DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
browser automation

Getting Started with Puppeteer Stealth: Install, Configure, and Test It

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

puppeteer-extra-plugin-stealth is a plugin for puppeteer-extra that changes browser-facing signals to make headless Puppeteer harder for some detection systems to identify. Install it as an npm or Yarn dependency, register StealthPlugin(), then test the result on a site you own or are authorized to assess. It is not a guarantee of undetectability or a way to defeat a site’s access controls.

What Puppeteer Stealth is—and what it is not

Puppeteer Stealth usually means the npm package puppeteer-extra-plugin-stealth, used with puppeteer-extra. It is not a separate browser. The plugin modifies observable browser characteristics that some sites use to identify automation; the project README describes its aim as applying “various techniques to make detection of headless puppeteer harder.”

The plugin is best treated as a testing aid for authorized browser automation: for example, checking a site you operate under a more representative set of browser signals. It does not make a browser universally undetectable, and it should not be treated as a way to bypass authentication, CAPTCHAs, rate limits, access restrictions, or a site’s terms. If a site provides an official API for your use case, that is generally a more stable integration route.

Install Puppeteer, puppeteer-extra, and the stealth plugin

Install the browser automation package, its puppeteer-extra wrapper, and the stealth plugin in the project where you will run your authorized checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

npm

npm install puppeteer puppeteer-extra puppeteer-extra-plugin-stealth

Yarn

yarn add puppeteer puppeteer-extra puppeteer-extra-plugin-stealth

Keep these dependencies recorded in the project manifest and lockfile. Pin and review the versions your project uses rather than assuming that a setup which worked with one browser and dependency combination will behave identically after an update.

Enable the default evasion set

In CommonJS, import puppeteer-extra and the plugin, register the plugin with .use(), then launch and use Puppeteer in the usual way. The following minimal script navigates to an example URL; replace it with a page you are authorized to test.

const puppeteer = require('puppeteer-extra')
const StealthPlugin = require('puppeteer-extra-plugin-stealth')

puppeteer.use(StealthPlugin())

;(async () => {
  const browser = await puppeteer.launch({ headless: true })
  try {
    const page = await browser.newPage()
    await page.goto('https://example.com')
    // Perform authorized checks or automation here.
  } finally {
    await browser.close()
  }
})()

Calling StealthPlugin() creates the plugin with its default enabled evasions; puppeteer.use() registers it before launch. The try/finally ensures the browser is closed if navigation or a check throws an error. For a quick smoke test, inspect the navigation result and page behavior rather than treating a successful load as proof that a detection system will accept every run.

TypeScript

The project also documents a TypeScript setup: import puppeteer-extra and puppeteer-extra-plugin-stealth, call puppeteer.use(StealthPlugin()), and launch as usual. The key setup order is the same—register the plugin before launching the browser. Check the types and module settings of the particular dependency versions in your project if your TypeScript compiler reports an import or type error.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure individual evasions when a test needs control

The default configuration is the simplest starting point, but the plugin is modular. Its API exposes availableEvasions, and the enabled set can be changed before the plugin is registered. For example, a project can remove console.debug from the enabled set when it wants to isolate or avoid that behavior. The project’s evasions directory is the place to inspect the current individual modules; the set and details can evolve, so do not assume a fixed list from an old example.

Use the default set first, then change one variable at a time. Record which evasions were enabled for a test so another developer can reproduce it. Avoid disabling or adding modules just to chase a single successful page load: a change may affect other pages, and the observed result only applies to the browser, target, and conditions you tested.

A reliable getting-started workflow

  1. Pin and review dependencies. Record the Puppeteer, puppeteer-extra, and stealth-plugin versions used by the project. Review changes before upgrading.
  2. Register the default plugin. Start with puppeteer.use(StealthPlugin()) before launching.
  3. Choose an authorized target. Prefer a staging environment, an internal test page, or a system for which you have explicit permission. Use the site’s API or documented automation route when available.
  4. Capture observable outcomes. Log navigation results and page errors, and save screenshots or other test artifacts as appropriate. Distinguish a page that loaded from one that rendered the content your test expects.
  5. Isolate behavior if necessary. Adjust the enabled evasion set only when a test question calls for it, then compare results with the rest of the setup held constant.
  6. Retest after changes. Repeat the test after browser or dependency updates. The project describes detection and evasion as a fast-moving cat-and-mouse problem, so a past result is not a permanent guarantee.

Keep ordinary automation hygiene in place: use realistic test data, controlled request rates, clear authorization, and the target’s terms and robots or API guidance. Stealth-related changes do not grant permission to access a service or remove the consequences of excessive or disallowed traffic.

What the plugin can—and cannot—change

The project’s stated focus is detectable browser characteristics. Its README gives the HeadlessChrome user-agent token as an obvious example of a signal that can expose automation. The plugin’s bundled evasions address browser-facing surfaces, but a site may make decisions using signals beyond the JavaScript surfaces it patches. Network behavior, interaction patterns, account context, and site-specific checks are examples of factors that should not be assumed to be controlled by this plugin.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no universal pass rate or dated benchmark established by the project and registry material summarized here. A successful test on one target does not establish that another site, browser version, or session will behave the same way. Phrase conclusions narrowly: report what your authorized test observed, including its browser and dependency setup, instead of claiming that Stealth makes Puppeteer undetectable.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common setup and test failures

Node cannot find a package

If Node reports that it cannot find puppeteer-extra or puppeteer-extra-plugin-stealth, verify that you installed dependencies in the project directory from which the script runs. Check the package manifest and rerun the appropriate npm or Yarn install command there. Also confirm that the script’s import style matches the project’s CommonJS or TypeScript/module configuration.

The browser does not launch

Separate browser-launch failures from stealth behavior. Confirm that Puppeteer and its browser installation are available in the environment where the script runs, and read the launch error before changing plugin settings. A failure to start the browser is not evidence that a particular evasion failed.

The page loads but the test does not find expected content

A successful page.goto() does not guarantee that an application has finished rendering the element your test needs. Check the navigation result, page errors, and whether the expected content appears; then use an appropriate wait for the application’s own observable state. Do this on an authorized target and avoid interpreting a missing element as proof of bot detection without other evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A target still identifies or blocks the browser

The plugin is not a universal bypass. The target may rely on signals outside the plugin’s browser-facing changes, or the test may be exercising a rule unrelated to headless-browser detection. Reproduce the issue on a system you control, inspect the target’s documented access route, and contact its operator where appropriate. Do not respond by attempting to defeat authentication, CAPTCHAs, rate limits, or other access restrictions.

Behavior changes after an upgrade

Compare the old and new dependency and browser versions, and rerun the same authorized test with a recorded configuration. If needed, narrow the enabled evasion set to isolate a behavior. Avoid drawing a broad conclusion from a single changed run; browser and site behavior can change independently of the plugin.

Performance, reliability, and maintenance

The plugin adds configuration and browser-side behavior to a Puppeteer run, so treat its setup as part of the test environment rather than as a universal reliability switch. Keep runs reproducible by recording dependency versions, browser configuration, target, and enabled evasions. Capture page errors and screenshots when they help distinguish a launch problem, a rendering problem, and a target response.

For production integrations, consider the maintenance cost of relying on browser automation and site behavior that you do not control. An official API, when available and suitable, is usually a less fragile interface. For authorized QA where a browser is specifically required, schedule retesting when dependencies or the target site change, and do not assume that a prior successful run establishes future access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

If your actual task is to obtain a website screenshot rather than run Puppeteer or assess browser signals, ScreenshotNeo is a separate website screenshot API and MCP server for developers—not a Puppeteer Stealth replacement or a bot-detection bypass. A GET request can return a screenshot or PDF. For example, using the supplied cURL pattern:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo documentation for the API details. Cookie banners, popups, and chat widgets are removed before the shot; bot checks, blank pages, and failed loads are never billed. An MCP server lets AI agents take screenshots. The free plan includes 1,000 screenshots a month with no card, and paid plans start at $5 for 3,000. This is useful for screenshot capture, but it does not run your Puppeteer checks or make a browser less detectable.

Sign up for ScreenshotNeo’s free plan to try 1,000 screenshots a month with no card.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.