atilla@ubuntu:~/$ unmapjs --help
_ _ _ __ _ __ ___ __ _ _ __ (_)___
| | | | '_ \| '_ ` _ \ / _` | '_ \| / __|
| |_| | | | | | | | | | (_| | |_) | \__ \
\__,_|_| |_|_| |_| |_|\__,_| .__// |___/
|_| |__/
github: @atiilla
usage: unmapjs [-h] [--version] --url URL [-o OUTPUT] [--include-node-modules] [--concurrency CONCURRENCY] [--pages FILE] [--verbose]
Recover source files from any web app via sourcemaps
options:
-h, --help show this help message and exit
--version show program's version number and exit
--url URL Target site URL (e.g., example.com or https://example.com)
-o OUTPUT, --output OUTPUT
Output directory (default: ./recovered-source)
--include-node-modules
Include files from node_modules (default: skip)
--concurrency CONCURRENCY
Number of parallel download threads (default: 10)
--pages FILE File with extra paths to probe, one per line (e.g., pages.txt)
--verbose Enable verbose output
CLI to unpack your js source maps to original files and folders.
unmapjs automatically discovers, downloads, and extracts original source code from JavaScript source maps exposed by React, Next.js, Vite, Webpack, Rollup, and Turbopack applications.
Features
- Discovers JS chunks and sourcemap references from any URL
- Supports Next.js
_buildManifest, Webpack, Vite, Rollup, and Turbopack prefixes - Recursively follows chunk references to find all sourcemaps
- Parallel downloads with configurable concurrency
- Animated progress bars and spinners
- Custom page list support (
--pages pages.txt) for targeted discovery - Filters out
node_modulesby default - Path traversal protection on extracted files
Installation
pip install unmapjs
Or install from source:
git clone https://github.com/atiilla/unmapjs.git
cd unmapjs
pip install .
Usage
unmapjs --url example.com
unmapjs --url https://example.com -o ./output --verbose
With a custom pages file:
unmapjs --url example.com --pages pages.txt
Where pages.txt contains paths to probe (one per line, lines starting with # are ignored):
# auth pages
/login
/signup
/forgot-password
# app routes
/dashboard
/settings
/api/docs
Options
| Flag | Description | Default |
|---|---|---|
--url |
Target site URL | required |
-o, --output |
Output directory | ./recovered-source |
--concurrency |
Parallel download threads | 10 |
--pages FILE |
File with extra paths to probe, one per line | |
--include-node-modules |
Include node_modules files |
false |
--verbose |
Enable verbose output | false |
--version |
Show version |
How It Works
- Discover — Fetches the target URL and common pages (
/login,/signup,/dashboard, etc.) to find JS/CSS chunk references - Download chunks — Downloads all discovered chunks and extracts
sourceMappingURLreferences - Download sourcemaps — Fetches all referenced
.mapfiles - Extract — Unpacks original source files from
sourcesContentand writes them to disk with their original directory structure
Supported Bundlers
| Bundler | Prefix |
|---|---|
| Webpack | webpack:/// |
| Next.js (Webpack) | webpack:///_N_E/ |
| Turbopack | turbopack:///[project]/ |
| Vite | vite:/// |
| Rollup | rollup:/// |
Disclaimer
This tool is intended for authorized security testing, bug bounty research, and educational purposes only. Only use it on applications you have permission to test. The author is not responsible for any misuse.
License
MIT
Metadata
Release files for unmapjs 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| unmapjs-1.0.0.tar.gz | 10.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| unmapjs-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 22.0 kB
Release files / unmapjs-1.0.0.tar.gz
| Download URL | unmapjs-1.0.0.tar.gz |
|---|---|
| Size | 10.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
824dd38f22c07eeb85725cd63ec54833368bb2912ef0bb67e2a751138b407414
|
|
BLAKE2b-256 checksum How to use checksums |
4bda6bb781281d9526157d99465720458ace0c5b944c50161a6dfef3e77e3398
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.3
|
Release files / unmapjs-1.0.0-py3-none-any.whl
| Download URL | unmapjs-1.0.0-py3-none-any.whl |
|---|---|
| Size | 11.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c1b83a0c27e7925627109926476472014660d2b48542bf84fe36325f6027e19e
|
|
BLAKE2b-256 checksum How to use checksums |
01dc47d4d986e84b0d4300e6bc69516c645fb1fc86d48f1d93771157a35ebeff
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.12.3
|