate JavaScript code that uses runtime code generation. Many obfuscators pack their code as eval() strings or Function constructor calls. The tool extracts each layer and annotates the unpacked code with clear markers showing where it was hidden.
Debugging Dynamically Generated Code
Frontend developers debug dynamically generated JavaScript by using the eval unpacker to see what code is actually being executed. When third-party libraries or frameworks use eval() or new Function() internally, the tool reveals the generated code, making it easier to trace bugs and understand unexpected behavior.
Vulnerability Research & Code Audit
Security auditors use the JavaScript eval/function unpacker during code audits to identify unsafe uses of eval() and related patterns. The tool highlights all dynamic code execution calls, their severity levels, and nesting depth — helping auditors assess the risk profile and identify code that should be refactored for security.
Learning About JavaScript Code Execution Patterns
Students and developers learning about JavaScript security use the eval unpacker to understand how eval(), new Function(), and timer-based code execution work. The pattern detection report shows real-world examples of each technique, making it easy to see how dynamic code execution is used — and abused — in practice.
Understanding JavaScript Eval/Function Unpacking
What is JavaScript Eval/Function Unpacking?
JavaScript eval/function unpacking is the process of extracting and revealing code that is executed dynamically through JavaScript's eval(),new Function(), setTimeout(), and setInterval() functions. These functions accept JavaScript code as string arguments and execute it at runtime, making the code invisible to static analysis tools and casual inspection.
Obfuscators and malicious scripts commonly use these techniques to hide their true functionality. Code passed to eval() can itself contain moreeval() calls, creating nested layers that must be recursively unwrapped. Our JavaScript eval/function unpacker automatically detects all four patterns, extracts the hidden code from each, and recursively processes up to 5 nesting levels to fully unpack the obfuscated code.
How Our JavaScript Eval/Function Unpacker Works
- 1. Paste & Scan: Paste your obfuscated JavaScript code into the input panel. The unpacker scans every character for four specific patterns:
eval()calls with string arguments,new Function()constructors with code strings,setTimeout()calls with string code, andsetInterval()calls with string code. Each match is recorded with its line number, severity level, and nesting depth. - 2. Recursive Extraction: When an
eval()or other dynamic call contains code that itself uses furthereval()calls, the unpacker recursively processes the extracted code — up to 5 levels deep. Each layer is independently identified and extracted. For example,eval("eval('code')")is unpacked as two separate layers, with level 1 containing the outer call and level 2 containing the inner code. - 3. Review & Export: The unpacked code appears in the output panel with inline annotations showing what was extracted and from where. Statistics show total detections, types found, max nesting depth, and size comparison. The pattern details table lists every match with its severity, line number, and nesting depth. Expand extracted code per layer to see the hidden code at each depth level. Copy or download the fully unpacked result.
Detected Patterns & Security Implications
- eval() Calls (High Severity):
eval(string)executes arbitrary JavaScript code passed as a string. This is the most commonly abused pattern in obfuscated and malicious scripts because it can execute any code at runtime. It also has significant performance and security implications — eval can access the local scope, making it particularly dangerous. - new Function() Constructor (High Severity):
new Function('return ...')creates a new function from a string. While slightly safer than eval (it executes in the global scope, not local), it is still widely used for obfuscation. The Function constructor is often used in multi-layer obfuscation to build and execute code strings without triggering eval detectors. - setTimeout/setInterval String Arguments (Medium Severity): Passing strings to
setTimeout()orsetInterval()is an anti-pattern that also enables code obfuscation. While less common in production code, malicious scripts sometimes use timer functions with string code to delay execution or evade timing-based detection heuristics.
Privacy, Security & Availability
The JavaScript eval/function unpacker is 100% free with no signup required. All code analysis is performedlocally in your browser using JavaScript pattern matching — your obfuscated code, extracted strings, and analysis resultsnever leave your device. There areno file size limits or usage caps. The tool detects up to 5 nesting levels of eval, Function constructor, setTimeout, and setInterval patterns, provides detailed per-layer extraction views, and includes copy-to-clipboard and download functionality. Use it as many times as you need to unpack obfuscated JavaScript code.
Frequently Asked Questions About JavaScript Eval/Function Unpacker
A JavaScript eval/function unpacker is a tool that detects and extracts code hidden inside eval(), new Function(), setTimeout(), and setInterval() calls. These functions execute JavaScript code passed as string arguments at runtime, making the code invisible to static analysis. The unpacker automatically finds these patterns, extracts the hidden code, and recursively processes nested eval layers up to 5 levels deep.
The eval/function unpacker detects four patterns: eval() calls with string arguments (e.g., eval("code")), new Function() constructors with code strings (e.g., new Function("return ...")), setTimeout() calls with string code (e.g., setTimeout("code", delay)), and setInterval() calls with string code (e.g., setInterval("code", interval)). Each pattern is identified by its severity level, line number, and nesting depth.
When an eval() call contains code that itself contains eval() calls, the unpacker recursively processes the extracted code to unpack the inner layers. For example, if you have eval("var x = 1; eval('var y = 2');"), the tool first extracts the outer code (var x = 1; eval('var y = 2');) and then processes that extracted code to find and extract the inner eval() as a second layer. This continues up to 5 nesting levels.
Absolutely. The JavaScript eval/function unpacker runs entirely in your browser. Your obfuscated code, extracted strings, and analysis results never leave your device. All processing happens locally on your computer — nothing is uploaded to any server, stored in a database, or tracked in any way.
Both eval() and new Function() execute code from strings, but they differ in scope. eval() executes code in the current local scope and can access local variables, making it more dangerous and easier to detect. new Function() creates a function that executes in the global scope, so it cannot access local variables but is still capable of executing arbitrary code. Our unpacker detects both patterns and assigns high severity to each.
Passing strings to setTimeout/setInterval is considered a JavaScript anti-pattern because it has the same security implications as eval() — it executes arbitrary code from strings. Obfuscated or malicious code uses this technique to hide code execution behind timer functions, often to delay execution, evade detection, or make the code more difficult to analyze statically.
Yes. The unpacker recursively processes eval(), new Function(), setTimeout(), and setInterval() calls up to 5 levels deep. Each extracted layer is independently identified, annotated with its depth level and source location, and displayed in the pattern details table. If the code has more than 5 nesting levels, additional passes may be needed to fully unpack it.
Yes. Security researchers, penetration testers, and malware analysts use the JavaScript eval/function unpacker to analyze obfuscated scripts that use dynamic code execution. The severity rating helps prioritize findings, and the per-layer extraction view makes it easy to trace through multiple levels of obfuscation to find the ultimate payload or functionality.
Yes — the JavaScript eval/function unpacker is 100% free with no signup, no account, and no usage limits. Unpack any obfuscated JavaScript code as many times as you need, completely free forever. There are no hidden charges, premium tiers, or usage caps of any kind.