New:Microsoft Teams Notifications Are Now Available in Socket.Learn more
Get Started

@stll/anonymize-wasm

Package Overview
Dependencies
Maintainers
1
Versions
56
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@stll/anonymize-wasm

PII detection and anonymization for browsers via WebAssembly. Same native SDK API as @stll/anonymize.

Source
npmnpm
Version
2.8.1
Version published
Weekly downloads
4.5K
-31.65%
Maintainers
1
Weekly downloads
 
Created
Source

@stll/anonymize-wasm

Browser-friendly build of @stll/anonymize.

Use this package when you need the runtime API in a browser or bundler environment. It ships the WebAssembly build and the Vite helper that keeps the wasm assets out of dependency pre-bundling.

Install

bun add @stll/anonymize-wasm

Usage

The package exposes text, sessions, caller detections, PDF inspection, and prepared-package/config assembly through WebAssembly. Native filesystem loaders and local document-provider tools remain Node-only. The binding is instantiated lazily on first use.

import { loadDefaultPipeline } from "@stll/anonymize-wasm";

// Loads the compressed default package bundled in the tarball.
const pipeline = await loadDefaultPipeline();
const { redaction } = pipeline.redactText("A contract signed by Jan Novak.");
console.log(redaction.redactedText);

Bring your own prepared package (bytes, an ArrayBuffer, or a URL to fetch):

import { loadPipeline } from "@stll/anonymize-wasm";

const pipeline = await loadPipeline(
  new URL("./my-package.stlanonpkg", import.meta.url),
);

With Vite, register the helper plugin so the wasm binary, ESM glue, and .stlanonpkg assets survive both dependency pre-bundling (dev) and a production vite build (the plugin emits the native/ assets and rewrites the runtime asset base to point at them):

import stllAnonymizeWasm from "@stll/anonymize-wasm/vite";
// vite.config: plugins: [stllAnonymizeWasm()]

By default the plugin emits every bundled prepared package into your build. The full-dictionary default package alone is large (~20 MB), plus the per-language cs, de, and en variants. If your app only needs some of them, restrict the emitted packages with the packages option (the wasm binary and glue are always emitted):

// Emit only the Czech scoped package.
stllAnonymizeWasm({ packages: ["cs"] });

// Emit the full-dictionary default plus English.
stllAnonymizeWasm({ packages: ["default", "en"] });

// Emit no prepared packages; the app supplies its own to loadPipeline().
stllAnonymizeWasm({ packages: "none" });

// Emit everything (the default).
stllAnonymizeWasm({ packages: "all" });

"default" selects the full-dictionary package that loadDefaultPipeline() (no argument) loads; a language code selects the scoped package that loadDefaultPipeline("cs") loads. Requesting a package that is not bundled fails the build.

Interplay with the runtime loaders: the plugin only controls which assets ship, not which the code asks for. Calling loadDefaultPipeline(language) for a package you did not emit resolves to a missing asset URL and rejects with a fetch error at runtime. Keep the packages list aligned with the languages your app actually loads, or load your own package bytes through loadPipeline.

Notes

  • Same redaction core as @stll/anonymize, running in WebAssembly.
  • The binding targets single-thread wasm32-unknown-unknown. It runs in ordinary browser contexts without SharedArrayBuffer, Web Workers, COOP, or COEP.

Third-party licenses

See the package's LICENSE and the repository root ATTRIBUTION.md for dependency attribution.

Building from source

The wasm binding is generated by wasm-bindgen and is not checked in:

cd packages/anonymize
bun run build:native-wasm   # needs the wasm32-unknown-unknown Rust target
bun run build               # tsdown + native node binding
bun run build:wasm-assets   # copy glue + build compressed packages into wasm/dist/native

The wasm32-unknown-unknown target is pinned in rust-toolchain.toml, so rustup installs it automatically; with a non-rustup toolchain run rustup target add wasm32-unknown-unknown first.

Keywords

anonymization

FAQs

Package last updated on 21 Aug 2026

Related posts