Serialize & Unserialize
Convert PHP serialized data to readable JSON, and JSON back to PHP serialize format.
Everything runs in your browser; nothing is sent to a server. String lengths are counted in UTF-8 bytes exactly like PHP, and broken lengths are repaired automatically. Objects are never instantiated, so it is safe to inspect untrusted data.
Continue your work
- JSON Formatter & Validator — Format and validate the JSON output.
- JSON Tree Viewer — Explore large unserialized data as a tree.
Share this tool
Found it useful? Send it to a friend or teammate.
Rate this tool
0.0
0 ratings
- 5 stars 0
- 4 stars 0
- 3 stars 0
- 2 stars 0
- 1 star 0
Clear instructions
Find steps, examples and limitations below.
Use online
Open the tool in a supported web browser.
Free to use
No sign-up required. Tool-specific limits may apply.
How to use the Serialize & Unserialize
PHP's serialize() format stores arrays and objects as strings, and you often find it in WordPress options, sessions and cache tables. Paste PHP serialized data, JSON, or either one Base64 or URL encoded, and the input type is detected for you. View the result the way PHP would print it (print_r, var_dump or var_export), as a collapsible Krumo tree, as dBug-style nested tables, as JSON, or serialized again. String lengths are counted in UTF-8 bytes exactly like PHP, and lengths broken by a search-and-replace are repaired automatically.
- 1 Paste your data, or load the PHP, JSON or broken example. The input type is detected automatically.
- 2 Pick an output view: print_r, var_dump, var_export, Krumo tree, dBug tables, JSON, serialize or Base64.
- 3 Copy or download the result, or use it as the new input.
Example and practical tips
a:1:{s:3:"url";s:19:"https://toolzhive.com";} fails in PHP because the URL is 21 bytes, not 19. The tool fixes the length; choose the serialize view to copy the repaired string.
Frequently asked questions
Why does unserialize() fail after a search-and-replace?
Serialized strings store their length. Replacing text changes the length without updating it, which breaks the data. This tool recalculates the lengths so the data loads again.
How are PHP objects shown?
The print_r, var_dump and var_export views show objects exactly as PHP would, including protected and private properties. In JSON, objects get a "__class" key holding the class name.
Can I convert JSON to PHP serialized data?
Yes. Paste JSON and choose the serialize view. JSON objects become associative arrays, or stdClass objects if you tick the option.
Is it safe to unserialize untrusted data?
This tool only parses text and never runs code, so it is safe to use here. In PHP, never call unserialize() on untrusted input; use JSON instead.
Report an issue
Something broken or not quite right? Tell us and we will look into it.