Skip to content

The open-source puppeteer-extra-plugin-stealth alternative

The stealth plugin is still the most-installed way to bolt evasions onto Puppeteer, at more than a million downloads a week, but it hasn't had a release since March 2023. Every evasion is a JavaScript patch on a stock Chrome, and JavaScript patches reveal themselves. Clearcote sets those values natively in the engine.

What is puppeteer-extra-plugin-stealth?

puppeteer-extra-plugin-stealth (by berstend) is a bundle of JavaScript evasion modules injected with page.evaluateOnNewDocument before page scripts run. Each patches a single tell: navigator.webdriver, plugins, chrome.runtime, the WebGL vendor, iframes, codecs and more. It is MIT-licensed and hugely popular, at more than a million npm downloads a week, and its approach was ported to playwright-stealth and selenium-stealth.

It is also unmaintained in practice: the last npm release (2.11.2) was in March 2023, and no code has been committed to the repository since. The structural limit predates that. These are JavaScript overrides on a stock engine, and overrides reveal themselves through Function.prototype.toString, altered property descriptors, and re-reads from Web Workers or cross-origin iframes where the patch isn't present. It doesn't change native values, doesn't touch TLS or HTTP/2, and doesn't address the Runtime.enable CDP leak. Its own README concedes that preventing every way to detect headless Chromium is probably impossible.

Clearcote vs puppeteer-extra-plugin-stealth

FeatureClearcotepuppeteer-extra-plugin-stealth
Approach Engine-level C++ patches: native values JavaScript evasions injected per document
Detectable seam None: native in every realm (page, workers, iframes) Visible via toString, descriptors, worker and iframe re-reads
TLS / network coherence Follows the claimed Chrome (JA3/JA4 + HTTP/2) Not addressed
Framework Playwright & Puppeteer (Python, Node, .NET) Puppeteer (Node); playwright-extra for Playwright
Maintenance Active Last release March 2023
License Open build BSD-3 MIT
Cost Open build free; latest build free with GitHub Free & open

Comparison compiled October 2026. puppeteer-extra-plugin-stealth is open source (mit); details change — check its project for the latest.

Why teams pick Clearcote

Native, not overridden

Every stealth-plugin evasion is a JavaScript override a detector can catch. Clearcote sets the values in the engine, so they read as native and there's no override to find.

Coherent across realms

JavaScript patches applied to the page diverge in Web Workers and cross-origin iframes. Engine-level values agree everywhere, closing that class of tell.

The network layer

The plugin has no access to TLS or HTTP/2. Clearcote's handshake follows the claimed Chrome version, so the wire matches the JavaScript.

Maintained and verified

Clearcote is checked against open tests every release. The plugin's evasions date from early 2023 and Chrome has moved on by dozens of versions since.

When puppeteer-extra-plugin-stealth might be the better pick

  • You already use Puppeteer and want a one-line evasion bundle for lenient targets.
  • You need something MIT-licensed to drop into an existing Node scraper.
  • For public test pages and older detection, it's quick and sometimes enough.

FAQ

Is puppeteer-extra-plugin-stealth still maintained?

Not actively. The last npm release, 2.11.2, was published in March 2023, and there have been no commits to the repository since. It still installs and is heavily used, but its evasions haven't kept pace with Chrome.

Why do JavaScript stealth patches get detected?

Because they're overrides on a real function. A detector can stringify it (a native function reads [native code]; an override shows its own source), inspect the property descriptor, or re-read the value from a fresh iframe or Web Worker where the patch isn't applied. Engine-level changes avoid this by making the value native everywhere.

How is Clearcote different from the stealth plugin?

The plugin injects JavaScript evasions into a stock Chrome; Clearcote is a modified Chromium where the values are native in the engine, coherent across workers and iframes, with a TLS/HTTP-2 persona the plugin has no access to.

Is there a version for Playwright?

Yes: playwright-extra can load the same plugin in Node, and playwright-stealth ports it to Python. Both share the same JavaScript-override design.

Related reading

Q&AWhy does Function.toString() reveal a hooked function?Calling toString() on a native function returns “[native code]”; an override returns its own source instead — so detectors stringify APIs to catch JavaScript spoofs.CompareClearcote vs playwright-stealthplaywright-stealth is the quickest way to add stealth to Playwright in Python: one wrapper and every page gets a set of JavaScript evasions. But the evasions are overrides on a stock browser, and its own maintainer calls it a proof of concept. Clearcote sets those values natively in the engine instead, so there is no override for a page to find.ResearchCoherence over camouflage: why a plausible identity beats a hidden oneMost stealth tooling tries to hide. The signals that survive scrutiny don't hide — they agree with each other.CompareClearcote vs CamoufoxCamoufox is a well-built open-source anti-detect browser, on Firefox. Clearcote takes the same engine-level approach to Chromium, so your automation presents the browser about 66% of the web actually uses instead of one used by about 3%.CompareClearcote vs CloakBrowserCloakBrowser is a capable engine-level stealth Chromium with a large following, but the patched binary is closed source. Clearcote is engine-level too, runs a newer Chromium, and ships an open build whose every patch you can read and rebuild.CompareClearcote vs undetected-chromedriverundetected-chromedriver is still downloaded about 2 million times a month, but its last release was in February 2024. It hides the Selenium/ChromeDriver seam on a stock Chrome and never touches the fingerprint or the network layer. Clearcote changes both in the engine.

Try the open-source Chromium alternative

Free and open source, a drop-in for Playwright & Puppeteer, coherent down to the TLS handshake.

Free for one browser with GitHub. No card.