http://localhost, or an https:// address in a modern browser
(Chrome, Edge, Firefox, Safari). Protection is disabled here.
Encryption protects the source data while locked. Once the code is decrypted and executed inside a browser, a technically skilled user may be able to inspect runtime behavior. No client-side HTML protection can guarantee absolute secrecy against a determined attacker.
This tool uses real cryptography (PBKDF2-HMAC-SHA-256 + AES-256-GCM via the Web Crypto API) with a random salt and IV. It never stores your password and never embeds your plaintext source in the protected file. The right-click / copy / view-source / selection and DevTools options are deterrents only, not security boundaries.
Same rendering engine as the protected file. Close when you are done.