PHP Serialize / Unserialize
Read and write PHP serialized data, JSON and PHP arrays, and fix broken string lengths.
Serialized PHP, JSON or a PHP array. Converted as you type; nothing is uploaded or executed.
About the PHP Serialize / Unserialize
Paste a value from PHP's serialize() — from a database column, a WordPress wp_options row, a session file or a cache — and read it as JSON or as PHP prints it with var_export(), print_r() or var_dump(). It works the other way too: paste JSON or a PHP array ([...], array(...) or var_export() output) and get the serialized string PHP would produce.
Every type is understood: strings, integers (64-bit), floats (including INF and NAN), booleans, null, arrays, objects with their public, protected and private properties, references (r: and R:), custom serialization (C:) and enums (E:). String lengths are counted in UTF-8 bytes, as PHP counts them — so when a database search-and-replace has changed a URL without updating its length, the tool shows exactly which string is wrong and Repair string lengths fixes every count, also inside serialized data that is stored in a string. Nothing is uploaded and nothing is unserialized into code: the data is only read as text.
How to use it
- Paste the serialized string, JSON or PHP array, or open a file. The format is detected (or choose it under Read as).
- Choose what to convert to: JSON, a serialized string,
var_export(), short array[...]code,print_r()orvar_dump(). The result updates as you type. - If the input says a string's length does not match, press Repair string lengths to recompute every
s:N:count, then check the result. - Copy the result, download it, or press Use as input to convert it further.
Examples
a:3:{s:4:"name";s:4:"Ravi";s:3:"age";i:34;s:4:"tags";a:2:{i:0;s:3:"php";i:1;s:4:"json";}}{
"name": "Ravi",
"age": 34,
"tags": [
"php",
"json"
]
}s:19:"https://new-shop.example.com";
Error: The string length 19 does not match… The text in the quotes is 28 bytes long. Repair string lengths gives s:28:"https://new-shop.example.com";
Replacing a domain in a database dump without updating the lengths breaks every serialized value that contained it; WordPress then silently ignores the option.
{"id": 7, "price": 249.5, "ok": true, "note": null}a:4:{s:2:"id";i:7;s:5:"price";d:249.5;s:2:"ok";b:1;s:4:"note";N;}O:8:"Customer":2:{s:4:"name";s:4:"Ravi";s:8:"\0*\0email";s:15:"ravi@example.in";}Customer Object
(
[name] => Ravi
[email:protected] => ravi@example.in
)Common uses
- Reading WordPress options, post meta and transients, WooCommerce order data, Drupal and Magento configuration stored as serialized PHP.
- Fixing serialized data after moving a site to a new domain with a plain search-and-replace.
- Debugging PHP sessions and cache entries without writing a script.
- Turning a PHP configuration array into JSON for a JavaScript or Python service, or JSON test data into a PHP array.
How PHP serialization works
Each value starts with a type letter: N; (null), b:1; (boolean), i:42; (integer), d:1.5; (float), s:5:"hello"; (string — 5 is its length in bytes, so "é" counts 2), a:2:{…} (array: the number of elements, then key and value pairs), O:8:"Customer":2:{…} (object: class name and properties), E:11:"Suit:Hearts"; (enum case), C: (a class that serializes itself) and r:3; / R:3; (references to an earlier value). Protected properties are stored as \0*\0name and private ones as \0ClassName\0name; the tool shows them as name plus visibility.
How values map to JSON and back
- Arrays with keys 0, 1, 2 … become JSON lists; other arrays become JSON objects.
- Objects become JSON objects with all their properties, the protected and private ones too (PHP's
json_encode()keeps only the public ones); Class name adds"__class": "Customer"so you can tell them apart. - Enum cases become
"Suit::Hearts": serialized data names the case, but not the value of a backed enum. - Floats that are whole numbers keep a decimal point (
2.0) so they stay floats; INF and NAN becomenull, because JSON has no such numbers. - From JSON, objects become associative arrays like
json_decode($json, true), orstdClassobjects; keys such as"7"become integer keys, as PHP does; integers too large for 64 bits become floats.
Is it safe?
Calling PHP's unserialize() on data you do not control can run code through class "magic methods" (object injection). This page never does that: it parses the text in your browser and only displays what it contains — no class is instantiated and no code runs. In your own PHP code, prefer json_decode() for untrusted input, or pass ['allowed_classes' => false] to unserialize().
Limitations
- PHP strings are byte strings. Text that is not valid UTF-8 (binary data such as images or encrypted values) cannot be shown exactly: invalid bytes appear as �, so do not convert binary data back with this tool.
- Classes that use custom serialization (
C:— Serializable, ArrayObject …) keep their data as an opaque string; objects that implement__serialize()are shown with the data they stored. - Repairing fixes lengths only. Where each string ends is worked out from the structure, so text that contains
";and serialized data stored inside a string (double serialization) are repaired too; when the element counts are wrong as well, or the data is cut off, the tool says that the result still does not read and the rest needs a manual fix. - Serialized enum cases carry only their name, so
print_r()of a backed enum showsSuit Enumwith its name, notSuit Enum:stringwith its value as PHP would. - PHP literals are read, not executed: only literal values (arrays, strings, numbers, booleans, null,
(object)casts and__set_state()fromvar_export()) are accepted, not constants, variables or function calls. var_dump()object numbers (#1) count objects in the order they appear, as a fresh script would.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is my data uploaded?
No. Everything is converted in your browser, and the page works offline once loaded. Serialized data often holds personal or session data, so this matters.
Why does unserialize() fail on my WordPress data?
Almost always because a length is wrong: someone replaced text (often a URL) in the database with a plain search-and-replace, and the s:N: count still has the old byte length. The error here names the string and its real length; Repair string lengths recomputes all of them. Use WP-CLI wp search-replace next time, which updates the lengths.
Why is the length different from the number of characters?
PHP counts bytes in UTF-8, not characters: "café" is 4 characters but 5 bytes, and an emoji is 4 bytes. That is why copying serialized text through an editor that changes the encoding (or curly quotes) also breaks it.
My data came from an SQL dump and shows \0 and \" — what now?
SQL dumps (and PHP string literals) write NUL bytes as \0 and quotes as \", so the lengths no longer match the visible text. Tick Unescape \0, \' and \" and the tool reads the data as it is stored. The private and protected property names of objects contain such NUL bytes.
What do r: and R: mean?
r:n; points to an object that already appeared (the same object used twice); R:n; is a PHP reference (&$value). n counts the values from the start, beginning with 1 for the outermost one. In JSON they become copies of the value they point to, since JSON has no references.
Can I edit the data and serialize it again?
Yes: convert to JSON or to PHP array code, edit it, paste it back and convert to Serialized. Visibility of object properties is kept when you stay within serialized data; JSON has no visibility, so objects that come back from JSON have public properties.