PHP Formatter
Re-indents PHP code safely without touching strings, comments, or inline HTML.
Decode PHP serialized strings, like those in WordPress options and session files, into readable JSON, or turn JSON into a PHP serialized string. Nothing is executed.
PHP's serialize() writes each value as a type letter followed by its data:
N; is null, b:1; is true, i:42; is an integer, and d:3.14; is a float.s:5:"hello"; is a string. The number is the length in bytes, not characters, so é counts as 2.a:2:{...} is an array with 2 key and value pairs.O:4:"User":1:{...} is an object of class User with 1 property. Private and protected property names carry hidden prefixes, which are shown here in readable form.The parser reads these rules itself. It never calls PHP or creates objects, so malicious input can't run code in your browser.
a:2:{s:4:"name";s:3:"Ada";s:5:"langs";a:2:{i:0;s:3:"PHP";i:1;s:2:"Go";}} unserializes to {"name": "Ada", "langs": ["PHP", "Go"]}.{"id": 7, "price": 9.5, "tags": []} gives a:3:{s:2:"id";
i:7;
s:5:"price";
d:9.5;
s:4:"tags";
a:0:{}}.s:4:"café";
is reported as wrong: café is 5 bytes in UTF-8, so it must be s:5:"café";
. This is the usual cause of broken WordPress data after a search and replace.Serializable (C: format) are shown as raw data, because their format is defined by their class.r: and R:) are shown as markers pointing to the value they refer to.Yes. Unlike PHP's unserialize(), this parser never creates objects or calls methods, so there is no object injection risk. Your data also stays in your browser.
The string lengths no longer match. Replacing http:// with https:// adds a byte, but s:20: still says 20. Use a serialization-aware tool such as WP-CLI's search-replace.
serialize() keeps PHP-specific types such as objects with their class and integer versus string keys, but only PHP can read it. json_encode() works in every language.
No. Conversion runs in your browser.
Often used together with the PHP Serialize / Unserialize.
Re-indents PHP code safely without touching strings, comments, or inline HTML.
Beautifies or minifies JSON.
Encodes and decodes Base64 for text and files.