Is this code safe?

Is this JavaScript safe?

Paste code before you run it. We'll explain what it does and flag suspicious behavior.

Examples:

Paste code on the left and press Check Code.

The scanner reports:

  • network requests and the hosts they contact
  • file reads, writes and deletions
  • shell command execution
  • code built and executed at runtime
  • access to cookies, credentials, clipboard and keystrokes
  • persistence, privilege changes and security tool tampering
  • encoded payloads and obfuscation

Findings are separated into capabilities (what the code can do) and suspicious behaviour (patterns typical of malicious scripts), because using the network is not the same as stealing data.

Static checks run locally in your browser. Nothing is uploaded, logged or stored.

Press Ctrl/Cmd + Enter to check.

How it works

Paste a snippet from a forum post, a browser console tip, an AI answer or a bookmarklet. The checker parses it into an abstract syntax tree and reports what the code can reach: the network, your cookies, browser storage, the clipboard and the page itself.

  1. The language is detected from the code, and you can override it in the dropdown.
  2. JavaScript and TypeScript are parsed into an abstract syntax tree, so function calls, imports and property accesses are matched structurally rather than as text. Python, PowerShell and shell are scanned with rules that first mask comments and string contents. HTML is scanned tag by tag, with inline scripts handed to the JavaScript analyzer.
  3. Findings are split into capabilities (what the code can do) and suspicious behaviour (patterns typical of malicious code).
  4. Behaviour chains are evaluated: reading cookies is one thing, reading cookies and posting them to a hardcoded host is another.
  5. A risk level is assigned, every finding links to its line, and you can optionally ask an AI model to explain the result in prose.

What it detects

  • fetch, axios, XMLHttpRequest, WebSocket and navigator.sendBeacon calls, with the hosts they contact
  • document.cookie, localStorage, sessionStorage and clipboard access
  • eval, new Function, setTimeout with a string, and indirect access such as window["ev"+"al"]
  • payloads decoded with atob, String.fromCharCode or Buffer.from and executed immediately
  • document-wide keydown listeners and selectors that target password fields
  • script and iframe elements injected with a remote src
  • Node APIs: child_process, fs reads and writes, process.env

Privacy: your code stays in your browser

The whole static analysis, including parsing, rule matching and risk scoring, is compiled into the page and runs on your machine. No request is made when you press Check Code, nothing is logged and nothing is stored. The only exception is the optional AI explanation: it is off by default, and when you tick the box the code is sent to the configured AI provider for that single request.

Why we never say "this code is safe"

Nobody can prove a piece of code is harmless by inspecting it. Code can fetch its real payload at runtime, behave differently on another machine, or hide its intent in a dependency you cannot see. So the verdict is always one of four: low apparent risk, potential risk, high risk, or unable to determine. "Low apparent risk" means these particular patterns are absent — nothing more.

Frequently asked questions

Does using fetch() mean the script is malicious?
No. Network access is a capability, not a verdict. It is reported so you can check which hosts are contacted and what is sent. The risk level only rises when network access is combined with something like reading cookies or executing a decoded payload.
Can it analyse minified or obfuscated JavaScript?
It parses minified code fine and still finds the dangerous calls. When the code is heavily obfuscated, the verdict becomes "unable to determine" rather than "low risk", because nobody can review it by reading it.
Does it handle TypeScript and JSX?
Yes. The parser accepts TypeScript syntax and JSX, so you can paste .ts and .tsx files unchanged.

Checkers by language