# Arkenfox user.js: a Firefox hardening template, not a browser

> A look at what the arkenfox user.js template actually changes in Firefox, how its release numbering tracks Firefox releases, and why the project tells you not to use it with Tor.

**arkenfox/user.js** — Firefox privacy, security and anti-tracking: a comprehensive user.js template for configuration and hardening

- Repository: https://github.com/arkenfox/user.js
- Stars: 12,855 · Forks: 555
- Language: JavaScript
- License: MIT
- Published: 2026-10-06 · Updated: 2026-10-06 · Language: en
- Canonical page: https://hysenlabs.com/projects/arkenfox-user-js

## A template of preferences, applied by Firefox itself

A `user.js` is a file of `user_pref()` calls that Firefox applies to your profile at startup. That mechanism is built into Firefox, not invented here, which is worth saying plainly: this repository ships no extension, no binary and no daemon. It ships one very long file, plus the tooling to keep it current.

The repository describes itself as a Firefox privacy, security and anti-tracking template for configuration and hardening, and the README calls it a template rather than a tool. The stated goal is as much privacy and enhanced security as possible while reducing tracking and fingerprinting, and the constraint stated alongside it is minimizing loss of functionality and breakage. The parenthetical is honest: the README says breakage will happen.

The single file `user.js` at the repository root is the artifact. Beside it sit the shell and batch equivalents of two housekeeping tasks, `updater.sh` and `prefsCleaner.sh`, along with their Windows counterparts `updater.bat` and `prefsCleaner.bat`, plus a `scratchpad-scripts/` directory and a `wikipiki/` directory that holds documentation sources. The licence is MIT.

Two repository files are worth reading as policy rather than code. The README opens by stating that the repository and the linked interactive webpage are the only official sources and that other sites claiming to be Arkenfox should not be trusted, and `_config.yml` exists because that webpage is published from this tree.

## Release numbering follows Firefox, not the project

Version 144.0 was published on 2026-04-20 and its notes are a list of links to four Firefox versions, 141 through 144, each with three links: release notes for users, developer documentation and a Mozilla security advisory. So a single Arkenfox release covers a range of Firefox versions rather than matching exactly one.

The 140.0 release from 2025-08-13 follows the same pattern for Firefox 136 through 140. Each version boundary also has its own GitHub issue referenced in the notes, labelled by the pair it bridges, which is how a contributor finds out what changed between two Firefox versions.

The point release tells you what happens when Firefox's own line splits. Version 140.1, published 2025-11-03, exists specifically for ESR users, and its notes open by saying the .1 refers to Arkenfox and has nothing to do with Firefox's versioning. It was cut to match an upcoming default change in Arkenfox so that users on the extended support release would not be left behind.

Read the two numbering schemes together and the upgrade path becomes clear: the trailing .1 is an Arkenfox adjustment for a Firefox audience that is not moving as fast, not a patch to a Firefox bug.

The last push to master was on 2026-09-09, months after the 144.0 release, which suggests Firefox has moved on and the matching Arkenfox release had not yet been cut at that point.

## What the 140.1 change says about the project's philosophy

The 140.1 notes contain the clearest statement of intent in the release history. The change enables `sanitizeOnShutdown` to help prevent first party website tracking across sessions, and the reasoning is that history and downloads data, which websites cannot access, is orthogonal to tracking and therefore exempt from being cleared. The notes call it a non-destructive change and add that users who want the old behaviour can add overrides.

That is a small change with a large amount of thought behind it, and it shows the project's default posture. Rather than clearing aggressively, Arkenfox keeps local history so first party state does not accumulate in the profile, and it explicitly tells you that a preference can be overridden rather than presenting the template as a finished product.

The same release also handles preference drift. Firefox 136 changed the preferences used for clearing history on shutdown, so the changelog lists both the old names and the FF136 and later names, including `privacy.clearOnShutdown_v2.browsingHistoryAndDownloads`, and adds `browser.display.document_color_use` because the preference it replaced is no longer used. This is the maintenance burden nobody sees: Firefox renames and removes preferences, and a template only stays useful if someone tracks those changes.

## The project tells you where it does not apply

Two warnings in the README are load bearing, and both are about using this outside desktop Firefox.

The first is Tor. The README states plainly that it does not recommend connecting over Tor on Firefox, and points to the Tor Browser instead if your threat model calls for it or for accessing hidden services. The reason follows from what the template does: hardening preferences that Firefox already applies inside the Tor Browser change a configuration the Tor Browser deliberately tunes, so the template works against the browser's own protections.

The second warning is broader. The template is made specifically for desktop Firefox, and using it as-is in other Gecko-based browsers can be counterproductive, with the Tor Browser named as the clearest case. That is the honest boundary of the project. It is not a cross-browser privacy framework with a Firefox profile, it is a Firefox profile.

For the same reason, there is no install command in the README. The mechanism is Firefox reading a file from your profile, so what you actually do is take the user.js for your Firefox version and let Firefox apply it on next start. The shell scripts in the repository root exist to fetch a current copy and to clean preferences you have set yourself, which is the operation most likely to be done repeatedly.

## Documentation lives in the wiki and in labelled issues

The README is short and points at documentation rather than duplicating it. The wiki has a page specifically explaining what a `user.js` is at a technical level, and the README says everyone, experts included, should read the wiki because it contains important information about a few settings. There is also an interactive page for the current release, contributed by another person, which lets you look at settings without reading the raw file.

The rest of the documentation is organised as GitHub issue labels, which the README collects as a sitemap:

```bash
updater.sh
prefsCleaner.sh
```

That covers releases, changelogs, the wiki, and four labelled issue views: sticky topic, diffs, common questions and answers, and the version transition issues. A sticky topic is the closest thing the project has to a support policy, and diffs are how a user sees what a new version will do to their existing profile.

So the documentation surface is a wiki, a generated page, and a set of issue labels rather than a manual. That is a real trade-off. It stays current because it is written when a change happens, but it is scattered, and someone deciding whether to adopt the template will spend time in the issue tracker rather than in a guide.

## What adopting it actually costs

The cost is not installation, it is maintenance, and the template is honest about the trade. Every Firefox release can rename or remove a preference, and a template that lags is a template that silently does nothing. The version boundary issues exist to catch that, which means keeping up requires reading them.

There is a second cost: functionality. The goal is minimal loss of functionality, not zero, and the README says so. Some sites rely on APIs that anti-fingerprinting settings restrict, and some sites simply detect a hardened profile. Expect to investigate a broken site by turning individual preferences back, which is what the override mechanism is for.

The licence is MIT, which is the permissive end of the scale and carries no obligation on anyone adopting it beyond attribution. There is no warranty of any kind, and for a template whose entire value is judgement calls about defaults, that is the honest framing: it is a well-argued starting position, not a guarantee.

## Conclusion

Arkenfox is the right starting point for someone hardening a desktop Firefox install who is willing to read the wiki and undo the settings that break their work. It is the wrong tool for a Gecko browser that is not Firefox, and the README is explicit that using it in the Tor Browser is counterproductive. Start at the releases page, take the template matching your Firefox version rather than the newest one, then read the sticky topic and changelog issues for that version before applying it, because the project itself says some breakage will happen and that overrides are the intended escape hatch.

## FAQ

### What is Arkenfox?

Arkenfox is a template of Firefox preferences distributed as a `user.js` file. Firefox applies those preferences to your profile at startup, and the project maintains them to reduce tracking and fingerprinting and to harden security settings, while accepting that some functionality will break.

### Can I use the arkenfox user.js in the Tor Browser?

No. The README states the template is made specifically for desktop Firefox and that using it as-is in other Gecko based browsers can be counterproductive, naming the Tor Browser as a case where it works against the browser's own configuration. It also states that it does not recommend connecting over Tor on Firefox, pointing to the Tor Browser for that threat model.

### How does arkenfox versioning relate to Firefox versions?

An Arkenfox major version covers a range of Firefox versions, so 144.0 references Firefox 141 through 144 with release notes, developer documentation and a security advisory for each. A trailing .1 is an Arkenfox-only point release, published for ESR users to match a default change, and it has nothing to do with Firefox's own numbering.

## Sources

- [arkenfox/user.js on GitHub](https://github.com/arkenfox/user.js)
- [Issues](https://github.com/arkenfox/user.js/issues)
- [License: MIT](https://github.com/arkenfox/user.js/blob/master/LICENSE)
- [README](https://github.com/arkenfox/user.js/blob/master/README.md)
- [Releases](https://github.com/arkenfox/user.js/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/arkenfox-user-js
