How feasible would it be, instead of encryption/decryption in the browser source code (which can be defeated easily), to do decryption and rendering in javascript, perhaps with emscripten + asm.js optimizations? That should provide a reasonable amount of security through obscurity.