viewhack

Look inside a WebAssembly .wasm file

Drop a .wasm module to see what it imports and exports, which toolchain built it, how its size splits between code, data and debug info, and the strings in its data. Open any function to read its instructions in the WebAssembly text format. No wabt to install, no account.

The module is read by this tab on your device and is not uploaded. It is never compiled or run, and any source-map or debug-info address inside it is shown, not fetched.

What it shows

Reading a module

A worked example
The SQLite build this site’s SQLite viewer uses, sql-wasm-browser.wasm from sql.js 1.14.2, is 658,410 bytes. 89% of it is code (585 KB in 1,879 functions); 68 KB is data, whose first string is 3.49.1, SQLite’s version. All 38 imports come from a module named a with one-letter names, the mark of Emscripten’s minified glue, and its memory starts at 338 pages (21 MB) and may grow to 32,768 pages (2 GB). It has no name section, so its functions are shown by number. It uses bulk memory, sign extension and non-trapping float-to-int instructions.
What imports tell you
A WebAssembly module can do nothing outside its own memory except through its imports, so the import list is the complete set of things it can ask its host for. A module whose WASI imports include path_open can ask to open files by name; one with only fd_write can write to streams the host already opened, usually just the console. Whether the host grants any of it is the host’s choice: browsers have no WASI at all, and wasmtime gives no folder access unless you pass --dir.
Why the text is long
The text format writes each instruction on its own line, so a module’s .wat is typically 15 to 25 times its size: sql.js’s 658 KB becomes about 15 MB of text. That is why functions open one at a time here.
Written for this site
The module is decoded by viewhack’s own reader and text printer, written from the WebAssembly Core Specification and the tool-conventions documents for the name, producers and target_features sections. It covers WebAssembly 1.0 and 2.0 plus the threads, GC, typed references, exception handling, tail call, memory64 and multi-memory proposals. Most SIMD arithmetic instructions are shown by opcode number (v128.op_N) rather than by name. No wabt or binaryen code is used, and no library is downloaded.
Tested on
Modules generated in the test with WASI imports, name and producers sections, a data segment, a source-map address, an exported memory and functions, and the real WebAssembly files bundled with sql.js (MIT), pdf.js’s colour-management module (written in Rust, built with wasm-bindgen) and the other vendored libraries on this site, every function of which decodes to its last byte.

What this cannot do

Other ways to look inside

Command line
wasm-objdump -x and wasm2wat (wabt), or wasm-tools print and wasm-tools objdump (Bytecode Alliance). twiggy top ranks what takes the space.
Browser DevTools
On a page that already loads the module, Chrome and Firefox list it under Sources and show its text, with DWARF source when the module was built with -g.