Skip to main content
atilla@ubuntu:~/$ unmapjs --help
 _   _ _ __  _ __ ___   __ _ _ __ (_)___
| | | | '_ \| '_ ` _ \ / _` | '_ \| / __|
| |_| | | | | | | | | | (_| | |_) | \__ \
 \__,_|_| |_|_| |_| |_|\__,_| .__// |___/
                            |_| |__/
      github: @atiilla

usage: unmapjs [-h] [--version] --url URL [-o OUTPUT] [--include-node-modules] [--concurrency CONCURRENCY] [--pages FILE] [--verbose]

Recover source files from any web app via sourcemaps

options:
  -h, --help            show this help message and exit
  --version             show program's version number and exit
  --url URL             Target site URL (e.g., example.com or https://example.com)
  -o OUTPUT, --output OUTPUT
                        Output directory (default: ./recovered-source)
  --include-node-modules
                        Include files from node_modules (default: skip)
  --concurrency CONCURRENCY
                        Number of parallel download threads (default: 10)
  --pages FILE          File with extra paths to probe, one per line (e.g., pages.txt)
  --verbose             Enable verbose output

CLI to unpack your js source maps to original files and folders.

unmapjs automatically discovers, downloads, and extracts original source code from JavaScript source maps exposed by React, Next.js, Vite, Webpack, Rollup, and Turbopack applications.

Features

  • Discovers JS chunks and sourcemap references from any URL
  • Supports Next.js _buildManifest, Webpack, Vite, Rollup, and Turbopack prefixes
  • Recursively follows chunk references to find all sourcemaps
  • Parallel downloads with configurable concurrency
  • Animated progress bars and spinners
  • Custom page list support (--pages pages.txt) for targeted discovery
  • Filters out node_modules by default
  • Path traversal protection on extracted files

Installation

pip install unmapjs

Or install from source:

git clone https://github.com/atiilla/unmapjs.git
cd unmapjs
pip install .

Usage

unmapjs --url example.com
unmapjs --url https://example.com -o ./output --verbose

With a custom pages file:

unmapjs --url example.com --pages pages.txt

Where pages.txt contains paths to probe (one per line, lines starting with # are ignored):

# auth pages
/login
/signup
/forgot-password
# app routes
/dashboard
/settings
/api/docs

Options

Flag Description Default
--url Target site URL required
-o, --output Output directory ./recovered-source
--concurrency Parallel download threads 10
--pages FILE File with extra paths to probe, one per line
--include-node-modules Include node_modules files false
--verbose Enable verbose output false
--version Show version

How It Works

  1. Discover — Fetches the target URL and common pages (/login, /signup, /dashboard, etc.) to find JS/CSS chunk references
  2. Download chunks — Downloads all discovered chunks and extracts sourceMappingURL references
  3. Download sourcemaps — Fetches all referenced .map files
  4. Extract — Unpacks original source files from sourcesContent and writes them to disk with their original directory structure

Supported Bundlers

Bundler Prefix
Webpack webpack:///
Next.js (Webpack) webpack:///_N_E/
Turbopack turbopack:///[project]/
Vite vite:///
Rollup rollup:///

Disclaimer

This tool is intended for authorized security testing, bug bounty research, and educational purposes only. Only use it on applications you have permission to test. The author is not responsible for any misuse.

License

MIT

Metadata

Release files for unmapjs 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for unmapjs 1.0.0
File Size Uploaded
unmapjs-1.0.0.tar.gz 10.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for unmapjs 1.0.0
File Interpreter ABI Platform
unmapjs-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 22.0 kB

Release files / unmapjs-1.0.0.tar.gz

Download URL unmapjs-1.0.0.tar.gz
Size 10.8 kB
Tags Source
SHA-256 checksum
How to use checksums
824dd38f22c07eeb85725cd63ec54833368bb2912ef0bb67e2a751138b407414
BLAKE2b-256 checksum
How to use checksums
4bda6bb781281d9526157d99465720458ace0c5b944c50161a6dfef3e77e3398
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release files / unmapjs-1.0.0-py3-none-any.whl

Download URL unmapjs-1.0.0-py3-none-any.whl
Size 11.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c1b83a0c27e7925627109926476472014660d2b48542bf84fe36325f6027e19e
BLAKE2b-256 checksum
How to use checksums
01dc47d4d986e84b0d4300e6bc69516c645fb1fc86d48f1d93771157a35ebeff
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page