Just as a general thought, not specific to this product:
This is decrypted and eval'd at runtime
Most(all?) string-based obfuscators can be bypassed by simply replacing eval with a logging eval implementation.
var oldEval = eval; eval = function(str){console.log(str);oldEval(str)};
A similar patch to the Function constructor can bypass the other easy dynamic code generation code path.If at some point, a string needs to be evaluated as code, then it's possible to intercept that code and output it.