PHP Serialize and Unserialize

Decode PHP serialized strings, like those in WordPress options and session files, into readable JSON, or turn JSON into a PHP serialized string. Nothing is executed.

Updated
Converted in your browser. Nothing is executed or uploaded.
Direction
Show as
Converts as you type.

How to use the PHP Serializer

  1. Pick the Direction: Unserialize to read PHP data, or Serialize to create it.
  2. Paste the serialized string or the JSON into Input.
  3. Press Convert. For unserialized data, switch Show as between JSON and print_r, then copy the result.

How it works

PHP's serialize() writes each value as a type letter followed by its data:

  • N; is null, b:1; is true, i:42; is an integer, and d:3.14; is a float.
  • s:5:"hello"; is a string. The number is the length in bytes, not characters, so é counts as 2.
  • a:2:{...} is an array with 2 key and value pairs.
  • O:4:"User":1:{...} is an object of class User with 1 property. Private and protected property names carry hidden prefixes, which are shown here in readable form.

The parser reads these rules itself. It never calls PHP or creates objects, so malicious input can't run code in your browser.

Examples

  • a:2:{s:4:"name";s:3:"Ada";s:5:"langs";a:2:{i:0;s:3:"PHP";i:1;s:2:"Go";}} unserializes to {"name": "Ada", "langs": ["PHP", "Go"]}.
  • Serializing {"id": 7, "price": 9.5, "tags": []} gives a:3:{s:2:"id"; i:7; s:5:"price"; d:9.5; s:4:"tags"; a:0:{}}.
  • s:4:"café"; is reported as wrong: café is 5 bytes in UTF-8, so it must be s:5:"café"; . This is the usual cause of broken WordPress data after a search and replace.

Limitations

  • Objects can be read, but serializing JSON always produces arrays, not objects.
  • Objects that implement Serializable (C: format) are shown as raw data, because their format is defined by their class.
  • References (r: and R:) are shown as markers pointing to the value they refer to.
  • Input is limited to 5 MB.

Frequently asked questions

Is it safe to unserialize untrusted data here?

Yes. Unlike PHP's unserialize(), this parser never creates objects or calls methods, so there is no object injection risk. Your data also stays in your browser.

Why is my WordPress serialized data broken after a search and replace?

The string lengths no longer match. Replacing http:// with https:// adds a byte, but s:20: still says 20. Use a serialization-aware tool such as WP-CLI's search-replace.

What is the difference between serialize and json_encode?

serialize() keeps PHP-specific types such as objects with their class and integer versus string keys, but only PHP can read it. json_encode() works in every language.

Is my data uploaded?

No. Conversion runs in your browser.

Often used together with the PHP Serialize / Unserialize.