Which one is stronger and harder to be cracked XLS padlock versus DoneEx

tossxv

New member
I was wondering about which one is harder to be breached penetrated to reverse its engineer and get the vba codes recorded in an application made on excel spreadsheet.
So, which one can really make it harder to be penetrated of getting its vba codes?

I do find that XLS padlock does has obfuscation to the vba codes which is sounding ok.
But the DoneEx seems to be doing obfuscation to be impossible to really be cracked by any reverse engineering?
 
Last edited:
I’m also trying to decide on whether to purchase. My thoughts are 1.) I see XLS Padlock released a new version today (news link below) that apparently separates the EXE from the data file and includes code signing. I wonder if that won’t be more secure if the VBA is isolated in the EXE, depending on how it is compiled? Not sure. 2.) I cannot find any verifiable commercial applications using XLS Padlock. Have you come across any?

 
c71 said:
whether to purchase. My thoughts are 1.) I see XLS Padlock released a new version today (news link below) that apparently separates the EXE from the data file and includes code signing. I wonder if that won’t be more secure if the VBA is isolated in the EXE, depending on how it is compiled? Not sure. 2.) I cannot find
In the new application bundle format, the VBA code is still in bytecode if you use the VBA compiler. It doesn’t have more weakness than in standalone EXE file. The main reason to choose the bundle format is for end users who don’t have a code signing certificate and get issues with some antivirus software.
 
c71 said:
2.) I cannot find any verifiable commercial applications using XLS Padlock. Have you come across any?
They are some, but not sure whether we are allowed to publish their names. Feel free to send us a PM to have some references.
 
I was wondering about which one is harder to be breached penetrated to reverse its engineer and get the vba codes recorded in an application made on excel spreadsheet.
So, which one can really make it harder to be penetrated of getting its vba codes?

I do find that XLS padlock does has obfuscation to the vba codes which is sounding ok.
But the DoneEx seems to be doing obfuscation to be impossible to really be cracked by any reverse engineering?

This question never got a direct answer from us, so here it is, with the facts as of XLS Padlock 2026.3.

XLS Padlock does not obfuscate your VBA code: it compiles it. When you build the application, the VBA Compiler turns the pasted macros into bytecode and removes their original source. There is no VBA source left to de-obfuscate: the VBA editor has nothing to show, and password-removal tools have nothing to unlock.

No vendor can honestly promise protection that is "impossible to crack". In an application compiled with XLS Padlock:

  • the workbook is stored encrypted and never written to disk in plaintext;
  • the formulas you choose are encrypted and evaluated at runtime, so the formula bar shows nothing to copy;
  • the EXE checks its own integrity at startup;
  • activation keys can be locked to the customer's hardware, and online activation responses can be signed with Ed25519 (since 2026.0) so they cannot be forged;
  • save files are encrypted with AES and checked with HMAC-SHA256;
  • NEW Web Update files are signed and verified before they are installed.
 
Back
Top